> Markdown version of [/jobs/ext/1281195-isso-security-analyst](https://www.wearedevelopers.com/jobs/ext/1281195-isso-security-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # ISSO Security Analyst - **Company:** MKS2 Technologies - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $85,000.0 - $90,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Information Security Management, Information Technology, Plan of Action and Milestones - **Published:** July 15, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e6b0bb145a9de8f9 ## About the Role * Experience supporting all RMF steps, security categorizations, creating and updating security artifacts and FISMA security documents, control implementation details, and Plan of Action and Milestones (POA&M) * Experience with National Institute of Standards and Technology (NIST) SP 800-53 security controls, RMF, and system authorizations and security compliance standards and processes * Experience creating plans and approaches for executing product installation securely in accordance with agency authorization policy requirements for system major changes and development lifecycles, while identifying potential risks and working with system stakeholders to create mitigation strategies to reduce or eliminate risks * Experience analyzing authorization documents and associated artifacts against authorization requirements to identify gaps, establish a schedule to address outstanding authorization requirements, and coordinate directly with system stakeholders to address identified gaps in accordance with required deadlines * Ability to independently lead client-facing meetings and present complex ATO topics to the client * Ability to organize, manage, and maintain large amounts of discrete data with various expiration dates across multiple systems simultaneously * Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements * Bachelor's degree in CS or Electronics Engineering and 5+ years of experience in information technology or 13+ years of experience in information technology in lieu of a degree Nice If You Have: * Experience with Continuous Authorization and Monitoring (CAM) * Experience working with the VA * Experience supporting ATOs for specialized devices * Ability to engage with varying levels of staff and leadership * Possession of excellent verbal and written communication skills ## Description As a Security Analyst on our team, you'll use your experience to work with Veterans Affairs (VA) Information System Owners (ISO), Information System Security Officers (ISSO), site managers, and other system stakeholders to coordinate and drive the completion of Risk Management Framework (RMF) steps 0-6 ATO activities and requirements, identify and mitigate risks, escalate project risks to leadership, understand and apply VA authorization policies and processes, and provide information system security expertise. You'll ensure the appropriate operational security posture is maintained for information systems throughout the system's lifecycle from product acquisition and installation through decommission. You will complete and maintain very detailed security documentation and coordinate to execute ATO support duties that document security details related to system installations, a variety of IT systems, networks, hardware, and software in a variety of complex and simple installation sites. You'll work with your client to translate security concepts into actionable, implementable solution recommendations to help the client make informed security decisions from all aspects of IT deployments ensuring full commissioning is completed through deployment into production and decommissioning. This is your opportunity to act as an information security and RMF subject matter expert while broadening your skills in cybersecurity. ## Related Videos - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Demystifying Crypto & Web3: A Technical Journey Through 15 Years of Innovation](https://www.wearedevelopers.com/videos/1516-demystifying-crypto-web3-a-technical-journey-through-15-years-of-innovation) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)