The Senior Information Security Policy Analyst supports VA research programs by conducting information security reviews of research systems, clinical studies, scientific computing devices, and research protocols.
This role develops and refines research cybersecurity policies, evaluates clinical trial security requirements, responds to Requests for Information (RFIs) from research partners, and provides guidance to ensure veterans' sensitive data is properly protected.
The analyst performs modified risk assessments, develops security reports and Standard Operating Procedures (SOPs), and provides training on research-focused cybersecurity practices in alignment with VA Handbooks, Directives, and NIST guidance.
The analyst will also support Authorization to Operate (ATO) activities for research-related systems, including coordinating RMF Steps 0–6, preparing and maintaining security documentation, analyzing authorization artifacts, identifying gaps, and supporting lifecycle compliance for specialized research environments and devices.
Must Have:
5+ years of experience developing or applying cybersecurity policies using NIST SP 800-37 and SP 800-53
Experience conducting information security reviews for research systems, studies, or scientific computing environments
Experience supporting RMF and FISMA compliance and creating/maintaining system authorization artifacts
Ability to respond to cybersecurity RFIs using VA Handbooks, Directives, and NIST guidance
Strong written and verbal communication skills for both technical and non-technical audiences
Risk analysis, gap assessment, and vulnerability evaluation skills
Ability to manage large volumes of documentation and data
Ability to obtain and maintain a Public Trust or Suitability/Fitness determination
Bachelor's degree in a technical field and 10 years of experience, or 8 years of experience in lieu of a degree
Nice to Have:
Professional certifications such as CAP, CISSP, CISM, PMP, or CCSK
Knowledge of VHA Research & Development Policies (Handbook 1200), VA 6500 series, HIPAA, and research security requirements
Experience with specialized research devices, scientific computing environments, or operational technology
Experience supporting Client for specialized or nontraditional systems
ServiceNow CAM experience
Customer service skills and the ability to work in a dynamic, fast-paced environment
Previous experience working with the VA