Security Analyst
Posted 1ds ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Security Analyst supporting Sprezzatura’s secure VA.gov Platform and federal ATO lifecycle. Translating cybersecurity requirements into engineering guidance, documentation, assessments, and compliance actions.
Responsibilities:
- Support the ongoing VA.gov Platform Authority to Operate (ATO) and associated continuous monitoring activities
- Develop, maintain, and coordinate security and privacy artifacts required to support the Platform authorization boundary
- Support updates to Privacy Threshold Analyses (PTAs), Privacy Impact Assessments (PIAs), Business Impact Analyses (BIAs), system boundary diagrams, architecture diagrams, threat models, and related security documentation
- Support creation and maintenance of Memoranda of Understanding/Interconnection Security Agreements (MOU/ISAs) for system-to-system integrations
- Evaluate proposed system and architecture changes to determine potential security and ATO impacts
- Coordinate with government security stakeholders and Authorizing Official Designated Representatives (AODRs) to validate security requirements and determine when additional security review is required
- Support security assessments, audits, evidence collection, and remediation activities
- Maintain accurate documentation and evidence demonstrating implementation of applicable security controls
- Serve as a security resource for engineers, product teams, and Platform stakeholders
- Translate complex federal security requirements into clear, actionable engineering guidance
- Collaborate with government security stakeholders, engineering teams, and other security SMEs to resolve security and compliance issues
- Maintain clear and accurate security documentation, decision records, procedures, and implementation guidance
- Participate in Agile ceremonies, security planning activities, architecture reviews, and cross-team Platform initiatives
Requirements:
- U.S. Citizen or Permanent Resident (Required)
- Ability to obtain and maintain a Public Trust clearance
- Bachelor’s Degree
- 4+ years of experience in cybersecurity, information security, security engineering, security compliance, or a related technical field
- Strong understanding of federal cybersecurity requirements and risk-management principles
- Experience supporting security assessments, authorization activities, compliance reviews, or continuous monitoring
- Working knowledge of NIST security controls and federal security frameworks
- Experience assessing technical architectures, system integrations, data flows, and security risks
- Understanding of Identity and Access Management concepts including authentication, authorization, identity lifecycle, roles, least privilege, separation of duties, and access management
- Experience reviewing, tracking, and supporting remediation of security vulnerabilities
- Familiarity with cloud environments and modern software development practices
- Ability to work directly with engineers to translate security requirements into technical implementation guidance
- Strong technical documentation and requirements-definition skills
- Excellent written and verbal communication skills
- Ability to operate independently as a security subject matter expert while collaborating effectively across engineering and product teams
- Must have reliable internet service that allows for effective telecommuting
Benefits:
- Medical, Dental, and Vision
- Health Saving Account (when enrolled in eligible plan) with Company contribution
- Company paid Life, Accidental Death, Short-term & Long-term Disability
- Voluntary Accident, Hospital Indemnity, & Critical Care Insurance
- Voluntary Medical & Dependent Care Flexible Spending Accounts
- Accrued Paid Time Off & Company Paid Holidays
- 401(k) Retirement Plan with Company match



















