Project Manager (Freelance) — Identity, Authentication & e-Signature SaaS

Job ID: 39735225

Budget: $5 – $40 USD

Mode: Remote · Commitment: ~20 hours/week · Initial term: 8–12 weeks (extendable)
Time zone: EU-friendly overlap preferred · Start: ASAP

Role Summary

We’re hiring a Project Manager / Technical Program Manager to orchestrate multiple parallel workstreams for a SaaS platform in digital identity, advanced authentication (passkeys/WebAuthn, 2FA/OTP), NFC, electronic signatures (PKI/HSM/QSCD), and cloud infrastructure (AWS + Terraform + Kubernetes).
Immediate focus: planning, execution, and audit-grade traceability for ISO 27001 readiness and trust-services standards, while coordinating vendors and distributed engineering teams.

Key Responsibilities
• Master Plan & PMO: Build and maintain WBS, schedule, critical path, dependencies, milestones, and executive reporting (RAG, SPI/CPI).
• Delivery Governance: Set cadences, Definition of Done, change control, and release coordination across CI/CD environments.
• Evidence Factory / Compliance: Operate a living matrix of requirement → evidence (logs, PRs, screenshots, policies) aligned to ISO 27001 and sector standards (e.g., ETSI/eIDAS).
• Advisors & Auditors Interface: Single point of contact for ISO 27001 readiness and conformity assessments for trust services.
• Technical Workstreams: PKI/HSM/QSCD (key ceremonies), authentication (OIDC, WebAuthn, 2FA), NFC, backend/API, frontend/app, and SRE/observability.
• FinOps: Cost tagging, environment budgets, rightsizing (e.g., RDS/DocDB), scheduled shutdowns, logging policies, and S3 lifecycle; track realized monthly savings.
• Risk & Security: Maintain RAID, BCP/DR drills, vulnerability management and remediation plans.
• Vendors: Run RFP/SOW, negotiate SLAs/DPAs for HSM/QSCD, KYC/IDV, messaging (SMS/e-mail/push), etc.

Requirements (Must-Have)
• 5+ years leading SaaS projects/programs with notable security/compliance scope.
• Hands-on experience with ISO 27001 (ISMS): scoping, risk, SoA, evidence.
• Confident coordinating cloud & platform teams: AWS, Terraform/IaC, Kubernetes/EKS, CI/CD (GitHub Actions or similar).
• Strong documentation skills (WBS, RAID, RACI, runbooks) and stakeholder communication.
• Professional English (written and spoken).

Nice to Have
• Familiarity with ETSI/eIDAS trust services, PKI, HSM/QSCD.
• Experience with passkeys/WebAuthn, 2FA/OTP, NFC, and auth UX.
• Airtable for PMO/DocOps and status dashboards.
• SOC 2, ISO 27701/22301, privacy/DPIA exposure.

30/60/90 Outcomes
• Days 1–14: Master Plan (WBS + schedule), RAID & RACI in place; governance calendar; Evidence Matrix created and 20–30% populated; initial FinOps backlog with ROI.
• Days 15–45: Readiness gates passed; CP/CPS draft (REV A) if applicable; QSCD/HSM PoC closed; ISO 27001 SoA complete; live dashboards for auth/sign/latency/cost.
• Days 46–90: Pre-audit package ready; remote-signature pilots; verified cloud savings; incident & release runbooks consolidated.

Ways of Working
• Cadence: daily stand-ups by workstream; weekly program review with KPIs; weekly CAB for releases; biweekly cost and vendor reviews.
• Program KPIs: % milestones on-time; evidence coverage; p95 login/sign latency; WebAuthn/2FA success rate; verified cloud savings; vulnerability time-to-close.

If this fits your background and availability (~20 h/week), we’d love to talk.