Cherokee Federal Logo

Cherokee Federal

Project Lead/Senior Information System Security Specialist

Posted 17 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Washington, DC
Senior level
In-Office or Remote
Hiring Remotely in Washington, DC
Senior level
Leads federal cybersecurity program management and ISSO activities for FHWA systems. Manages plans, schedules, risks, deliverables, staffing, reporting, audits, contingency testing, authorization documentation, vulnerability remediation, security assessments, cloud controls, DevSecOps, incident support, and compliance with FISMA, NIST, FIPS, and FedRAMP requirements. Advises system owners, developers, infrastructure teams, and government stakeholders on cybersecurity risk and information assurance.
The summary above was generated by AI

The Project Lead/Senior Information System Security Specialist 

 

The Project Lead/Senior Information System Security Specialist  provides program management and technical cybersecurity support for the Department of Transportation (DOT), Federal Highway Administration (FHWA) Cyber Security Management Support program. Under the oversight of the FHWA Information System Security Manager (ISSM), this position plans, implements, operates, monitors, and reports on cybersecurity activities that strengthen the security posture of FHWA information systems.

The position manages work identified in the Statement of Work and provides ongoing recommendations to mitigate cybersecurity threats and risks. Program management activities align with applicable Project Management Body of Knowledge (PMBOK) principles and practices. This position requires an individual to perform as both a Project Manager and an ISSO. A strong cybersecurity background is required.

Compensation & Benefits:

Estimated Starting Salary Range for Project Lead/Senior Information System Security Specialist: TBD

Pay commensurate with experience.

Full-time benefits include Medical, Dental, Vision, 401K, and other possible benefits as provided. Benefits are subject to change with or without notice.

Project Lead/Senior Information System Security Specialist Responsibilities Include:

• Develop, maintain, and manage annual and overall project plans, schedules, risk registers, issue logs, communications plans, quality plans, and related program documentation.

• Plan, coordinate, execute, track, and oversee program activities, individual work tasks, milestones, staffing, finances, deliverables, and performance from initiation through completion.

• Ensure all work remains aligned with task-order requirements, established schedules, delivery dates, and Government-approved milestones.

• Track planned, actual, accepted, and rejected deliverables; document rejection reasons; and manage corrective actions through resolution.

• Prepare Monthly Quality and Performance Reports, project status reports, and monthly status briefings addressing program health, accomplishments, ongoing and completed activities, staffing, risks, issues, milestones, and proposed resolutions.

• Schedule, coordinate, and host the Project Kick-Off Meeting and Monthly Status Review meetings; develop agendas, coordinate Government review, prepare meeting minutes, and track action items.

• Coordinate transition-in activities with Government personnel, the incumbent contractor, and other stakeholders.

• Manage staffing activities to maintain the required mix of skills, experience, certifications, licenses, and subject-matter expertise.

• Support the acquisition, retention, management, and training of assigned personnel.

• Ensure contractor personnel meet applicable labor-category requirements and complete required Government background checks and security requirements before receiving access to FHWA resources, data, and networks.

• Maintain quality-control processes and conduct peer reviews to ensure documents submitted to FHWA are technically accurate, professionally prepared, and free of grammatical and typographical errors.

• Identify and recommend opportunities to improve operational efficiency, cost effectiveness, cybersecurity effectiveness, and overall program value.

• Provide cybersecurity subject-matter expertise in incident handling, vulnerability detection, remediation planning, secure application development, cloud environments, and cloud services.

• Support the Information System Security Manager (ISSM) in maintaining the appropriate operational Information Assurance (IA) posture for systems, programs, and enclaves.

• Review logs using Elasticsearch suspicious log-activity queries to identify, investigate, and support response to cybersecurity incidents.

• Support FHWA DevSecOps implementation, including architecture diagrams, process documentation, standard operating procedures, and the integration and management of static code vulnerability scanners.

• Maintain an accurate inventory of FHWA network ranges, assets, groups, and custom groups in the DOT Continuous Diagnostics and Mitigation BigFix tool.

• Conduct and analyze vulnerability and compliance scans for Linux, Windows, and virtual environments using tools such as Tenable Nessus, Splunk, Netsparker, BigFix, SYNACK, and other approved technologies.

• Identify, assess, track, and support remediation of web application, database, network, and infrastructure vulnerabilities.

• Perform dynamic web application security testing through manual testing and application-security tools to identify exploitable vulnerabilities.

• Maintain FHWA core system documentation using standardized templates, technical guides, baseline-management artifacts, and supporting checklists.

• Support development and maintenance of Authorization to Operate and privacy documentation.

• Provide program support for FISMA, CFO, Office of Inspector General, and Government Accountability Office audits, evaluations, data calls, and other inquiries.

• Track and report audit findings, corrective actions, status, and resolutions.

• Execute Information System Contingency Plan testing and provide contingency training for personnel assigned system-recovery responsibilities.

• Support tabletop and functional contingency tests, backup and recovery activities, and application of NIST guidance for contingency planning.

• Analyze security controls for cloud-based systems and support compliance with Federal cloud-security requirements.

• Provide cybersecurity guidance and programmatic assistance to system owners, business sponsors, developers, infrastructure teams, and IT operations personnel.

• Performs other job-related duties as assigned.

Project Lead/Senior Information System Security Specialist Experience, Education, Skills, Abilities Requested:

• Bachelor’s degree in Cybersecurity or a related technical field.

• Current, verifiable Certified Information Systems Security Professional (CISSP) certification.

• Current, verifiable Certificate of Cloud Security Knowledge, Microsoft Azure certification, or another recognized cloud-security certification.

• PMP certification is highly desirable.

• Desired certifications include ITIL v3 or later and relevant certifications from ISC2, ISACA, SANS, EC-Council, Cisco, or similar organizations.

• Demonstrated knowledge of project and program management principles, methodologies, and PMBOK practices.

• Experience with tools such as Tenable Nessus, Splunk, Netsparker, BigFix, and SYNACK.

• Experience assisting Government sponsors in responses to inspections and assessments.

• Experience developing and managing project plans, schedules, status reports, risk registers, deliverable trackers, quality documentation, and management reports.

• Experience coordinating technical and administrative work across Government stakeholders, contractor management, technical teams, system owners, and other project participants.

• Strong written, verbal, analytical, organizational, briefing, and documentation skills.

• Ability to communicate effectively with technical and nontechnical stakeholders.

• Expert knowledge of Federal cybersecurity and privacy laws, regulations, policies, procedures, and implementation standards.

• Expert experience supporting compliance with applicable NIST Special Publications, FIPS 199, and FIPS 200.

• Understanding of the FISMA assessment and authorization process, GSA FedRAMP processes, and current cloud-service technologies.

• Experience applying Federal Information Security Continuous Monitoring and Continuous Diagnostics and Mitigation program technologies.

• Knowledge of secure application-development concepts, dynamic and static application-security testing tools, scan results, and remediation practices.

• Experience conducting vulnerability, application-security, database-security, and network-security assessments and interpreting assessment results.

• Understanding of Identity, Credential, and Access Management implementation.

• Expert experience with enterprise security architecture methodologies, concepts, procedures, principles, and tools.

• Knowledge of Windows Server, Linux/Unix, Active Directory, domain structures, network protocols, authentication, digital signatures, firewalls, data-loss-prevention technologies, intrusion-detection and intrusion-prevention systems, and security best practices.

• At least three years of experience in contingency planning, backup and recovery best practices, and NIST contingency-planning guidance.

• Experience assessing cloud-system security controls.

• Experience with risk-management tools, including JCAM (formerly CSAM).

• Proficiency with Microsoft Word, Excel, PowerPoint, Visio, Teams, Tableau, and SharePoint.

• Ability to manage multiple concurrent priorities.

• Must possess or be able to obtain a DOT Public Trust clearance.

• Must satisfy all applicable Cherokee Federal, Government, and DOT personnel-security and background-screening requirements.

• Must pass pre-employment qualifications of Cherokee Federal.

Company Information:

Criterion is a part of Cherokee Federal – the division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted partner for more than 60 federal clients, Cherokee Federal LLCs are focused on building a brighter future, solving complex challenges, and serving the government’s mission with compassion and heart.

#CherokeeFederal #LI-SM2 #AppC

Cherokee Federal is a military friendly employer. Veterans and active military transitioning to civilian status are encouraged to apply.

Similar searchable job titles:

• Senior Information System Security Specialist
• Information System Security Officer (ISSO)
• Cybersecurity Project Manager
• Senior Cybersecurity Specialist
• Information Security Project Lead

Keywords:

• Cybersecurity
• Information System Security
• Project Management
• Risk Management Framework (RMF)
• Vulnerability Management

Legal Disclaimer:

All qualified applicants will receive consideration for employment without regard to protected veteran status, disability or any other status protected under applicable federal, state or local law.

Many of our job openings require access to government buildings or military installations.

Similar Jobs

An Hour Ago
In-Office or Remote
71K-183K Annually
Senior level
71K-183K Annually
Senior level
Information Technology • Internet of Things • Mobile • On-Demand • Software
Leads Risk & Resilience advisory pursuits and client engagements, including portfolio oversight, executive advising, solution shaping, SOW and pricing governance, delivery quality, and practice development. Partners with sales and technical experts to translate enterprise risk, cybersecurity, cloud, AI, compliance, and resilience challenges into actionable strategies and commercial solutions. Oversees engagement health, mentors teams, develops repeatable offerings, and supports growth of the advisory practice.
Top Skills: Artificial IntelligenceAWSCloud ComputingCybersecurityGCPAzureVMware
An Hour Ago
Remote or Hybrid
113K-193K Annually
Mid level
113K-193K Annually
Mid level
Artificial Intelligence • Big Data • Healthtech • Information Technology • Machine Learning • Software • Analytics
Designs, deploys, and integrates threat intelligence platforms and data pipelines; enriches and normalizes IOCs; integrates TIPs with SIEM, EDR, NDR, and SOAR; builds automated detection, enrichment, and response playbooks; leverages LLM/agentic AI for intelligence delivery; supports CTI, SOC, IR, threat hunting, and other SecOps stakeholders to improve detection fidelity and reduce response time.
Top Skills: Active DirectoryAnomaliAWSBashCentosCi/CdDockerEdrElasticElasticsearchGitGoIbm QradarJavaJavascript/Node.JsJSONKafkaKali)Linux (UbuntuLlmMac Os XMcp ServerMicrosoft SentinelMispNdrOpenctiPowershellPythonRagRest ApisRhelSIEMSoar (Cortex XsoarSparkSplunkSplunk SoarStixSwimlaneTaxiiThreatconnectTines)Windows Server
2 Hours Ago
Remote or Hybrid
US
128K-193K Annually
Expert/Leader
128K-193K Annually
Expert/Leader
Information Technology
Designs and delivers Snowflake data architectures on AWS, including dbt-based data engineering and AI-enabled solutions. Leads RAG, vector search, embedding, semantic search, and analytics initiatives from proof of concept through production. Directs project teams, oversees solution quality and budgets, supports proposals and business cases, and serves as a trusted technical advisor to clients. Requires strong data engineering, governance, documentation, communication, and stakeholder-management skills, with travel as needed.
Top Skills: AWSDbtEmbedding PipelinesGenerative AiPrompt OrchestrationRetrieval-Augmented GenerationSemantic SearchSnowflakeSQLVector Search

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account