About Zen:
Own your opportunity to work with a client-focused agile small business. Make an impact by advancing our government organizations charged with keeping our country safe, prosperous, and secure. Zen Strategics, LLC is a cleared, minority-owned SBA 8(a) specialized consulting firm, offering innovative Cybersecurity, Cloud Migration, and Information Technology Modernization. We are a leading organization committed to delivering innovative solutions and ensuring the highest standards of security for our customers' digital assets. We are dedicated to staying ahead of evolving cyber threats and protecting our clients' data with cutting-edge technologies and proactive security measures.??
Position Description:
Seize your opportunity to make a personal impact as a Project Manager, Senior. Zen is your place to make meaningful contributions to challenging projects and grow a rewarding career. As a Project Manager, Senior, you will be responsible for ensuring the accurate and timely accomplishment of our client’s security controls assessments in accordance with DOC, NOAA, and NWS policies and procedures for implementation of the Risk Management Framework. This position is a key member of our client delivery Assessment and Authorization (A&A). We are actively seeking a highly proficient project manager able to with minimal guidance schedule, resource and report on assessments including Cloud systems, blended On Prem systems with cloud components, including combinations of Software as a Service (SAAS), Platform as a Service (PAAS) and Infrastructure as a Service (IAAS) topologies. Cloud services are from various vendors (Microsoft (MS) Azure, Google Cloud, Amazon Web Services (AWS), along with scheduling penetration tests. Position requires being present during core business hours of 9:00 AM to 3:00 PM and cannot begin work any earlier than 7 AM. Work is authorized to be performed from a remote location 2-3 days a week. However, be able to be onsite with as little as 24 hours' notice.
Responsibilities:
As a Project Manager, Senior, you’ll be Zen’s expert, developing and implementing security standards and best practices for cloud infrastructure and solutions in AWS, Azure, OCI, and GCP cloud platforms hosted in FedRAMP and FedRAMP environments. You’ll assist the ISSM in meeting their duties and responsibilities by scheduling, preparing, reviewing, and updating authorization packages. You’ll ensure approved procedures are in place for clearing, sanitizing, and destroying various types of hardware and media. Notify ISSM when changes occur that might affect the authorization determination of the information system(s). Conduct periodic reviews of information systems to ensure compliance with the security authorization package. Coordinate any changes or modifications to hardware, software, or firmware of a system with the ISSM and AO/DAO prior to the change. Analyze, plan, and develop projects plans as directed by NWS ISSM. Determines and defines clear deliverables to meet requirements and customer requests. Assembles project teams, assigns responsibilities, identifies appropriate resources needed, and develops schedules to meet milestones and project deliverables. Builds and maintains internal relationships with IT process owners supporting the service and assists with the definition and agreement of Operating Level Agreements. Coordinate with Operations and Maintenance (O&M) teams to drive compliance with Security Controls and requirements. Assesses project issues and develops resolutions to meet needs.
Required Education/ Qualifications:
- Education: BS in Information Technology, Project Management, or Cybersecurity preferred
- Experience:
- 10 or more recent years (within the past 11 years) working in a Project Management role.
- 7 or more years working within the information security field, with emphasis on security operations, incident management, intrusion detection, firewall deployment, and security event analysis.
- At least 8 years of recent experience (within the last 10 years) in applying IT security concepts, methodologies, principles, procedures and using industry-standard IT security tools.
- At least 8 years of recent experience (within the last 10 years) with enterprise architecture methodologies, concepts, procedures, principles, and tools.
- At least 8 years of recent experience (within the last 10 years) in contingency planning and backup and recovery best practices and application of NIST guidance in this area.
- At least 8 years of recent experience (within the last 10 years) in using technical testing tools (Tenable Security Center, ArcSight, IBM Big Fix, etc.).
- At least 8 years of recent experience (within the last 10 years) in conducting penetration testing or the ability to bring in a penetration tester when required .
- US Citizenship Required.
- Certifications: Possess at least one of the following professional certifications required by DOC Enterprise Cybersecurity Policy (ECP) Annex C-1: Information System Security Training for Significant Roles for a Certification Agent/Security Controls Assessor:
- Certified Information Systems Security Professional (CISSP)
- Certified Information Systems Auditor (CISA)
- GIAC Certified Incident Handler (GCIH)
- GIAC Systems and Network Auditor (GSNA)
- Electronic Commerce Council Certified Ethical Hacker (CEH)
- ISC2 Certified in Governance, Risk and Compliance (CGRC)
- Security Certified Network Professional (SCNP)
- Security Certified Network Architect (SCNA)
If you do not possess one of the certifications above, you must provide documentation showing you have already taken training and copy examination scheduled. You must pass the exam within six months of joining Zen Strategics.
- Certifications: Project Management Insititute’s Project Management Professional active and in good standing highly preferred.
- Strong written and verbal communication, leadership, and collaborative team interpersonal skills.
- Ability to manage multiple projects simultaneously.
- Proficiency in interview skills
- Proficiency in interpersonal skills.
- Proficiency in handling multiple tasks concurrently.
- Successful completion of background investigation without any adverse findings are required. Knowledge of and experience with the technical and administrative information system security requirements for high impact, high availability systems in government organizations is required.