DFC - Program Manager

Remote
Full Time
DFC - ISSO
Experienced
cFocus Software seeks a Program Manager to join our program supporting the United States International Defense Finance Agency (DFC). This position is remote. This position requires an Active Public Trust clearance.
Qualifications:
  • Active Public Trust clearance
  • B.S. Computer Science, Information Technology, or a related field
  • 10+ years of progressively responsible program or project management experience, including at least five years leading federal IT or cybersecurity service-delivery programs of comparable scope and complexity.
  • Demonstrated experience managing staffing, schedules, risk and issue registers, quality assurance, service levels, deliverables, financial/burn-rate reporting, invoicing support, and subcontractor performance.
  • Experience developing and maintaining program management, communications, quality, staffing, training, and transition plans for Government review.
  • Experience producing executive briefings and recurring performance reports supported by accurate, auditable, and traceable data.
  • Strong knowledge of federal cybersecurity program operations and working familiarity with FISMA, OMB Circular A-130, the NIST Risk Management Framework, NIST SP 800-39, NIST SP 800-30, continuous monitoring, ATO processes, POA&M management, audit readiness, and federal records requirements.
  • Ability to coordinate effectively with senior federal officials, technical teams, system owners, auditors, privacy and records stakeholders, and multiple contractor organizations while respecting inherently governmental decision authorities.
  • U.S. citizenship and eligibility for, and ability to obtain and maintain, a Tier 4 High-Risk Public Trust background investigation and required DFC access approvals.
  • Active Project Management Professional (PMP) certification
  • Experience managing federal ISSO, RMF, security compliance, continuous monitoring, vulnerability management, incident response coordination, or cybersecurity audit-support programs.
  • Working familiarity with ServiceNow, CSAM or a comparable federal GRC platform, Splunk, vulnerability scanning tools such as Tenable or Qualys, and Microsoft security/cloud services.
  • Experience with hybrid and Zero Trust-aligned environments that include Microsoft 365, Azure Government, Entra ID, Okta, Palo Alto, Zscaler, Cisco, and Aruba technologies.
  • Experience supporting systems that process Controlled Unclassified Information (CUI), Personally Identifiable Information (PII), or other sensitive federal information

Duties:
  • Direct overall contract performance across all PWS task areas and ensure services are properly planned, staffed, coordinated, documented, and delivered in accordance with required outcomes, schedules, SLAs, KPIs, AQLs, and acceptance criteria.
  • Lead contract kickoff activities and develop the Program Management Plan (PMP) within 10 business days of award; maintain the PMP as a living document and submit material updates for Government review and approval before implementation.
  • Establish the program governance structure, lines of authority, communications and escalation paths, internal controls, action-item discipline, and coordination model with the COR and Government-designated technical stakeholders.
  • Coordinate contract-level matters with the Lead ISSO, including staffing, reporting, invoicing, performance concerns, risk escalation, continuity of operations, and changes affecting scope or service delivery.
  • Ensure Contractor activities support DFC cybersecurity objectives while preserving Government authority for authorization decisions, risk acceptance, policy determinations, and other inherently governmental functions
  • Serve as the primary operational liaison between Contractor management and DFC OIT cybersecurity leadership for program performance, priorities, deliverables, staffing, risks, and corrective actions.
  • Coordinate with the COR, CISO, Government-designated ISSM, federal ISSOs, AO/AODR, System Owners, Common Control Providers, Privacy Office, Records personnel, auditors, and other designated stakeholders.
  • Coordinate within scope with DFC’s Enterprise IT Operations, Security Operations Center (SOC), Application Development, cloud, infrastructure, and other contractor teams.
  • Support governance forums—including the Enterprise Review Board, Change Control Board, Cybersecurity Steering Committee, Risk Management Working Group, Privacy Working Group, and other designated bodies—with timely metrics, dashboards, briefings, recommendations, and decision-support materials.
  • Develop and execute a Communications Plan covering incident escalation, stakeholder updates, SIA/change communications, maintenance and ConMon notifications, authorization milestones, governance reporting, executive briefings, and RCA communications.
  • Implement a risk and issue management process aligned with NIST SP 800-39, NIST SP 800-30, and DFC OIT policy.
  • Maintain a current Risk Register covering cybersecurity, programmatic, staffing, schedule, vendor, dependency, and supply-chain risks, including impact, likelihood, mitigation, ownership, status, escalation path, and target closure date.
  • Maintain the Issue and Action Item Log from identification through evidence-based closure; escalate issues that may affect security posture, authorization, audit readiness, operations, service levels, or contract performance.
  • Manage integrated schedules, milestones, dependencies, deliverable due dates, staffing actions, and transition activities; identify emerging risks early enough to support informed Government decisions.
  • Track labor usage and burn rate by labor category and individual position, support invoice validation, monitor funding status, and provide accurate funding forecasts
  • Submit the Weekly Activity Report each Friday by close of business, summarizing work performed, issues, planned activities, and identified risks.
  • Submit the Monthly Program Status Report by the fifth business day, including contract performance, SLA/KPI results, staffing, risks and issues, mitigation actions, upcoming activities, burn rate, and funding forecasts.
  • Prepare the Quarterly Executive Review Briefing at least five business days before the scheduled review, presenting performance and cybersecurity posture trends, top risks, significant issues, and Contractor recommendations.
  • Maintain version-controlled, traceable, audit-ready program artifacts—including the PMP, Communications Plan, QMP, Risk Register, Issue and Action Item Log, Staffing Plan, Training Plan, Transition Plans, standard operating procedures, and runbooks—in Government-designated repositories.
  • Plan and execute transition-in and transition-out activities, including knowledge transfer, tool/repository orientation, documentation and status validation, open-risk review, deliverable schedule review, and coordination with incumbent or successor personnel.
Share

Apply for this position

Required*
We've received your resume. Click here to update it.
Attach resume as .pdf, .doc, .docx, .odt, .txt, or .rtf (limit 5MB) or Paste resume

Paste your resume here or Attach resume file

To comply with government Equal Employment Opportunity and/or Affirmative Action reporting regulations, we are requesting (but NOT requiring) that you enter this personal data. This information will not be used in connection with any employment decisions, and will be used solely as permitted by state and federal law. Your voluntary cooperation would be appreciated. Learn more.

Invitation for Job Applicants to Self-Identify as a U.S. Veteran
  • A “disabled veteran” is one of the following:
    • a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or
    • a person who was discharged or released from active duty because of a service-connected disability.
  • A “recently separated veteran” means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.
  • An “active duty wartime or campaign badge veteran” means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.
  • An “Armed forces service medal veteran” means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.
Veteran status



Voluntary Self-Identification of Disability
Voluntary Self-Identification of Disability Form CC-305
OMB Control Number 1250-0005
Expires 05/31/2026
Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Please check one of the boxes below:

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

You must enter your name and date
Human Check*