IT Cybersecurity Analyst U.S. Department of State
- $143,913–$187,093
- Full-time
| Location | Manassass, Virginia |
| Job Type | Full-time |
Position Title: ATO Security Analyst (Research)
As an ATO Security Analyst on our team, you'll work with VA to discover and mitigate cybersecurity risks, support responses to requests for information on cyber best practices and support the application of information system security practices to ensure the appropriate information security posture is maintained within VA research projects. You’ll use your ATO experience to work with Veterans Affairs (VA) Information System Owners (ISO), Information System Security Officers (ISSO), site managers, and other system stakeholders to coordinate and drive the completion of Risk Management Framework (RMF) steps 0-6 ATO activities and requirements, identify and mitigate risks, escalate project risks to leadership, understand and apply VA authorization policies and processes and provide information system security expertise to ensure the appropriate operational security posture is maintained for information systems throughout the system’s lifecycle from product acquisition and installation through decommission. You will complete and maintain very detailed security documentation to execute ATO support duties that documents security details related to system installations, a variety of IT systems, networks, hardware and software in a variety of complex and simple installation sites, as applicable.
You Have:
Experience with supporting all RMF steps, security categorizations, creating and updating security artifacts and FISMA security documents, control implementation details, and Plan of Action and Milestones (POA&M)
Experience with National Institute of Standards and Technology (NIST) SP 800-53 security controls, RMF, and system authorizations and security compliance standards and processes
Experience in creating plans and approaches for executing product installation securely in accordance with agency authorization policy requirements for system major changes and development lifecycle while identifying potential risks and working with system stakeholders to create mitigation strategies to reduce or eliminate risks
Analyze authorization documents and associated artifacts against authorization requirements to identify gaps, establish a schedule to address outstanding authorization requirements, and coordinate directly with system stakeholders to address identified gaps in accordance with required deadlines
Excellent oral and written communication skills and the ability to independently lead client-facing meetings and present complex ATO topics to the client
Ability to review and reply to cybersecurity guidance requests from research partners using current VA Handbooks, Directives, and NIST guidance within a standardized timeframe
Ability to organize, manage, and maintain large amounts of discrete data with various expiration dates across multiple systems simultaneously
Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements
Bachelor’s degree in computer science, Electronics Engineering or other Engineering or technical discipline and 5 years of relevant work experience or 13 years of relevant work experience in lieu of degree
Nice If You Have:
Knowledge of: VHA Research and Development Policies, Handbook 1200, VA 6500 Handbooks and Directives, data security and governance, and/or HIPAA
Ability to engage with varying levels of staff/leadership
Experience supporting ATOs for specialized devices