Senior ATO Security Analyst

American Management Group
Manassas, VA, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Shift work
Job source

Tech stack

Cyber Security Information Systems Information Security Management Information Technology

Job description

As a Senior ATO Security Analyst on our team, you’ll use your experience to work with the Veterans Affairs (VA) Information System Owners (ISO) and Information System Security Officers (ISSO) to coordinate and drive the completion of Risk Management Framework (RMF) steps 0-6 ATO activities and requirements, identify and mitigate system cybersecurity risks, escalate project risks to leadership, understand and apply VA authorization policies and processes and provide information system security expertise to ensure the appropriate operational security posture is maintained for information systems. You will complete and maintain very detailed security documentation and coordinate closely with ISOs and ISSOs to execute ATO support duties. You’ll work with your client to translate security concepts into actionable implementable solution recommendations to help the client make informed security decisions. This is your opportunity to act as an information security and RMF subject

Requirements

matter expert while broadening your skills in cybersecurity. This position is open to remote delivery anywhere within the U.S., to include the District of Columbia.

Must Have:

  • Experience proactively and independently managing complex system records in the Enterprise Mission Assurance Support Service (eMASS) tool.

  • Experience with supporting all RMF steps, security categorizations, creating and updating security artifacts and FISMA security documents, control implementation details, and Plan of Action and Milestones (POA&M)

  • Experience with National Institute of Standards and Technology (NIST) SP 800-53 security controls, RMF, and system authorizations and security compliance standards and processes

  • Experience with Federal Information Security Management Act (FISMA) and Federal Information System Controls Audit Manual (FISCAM) criteria

  • Analyze authorization documents and associated artifacts against authorization requirements to identify gaps, establish a schedule to address outstanding authorization requirements, and coordinate directly with system stakeholders to address identified gaps in accordance with required deadlines

  • Excellent oral and written communication skills and the ability to independently lead client-facing meetings and present complex ATO topics to the client

  • Ability to organize, manage, and maintain large amounts of discrete data with various expiration dates across multiple systems simultaneously

Nice to have:

  • Experience working with VA

  • Ability to engage with varying levels of staff/leadership

  • Experience supporting ATOs for specialized devices

Education Requirement:

  • Bachelor’s degree (computer science, electronics engineering or technical discipline is required).

  • 5+ years of related experience

  • 8 years of additional relevant experience may be substituted for education.

About the company

Information Sciences Consulting, Inc. (ISCI), a VA Certified Service-Disabled Veteran-Owned company, has an exciting opportunity for a Senior ATO Security Analyst to join our team in support of the ITOPS endeavor at the US Department of Veteran’s Affairs. This is a fully remote position. Come join our great team in the ongoing effort to strengthen and maintain IT security across the VA network.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on juju.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · WWC Europe 2026

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · WWC Europe 2026

Videos

See all

Related articles

See all