ISSO Security Analyst
As a security analyst on our team, you’ll use your experience to work with Veterans Affairs (VA) Information System Owners (ISO), Information System Security Officers (ISSO), site managers, and other system stakeholders to coordinate and drive the completion of Risk Management Framework (RMF) steps 0-6 ATO activities and requirements, identify and mitigate risks, escalate project risks to leadership, understand and apply VA authorization policies and processes, and provide information system security expertise. You'll ensure the appropriate operational security posture is maintained for information systems throughout the system’s lifecycle from product acquisition and installation through decommission.
You will complete and maintain very detailed security documentation and coordinate to execute ATO support duties that document security details related to system installations, a variety of IT systems, networks, hardware, and software in a variety of complex and simple installation sites. You’ll work with your client to translate security concepts into actionable implementable solution recommendations to help the client make informed security decisions from all aspects of IT deployments ensuring full commissioning is completed through deployment into production and decommissioning. This is your opportunity to act as an information system security and RMF subject matter expert while broadening your skills in cybersecurity. Due to the nature of work performed within this facility, U.S. citizenship is required.
Responsibilities
- Support all RMF steps, including security categorizations, creating and updating security artifacts and FISMA security documents, control implementation details, and Plan of Action and Milestones (POA&M)
- Apply National Institute of Standards and Technology (NIST) SP 800-53 security controls, RMF, and system authorizations and security compliance standards and processes
- Create plans and approaches for executing product installation securely in accordance with agency authorization policy requirements for system major changes and development lifecycles while identifying potential risks and working with system stakeholders to create mitigation strategies
- Analyze authorization documents and associated artifacts against authorization requirements to identify gaps, establish a schedule to address outstanding authorization requirements, and coordinate directly with system stakeholders to address identified gaps in accordance with required deadlines
- Independently lead client-facing meetings and present complex ATO topics to the client
- Organize, manage, and maintain large amounts of discrete data with various expiration dates across multiple systems simultaneously
Requirements
- Bachelor’s degree in Computer Science or Electronics Engineering and 5+ years of experience in information technology, or 13+ years of experience in information technology in lieu of a degree
- Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements
- U.S. citizenship
Nice to Have
- Experience with Continuous Authorization and Monitoring (CAM)
- Experience working with the VA
- Experience supporting ATOs for specialized devices
- Ability to engage with varying levels of staff and leadership
- Excellent verbal and written communication skills
Benefits
- Health, life, disability, financial, and retirement benefits
- Paid leave, professional development, tuition assistance, work-life programs, and dependent care
- Recognition awards program for exceptional performance and superior demonstration of company values
Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen’s benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits.
Pay
The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). Salary is determined by various factors, including but not limited to location, the individual’s particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements.
Schedule
This posting will close within 90 days from the posting date.
Work models include:
- Remote: Generally expected to have cameras on during meetings. May require occasional in-person work at a Booz Allen or customer facility.
- Hybrid: Expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and role needs. May also require work from or visits to a customer facility.
- Onsite: Work primarily performed at a Booz Allen office or customer facility, collaborating directly with colleagues and customers as required by the role.