02 Aug
|
id4 consultancy
|
India
02 Aug
id4 consultancy
India
Technical Project Manager (Security & Compliance)
Education:
Bachelor’s / Master’s degree in Computer science and Engineering / Computer Applications / Information Technology OR equivalent.
Certification: CISA / ISACA, PMP / PMI-ACP is mandatory.
Brief description of Role:
Looking for a candidate to modernize the vulnerability management program in-compliance with the FedRAMP 2026 Vulnerability Detection & Response (VDR) and Vulnerability Evaluation & Reporting (VER), which become mandatory on Dec 7, 2026 under CISA BOD 26-04. This is a high-visibility, deadline-driven program touching security engineering, DevOps, GRC, and executive stakeholders.
The Technical Project Manager serves as the connective tissue across all workstreams — an overlay resource who keeps four specialized engineers, internal platform teams, and business stakeholders aligned and moving toward a fixed regulatory deadline.
Key responsibilities:
❖ Own day-to-day program management for a ~16-week implementation with a fixed, non-negotiable compliance cutover date
❖ Serve as the primary liaison between the implementation team, internal security/platform/DevOps teams, and business stakeholders; run weekly steering sessions and executive readouts
❖ Build and maintain the integrated project plan across two parallel workstreams (platform/integration build and evaluation/reporting/controls), tracking dependencies, milestones, and the critical path to the deadline
❖ Track SLAs, risks, and blockers; escalate early and drive resolution across indirect reporting teams.
❖ Coordinate access, environments, change windows, and internal approvals so engineers stay unblocked.
❖ Manage scope against the ~22 VDR/VER requirements; maintain a control-to-requirement traceability view.
❖ Coordinate the parallel-run and cutover from the legacy scanning toolchain to the recent consolidated platform, including training and handoff to internal teams.
❖ Prepare status reporting suitable for both engineering audiences and executive/audit audiences.
Mandatory Skills:
❖ Minimum 6+ years of technical project/program management experience delivering infrastructure, security, or platform engineering projects
❖ Demonstrated success delivering projects with hard external deadlines (regulatory, contractual, or launch-driven)
❖ Ability to work fluently with engineers - comfortable discussing CI/CD pipelines, API integrations, cloud environments and scanning tools at a working level
❖ Strong stakeholder management: experience aligning security, engineering, and business leadership with competing priorities
❖ Excellent risk management; a track record of surfacing problems weeks before they become schedule threats
❖ Direct experience with FedRAMP programs (ATO processes, 3PAO assessments, continuous monitoring, POA&M; management) or other federal compliance frameworks (FISMA, CMMC, StateRAMP)
❖ Prior delivery of security tooling implementations (vulnerability management, SIEM, CNAPP, ASPM/aggregation platforms)
❖ Familiarity with the 2026 FedRAMP VDR / VER rule changes and CISA BOD 26-04
❖ Experience running hybrid onshore/offshore delivery teams
Soft Skills:
- Excellent problem-solving skills, with a keen attention to detail.
- Effective communication skills – written, spoken, listening and presentation.
- Great Team player and experience working with global teams and global organizations.
- Genuine interest in learning and knowledge sharing
- Strong collaboration and communication skills, with experience working in cross-functional teams.
📌 Technical Project Manager (Security & Compliance) -Contract (India)
🏢 id4 consultancy
📍 India