This position is contingent upon contract award.
Wichita Tribal Enterprise, a Quivera Enterprises company, is seeking an experienced InfoSec Engineer III / Project Manager to support the Department of the Interior (DOI), Indian Affairs (IA), Office of Information Technology (OIT). This position provides senior-level cybersecurity engineering and project management leadership supporting enterprise Risk Management Framework (RMF) activities, federal information security compliance, and IT modernization initiatives.
The InfoSec Engineer III / Project Manager is responsible for leading cybersecurity assessments, developing and maintaining system authorization packages, implementing Risk Management Framework (RMF) processes, and providing strategic information assurance guidance while managing one or more federal IT projects. This role oversees project planning, execution, compliance, budget, schedule, deliverables, customer relationships, and technical performance in accordance with the Performance Work Statement (PWS), federal laws, regulations, and Departmental policies.
Working closely with the Contracting Officer's Representative (COR), Federal Task Leads, Associate Chief Information Officer (ACIO) leadership, project managers, and technical teams, this position serves as a trusted advisor on cybersecurity, risk management, and project execution. The successful candidate will possess extensive experience implementing NIST guidance, developing security policies and architectures, managing complex federal IT projects, and ensuring compliance with FISMA, FITARA, NIST SP 800-37, NIST SP 800-53, and other federal cybersecurity requirements while delivering secure, compliant, and mission-focused technology solutions.
Key Responsibilities
Information Security & Risk Management Framework
- Provide multidisciplinary administrative and technical security support for the Indian Affairs Risk Management Framework (RMF) program.
- Lead and support implementation of the NIST Risk Management Framework throughout the system development lifecycle.
- Conduct security assessments and develop all required deliverables associated with system authorization packages.
- Develop, maintain, and review System Security Plans, Security Assessment Plans, Security Assessment Reports, Plans of Action and Milestones, Risk Assessments, Contingency Plans, Configuration Management documentation, and related security authorization artifacts.
- Evaluate and document technical, management, and operational security controls in accordance with NIST SP 800-53, as amended.
- Conduct risk assessments in accordance with NIST guidance and provide risk analysis and recommendations to Associate Chief Information Officer leadership.
- Perform security analysis and assessment across physical, computer, personnel, information, administrative, operational, and communications security domains.
- Identify vulnerabilities, security weaknesses, and compliance deficiencies and develop appropriate mitigation and remediation recommendations.
- Assist senior management with establishing plans of action for remediation of organization-wide cybersecurity weaknesses.
- Provide information assurance guidance related to the development, modification, and operation of information systems and industrial control systems.
- Develop cybersecurity policies, architectures, procedures, standards, and Standard Operating Procedures supporting federal regulations, directives, and Departmental requirements.
- Maintain knowledge of changes to federal cybersecurity regulations, emerging technologies, threats, and industry best practices.
Cybersecurity Strategy & Governance
- Provide strategic guidance supporting continued development and maturation of the Indian Affairs cybersecurity program.
- Recommend integration of security processes across OIT and other organizational offices and divisions to support compliance with federal regulations and Departmental policy.
- Lead security initiatives designed to improve organizational efficiency, strengthen governance, and promote an enterprise-wide security mindset.
- Support integration of cybersecurity requirements throughout the System Development Life Cycle.
- Provide security recommendations concerning new and existing federal IT projects.
- Coordinate with federal agency representatives, commercial organizations, and Subject Matter Experts to remain informed of regulatory, technology, and cybersecurity developments.
- Advise program and executive leadership regarding cybersecurity risks, mitigation strategies, compliance requirements, and security priorities.
Project Management Leadership
- Provide project management leadership and services supporting the goals and objectives of the Performance Work Statement as directed by the Contracting Officer's Representative and Federal Task Lead.
- Manage one or more IT and cybersecurity projects from initiation through implementation, operation, and closeout.
- Oversee project management teams, compliance activities, daily operations, and client/customer relationships.
- Maintain responsibility for the quality, accuracy, completeness, and timeliness of project deliverables.
- Develop, monitor, and report project objectives, milestones, budgets, schedules, risks, dependencies, and overall performance.
- Manage the technical, contractual, administrative, and financial aspects of assigned projects.
- Identify project management issues and risks and develop recommended resolutions in collaboration with appropriate federal stakeholders.
- Ensure assigned projects and services are implemented in accordance with task order requirements, federal laws, regulations, policies, and procedures.
- Apply Project Management Institute principles and PMBOK methodologies to project planning, execution, monitoring, control, and closeout.
- Establish project governance, documentation, reporting structures, and performance measurement processes.
Federal IT Governance & Investment Management
- Apply knowledge of Federal Enterprise Architecture, Capital Planning and Investment Control, System Development Life Cycle, IT Security Management, and Risk Management to assigned initiatives.
- Support federal IT investment management and governance processes.
- Apply federal IT laws, regulations, and requirements including FITARA, the Clinger-Cohen Act, the E-Government Act, and FISMA.
- Review and analyze cost, schedule, risk, and performance requirements associated with federal IT investments.
- Support OMB reporting requirements and align internal project reporting with applicable external federal reporting requirements.
- Apply consistent IT Portfolio Management practices to improve data quality, governance, documentation, and decision-making.
- Support development of business cases, project plans, status reports, executive briefings, risk registers, and other federal IT governance deliverables.
Project Planning, Performance & Risk
- Develop and maintain integrated project plans, schedules, milestones, work breakdown structures, and performance measures.
- Monitor project costs, resource requirements, schedules, deliverables, and technical performance.
- Identify project and cybersecurity risks and maintain appropriate risk registers, mitigation strategies, and escalation processes.
- Coordinate dependencies among cybersecurity, technical, operational, contractual, and business workstreams.
- Provide timely project status, risk, schedule, and performance reporting to federal and contractor leadership.
- Facilitate project meetings, technical reviews, status meetings, risk reviews, and executive briefings.
- Ensure project documentation is accurate, complete, current, and maintained in accordance with federal requirements.
Stakeholder & Team Leadership
- Serve as a primary interface among federal leadership, project managers, cybersecurity personnel, system owners, technical teams, contractors, and other stakeholders.
- Lead multidisciplinary project and security teams while promoting accountability, collaboration, and effective communication.
- Provide technical and project management guidance to team members and stakeholders.
- Communicate complex cybersecurity, project, and risk information to both technical and nontechnical audiences.
- Develop and maintain productive relationships with clients, customers, federal stakeholders, and project team members.
- Facilitate decision-making and issue resolution across organizational and technical boundaries.
Human-Centered Design
- Apply Human-Centered Design approaches to federal IT initiatives when appropriate.
- Utilize techniques such as Journey Mapping, Affinity Mapping, Storyboarding, stakeholder interviews, and facilitated workshops to better understand user needs.
- Incorporate user and stakeholder feedback into project planning, solution development, process improvement, and implementation activities.
Required Qualifications
Education & Experience
One of the following combinations is required:
- Bachelor's degree and at least six years of relevant professional experience; or
- Master's degree and at least five years of relevant professional experience; or
- At least eight years of relevant professional experience in lieu of a degree.
An industry-recognized technical certification may be accepted in lieu of one year of required experience where permitted by the contract.
In addition:
- Minimum of five years of project management experience.
- Minimum of four years of direct, full-time experience conducting security assessments and developing all deliverables associated with system authorization packages.
- Demonstrated experience managing federal IT or cybersecurity projects.
- Demonstrated experience with federal information security and Risk Management Framework activities.
Required Certification
- Project Management Professional (PMP) certification required.
Required Cybersecurity Experience
- Extensive experience implementing the NIST Risk Management Framework.
- Expert-level knowledge of NIST SP 800-53 security controls and assessment requirements.
- Experience developing and maintaining complete system authorization packages.
- Experience conducting risk assessments, security assessments, and vulnerability analyses.
- Experience developing mitigation plans and remediation strategies.
- Knowledge of contingency planning and disaster recovery.
- Experience with configuration management and security configuration requirements.
- Experience developing cybersecurity policies, architectures, standards, and Standard Operating Procedures.
- Experience evaluating and documenting technical, operational, and management security controls.
- Experience integrating cybersecurity requirements throughout the System Development Life Cycle.
- Knowledge of information assurance requirements applicable to information systems and industrial control systems.
Required Project Management Experience
- In-depth knowledge of IT project management principles and practices, including PMI and PMBOK methodologies.
- Experience managing project scope, schedule, cost, resources, risks, quality, and performance.
- Experience managing the technical, contractual, administrative, and financial aspects of projects.
- Experience reviewing and analyzing cost, schedule, and performance requirements for federal IT investments.
- Knowledge of federal IT governance and investment management processes.
- Experience with:
- Federal Enterprise Architecture
- Capital Planning and Investment Control
- System Development Life Cycle
- IT Security Management
- Risk Management
- IT Portfolio Management
- Knowledge of federal IT laws and regulations, including:
- FITARA
- Clinger-Cohen Act of 1996
- Title III of the E-Government Act of 2002
- FISMA
- Knowledge of OMB reporting requirements.
- Experience aligning internal program reporting with federal reporting requirements.
- Ability to develop and maintain project plans, schedules, risk registers, budgets, performance measures, and executive status reports.
- Excellent leadership, verbal communication, written communication, presentation, and stakeholder management skills.
Preferred Qualifications
- Previous experience supporting the Department of the Interior, Indian Affairs, Bureau of Indian Affairs, or other federal civilian agencies.
- Experience supporting federal cybersecurity, governance, risk, and compliance programs.
- Experience serving in a combined cybersecurity and project management leadership role.
- Experience with federal system authorization and Authority to Operate processes.
- Knowledge of GRC platforms and security authorization tools.
- Experience with cloud security, FedRAMP, or federal cloud environments.
- Knowledge of Industrial Control System and Operational Technology security.
- Experience facilitating executive-level cybersecurity and project briefings.
- Experience managing multidisciplinary technical and cybersecurity teams.
Key Knowledge Areas
- NIST Risk Management Framework
- NIST SP 800-53
- Security Assessment & Authorization
- Risk Assessment & Management
- Vulnerability Management
- Security Control Assessment
- System Authorization Packages
- Information Assurance
- FISMA
- Federal IT Governance
- Federal IT Investment Management
- PMBOK
- IT Project Management
- IT Portfolio Management
- FEA
- CPIC
- SDLC
- FITARA
- OMB Reporting
- Configuration Management
- Contingency Planning
- Disaster Recovery
- Cybersecurity Policy Development
- Human-Centered Design
- Journey Mapping
- Affinity Mapping
- Storyboarding
Physical Demands – IT Office/Technical Role
The physical demands described here are representative of those that must be met by an employee, with or without reasonable accommodation.
This role is primarily office-based and requires prolonged computer use, including sitting, typing, and operating standard office equipment. Occasional walking, standing, bending, and reaching may be required to support equipment setup and troubleshooting. The employee must be able to lift up to 15 pounds, with occasional heavier lifting.
The employee must be able to communicate effectively and maintain visual acuity, including close, distance, color, and depth perception. Occasional travel and extended hours may be required to support operational needs and deadlines.
Equal Employment Opportunity
Quivera Enterprises LLC and its subsidiaries are 100% tribally owned and SBA-certified Small Disadvantaged Businesses. We are proud to be an Equal Opportunity Employer and are committed to creating an inclusive workplace where all qualified applicants receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other status protected by applicable federal, state, or local law.
As a tribally owned organization, Quivera Enterprises and its subsidiaries may apply Indian Preference in accordance with applicable tribal, federal, and contractual requirements where authorized by law.
Dream. Grow. Thrive.
