
Security Analyst
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Assist in the ongoing management of the VA.gov Platform Authority to Operate (ATO) and related continuous monitoring efforts.
• Create, maintain, and coordinate security and privacy documentation necessary for supporting the Platform's authorization boundary.
• Facilitate updates to Privacy Threshold Analyses (PTAs), Privacy Impact Assessments (PIAs), Business Impact Analyses (BIAs), system boundary diagrams, architecture diagrams, threat models, and other relevant security documentation.
• Aid in the development and upkeep of Memoranda of Understanding/Interconnection Security Agreements (MOU/ISAs) for system integrations.
• Assess proposed changes to systems and architectures to evaluate their potential security and ATO implications.
• Collaborate with government security stakeholders and Authorizing Official Designated Representatives (AODRs) to confirm security requirements and identify when further security reviews are necessary.
• Support security evaluations, audits, evidence collection, and remediation efforts.
• Ensure precise documentation and evidence reflecting the implementation of relevant security controls.
• Act as a security resource for engineers, product teams, and Platform stakeholders.
• Convert complex federal security requirements into straightforward, actionable engineering directions.
• Work together with government security stakeholders, engineering teams, and other security subject matter experts to address security and compliance challenges.
• Keep clear and accurate security documentation, decision records, procedures, and implementation guidance.
• Engage in Agile ceremonies, security planning activities, architecture evaluations, and cross-team Platform initiatives.
• Must be a U.S. Citizen or Permanent Resident (Required).
• Capability to obtain and maintain a Public Trust clearance.
• Bachelor’s Degree.
• A minimum of 4 years of experience in cybersecurity, information security, security engineering, security compliance, or a related technical discipline.
• In-depth knowledge of federal cybersecurity requirements and risk management principles.
• Experience in supporting security assessments, authorization processes, compliance reviews, or continuous monitoring.
• Familiarity with NIST security controls and federal security frameworks.
• Proven experience in evaluating technical architectures, system integrations, data flows, and security risks.
• Understanding of Identity and Access Management concepts including authentication, authorization, identity lifecycle, roles, least privilege, separation of duties, and access management.
• Experience in reviewing, tracking, and assisting in the remediation of security vulnerabilities.
• Knowledge of cloud environments and contemporary software development practices.
• Ability to collaborate closely with engineers to translate security requirements into technical implementation guidance.
• Strong skills in technical documentation and requirements definition.
• Excellent written and verbal communication abilities.
• Capacity to operate independently as a security subject matter expert while effectively collaborating across engineering and product teams.
• Must possess reliable internet service to facilitate effective telecommuting.
• Medical, Dental, and Vision insurance.
• Health Savings Account (when enrolled in an eligible plan) with Company contribution.
• Company-paid Life, Accidental Death, Short-term & Long-term Disability insurance.
• Voluntary Accident, Hospital Indemnity, & Critical Care Insurance.
• Voluntary Medical & Dependent Care Flexible Spending Accounts.
• Accrued Paid Time Off & Company Paid Holidays.
• 401(k) Retirement Plan with Company match.
Vibrant
Solo Network
Zafran Security
The Formula Consulting
Get handpicked remote jobs straight to your inbox weekly.