Information Security Policy Analyst Senior

Expert In Recruitment Solutions

  • Durham, NC
  • 3 days ago
  • Remote

    Highlights

    The analyst will also support Authorization to Operate (ATO) activities for research-related systems, including coordinating RMF Steps 0–6, preparing and maintaining security documentation, analyzing authorization artifacts, identifying gaps, and supporting lifecycle compliance for specialized research environments and devices. This role develops and refines research cybersecurity policies, evaluates clinical trial security requirements, responds to Requests for Information (RFIs) from research partners, and provides guidance to ensure veterans' sensitive data is properly protected.

    Numbers & Facts

    LocationDurham, NC (
    Remote
    )

    Description

    The Senior Information Security Policy Analyst supports VA research programs by conducting information security reviews of research systems, clinical studies, scientific computing devices, and research protocols.
    This role develops and refines research cybersecurity policies, evaluates clinical trial security requirements, responds to Requests for Information (RFIs) from research partners, and provides guidance to ensure veterans' sensitive data is properly protected.
    The analyst performs modified risk assessments, develops security reports and Standard Operating Procedures (SOPs), and provides training on research-focused cybersecurity practices in alignment with VA Handbooks, Directives, and NIST guidance.
    The analyst will also support Authorization to Operate (ATO) activities for research-related systems, including coordinating RMF Steps 0–6, preparing and maintaining security documentation, analyzing authorization artifacts, identifying gaps, and supporting lifecycle compliance for specialized research environments and devices.

    Must Have:
    5+ years of experience developing or applying cybersecurity policies using NIST SP 800-37 and SP 800-53
    Experience conducting information security reviews for research systems, studies, or scientific computing environments
    Experience supporting RMF and FISMA compliance and creating/maintaining system authorization artifacts
    Ability to respond to cybersecurity RFIs using VA Handbooks, Directives, and NIST guidance
    Strong written and verbal communication skills for both technical and non-technical audiences
    Risk analysis, gap assessment, and vulnerability evaluation skills
    Ability to manage large volumes of documentation and data
    Ability to obtain and maintain a Public Trust or Suitability/Fitness determination
    Bachelor's degree in a technical field and 10 years of experience, or 8 years of experience in lieu of a degree

    Nice to Have:
    Professional certifications such as CAP, CISSP, CISM, PMP, or CCSK
    Knowledge of VHA Research & Development Policies (Handbook 1200), VA 6500 series, HIPAA, and research security requirements
    Experience with specialized research devices, scientific computing environments, or operational technology
    Experience supporting Client for specialized or nontraditional systems
    ServiceNow CAM experience
    Customer service skills and the ability to work in a dynamic, fast-paced environment
    Previous experience working with the VA

    Similar Jobs