Senior ISSO Security Analyst

IronArch Technology
United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Cloud Engineering Cyber Security Information Systems Information Security Management Software Engineering Enterprise Software Applications SARS Software Products Cloud Platform System Information Technology Servicenow

Job description

As a trusted cybersecurity advisor, you will work closely with VA Information System Owners (ISOs), Information System Security Officers (ISSOs), system administrators, site managers, engineers, and executive stakeholders to guide systems through the full RMF lifecycle while ensuring compliance with Federal cybersecurity requirements.

You will ensure the appropriate operational security posture is maintained throughout the information system lifecycle-from system acquisition and implementation through production operations and eventual decommissioning. You’ll develop and maintain comprehensive security documentation, coordinate authorization activities, identify security risks, and provide expert recommendations that enable secure deployment of enterprise IT systems.

You will also serve as a subject matter expert on VA authorization policies, NIST security controls, FISMA compliance, and cybersecurity best practices while helping clients translate complex security requirements into practical, risk-based solutions.

Work Location: Remote (U.S.-based). Occasional travel to VA or customer locations may be required for meetings, security reviews, or program activities.

Key Responsibilities

Risk Management Framework (RMF) & Authorization Support

  • Lead and coordinate RMF Steps 0-6 activities supporting Authorization to Operate (ATO) packages.
  • Support Information System Owners (ISOs), ISSOs, and system stakeholders throughout the authorization lifecycle.
  • Ensure compliance with VA cybersecurity policies, FISMA, NIST, and agency authorization requirements.
  • Support system authorizations, continuous monitoring, and annual security assessments.
  • Track authorization milestones, documentation updates, and artifact expiration dates across multiple systems.

Security Documentation & Compliance

  • Develop, review, and maintain System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action & Milestones (POA&Ms), Security Impact Analyses (SIAs), and other RMF artifacts.
  • Document NIST SP 800-53 security control implementations and validate compliance.
  • Analyze authorization packages to identify deficiencies and coordinate remediation activities.
  • Maintain accurate and audit-ready security documentation throughout the system lifecycle.

Risk Assessment & Security Advisory

  • Identify cybersecurity risks associated with system implementations, upgrades, and operational environments.
  • Develop mitigation strategies in collaboration with technical and business stakeholders.
  • Provide security guidance for system installations, major changes, cloud implementations, and software development efforts.
  • Present security findings, recommendations, and authorization status to government leadership and technical teams.

Client Engagement & Collaboration

  • Serve as the primary cybersecurity advisor for assigned systems.
  • Independently lead customer meetings involving RMF, ATO, security compliance, and authorization readiness.
  • Collaborate with engineers, developers, project managers, system owners, and cybersecurity teams to ensure successful authorization outcomes.
  • Translate technical cybersecurity concepts into actionable recommendations for both technical and non-technical audiences.

Continuous Improvement

  • Support Continuous Authorization and Monitoring (CAM) initiatives.
  • Recommend process improvements that streamline authorization activities and strengthen cybersecurity posture.
  • Stay current on evolving VA cybersecurity guidance, NIST publications, Executive Orders, and Federal security requirements.

Requirements

  • Master’s degree in Computer Science, Cybersecurity, Information Technology, Electronics Engineering, or a related field with 10+ years of professional IT experience; or
  • 20+ years of Information Technology experience in lieu of a degree.
  • Extensive experience supporting all RMF lifecycle activities (Steps 0-6).
  • Experience creating, updating, and maintaining FISMA security documentation and RMF artifacts.
  • Strong knowledge of NIST SP 800-53 security controls, Risk Management Framework (RMF), FISMA, and Federal cybersecurity compliance requirements.
  • Experience planning secure product implementations, system major changes, and development lifecycle security activities.
  • Experience analyzing authorization documentation, identifying authorization gaps, and coordinating remediation efforts.
  • Demonstrated ability to independently lead client-facing meetings and present complex cybersecurity and ATO topics.
  • Strong organizational skills with the ability to manage multiple authorization packages, documentation sets, and project timelines simultaneously.
  • Ability to obtain and maintain a VA Public Trust Clearance.

AI Capabilities

  • Experience using AI-assisted tools responsibly to improve cybersecurity documentation, security assessments, risk analysis, and operational efficiency.
  • Familiarity with evaluating AI-enabled cybersecurity capabilities while ensuring compliance with Federal security and privacy requirements.

Clearance Requirements

  • U.S. Citizenship is required.
  • Ability to obtain and maintain a VA Public Trust Clearance.
  • Candidates with an active VA Public Trust, current Federal Public Trust, or recently completed VA background investigation are strongly preferred, as they can significantly reduce onboarding timelines.

Preferred Experience

  • Prior experience supporting the U.S. Department of Veterans Affairs (VA) is strongly preferred.
  • Experience supporting Continuous Authorization and Monitoring (CAM).
  • Experience supporting Authorization to Operate (ATO) packages for specialized devices, enterprise applications, or cloud environments.
  • Experience with the VA Enterprise Cybersecurity Program (ECP) and VA Risk Management Framework (RMF) processes.
  • Experience using VA security tools such as eMASS, Archer, and ServiceNow.
  • Ability to effectively communicate with technical teams, executive leadership, and government stakeholders.
  • Excellent written, verbal, and presentation communication skills.
  • Professional certifications such as CISSP, CAP, Security+, CASP+, CISM, GSLC, or equivalent.
  • Active VA Public Trust or recently adjudicated Federal Public Trust is highly desirable.

Benefits & conditions

Pulled from the full job description

  • Professional development assistance
  • Pet insurance
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance
  • Paid jury duty, Why IronArch Technology?
  • Awarded Best Place to Work 9 times!
  • Competitive compensation and market-leading bonus opportunities
  • Medical, dental and vision benefits where a significant portion of the premium is subsidized by IronArch. For qualifying high-deductible health plans, IronArch also contributes towards a Health Reimbursement Account to cover eligible medical expenses
  • Company-provided healthcare concierge assistance to help explain your coverage in plain language; help you find, choose, and schedule quality care; and address billing, benefit, or claims concerns, potentially saving hours of your time
  • 401(k) retirement plan where the company contributes dollar for dollar up to 3 percent, and 50 cents on the dollar for the 4th and 5th percent with immediate entry and immediate vesting
  • 20 days of PTO accumulated per calendar year
  • 11paid holidays
  • Bereavement, jury duty, parental (maternity/paternity/adoption), and military leaves
  • Sabbatical programs
  • Company-paid short- and long-term disability
  • Company-paid life insurance
  • Voluntary life, accidental and indemnity income replacement benefits
  • Professional development reimbursement
  • Health club reimbursement
  • Matching donation program and annual philanthropic activities
  • Pet insurance
  • And more!

Apply today to learn why IronArch Technology has been recognized as “Best Place to Work” for 9 years!

IronArch Technology is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law.

In alignment with applicable state and local pay transparency laws, IronArch includes a salary range in our job descriptions to support equity and transparency in our hiring process. The compensation range provided reflects what we reasonably expect to offer for this role, with the final offer determined by a variety of factors including skills, experience, and scope of responsibilities.

About the company

Known for being a Best Place to Work and a People First company, IronArch Technology is an award-winning Service-Disabled Veteran-Owned Small Business (SDVOSB) specializing in providing innovative solutions and world class services to Federal Government clients.

Our employees have voted us as a ‘Best Place to Work’ 9 times and we are an INC 5000 recipient for being one of the fastest growing businesses in the United States.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:23 min

Closing thoughts and educational resources for edge network engineering

Austin Gil · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

1:29 min

Recommended community resources for cloud engineers

Piet Van Dongen · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all