Get more replies from employers
Send a job-specific resume in minutes.
Ironarch Technology LLC is seeking an ATO Security Analyst to support the Department of Veterans Affairs in maintaining cybersecurity compliance across research environments. This critical role involves managing ATO and ATC packages, ensuring systems remain authorized and operational to provide Veterans access to modernized care tools.
The ideal candidate will have hands-on experience with the RMF lifecycle and must be a U.S. citizen capable of obtaining a VA Public Trust. The position offers a remote work option with competitive benefits.
IronArch Technology is looking for an ATO Security Analyst to support the Department of Veterans Affairs in maintaining cybersecurity compliance across VA research environments. This is a documentation-first role. You will own the paperwork that keeps VA systems authorized and running: ATO and ATC packages, security artifacts, POA&Ms, gap analyses, and FISMA documentation.
You'll work directly with VA Information System Owners (ISOs), Information System Security Officers (ISSOs), site managers, and research stakeholders to drive ATO activities from start to finish.
Develop, review, and maintain ATO and ATC packages, including system security plans (SSPs), control implementation statements, FISMA documents, and POA&Ms across a portfolio of VA research systems. Own the tracking and resolution of open POA&M items, keep authorization schedules current, and ensure nothing falls through the cracks.
Support all RMF steps from security categorization through authorization, coordinating directly with VA ISOs, ISSOs, site managers, and system owners to close gaps and hit deadlines. Provide cybersecurity compliance answers to research teams using current VA Handbooks, Directives, and NIST guidance.
Conduct security assessment reviews for VA research submissions, work within the VA’s Continuous Authorization and Monitoring (CAM) framework, and support product installation planning for major system changes. Lead client-facing meetings on ATO topics regularly, walking both technical and non-technical audiences through complex authorization status.
Bachelor's degree in computer science, electronics engineering, or another engineering or technical discipline, plus 5 years of relevant experience. 13 years of relevant experience may substitute in lieu of a degree (8 additional years may substitute for education per contract requirements).
Hands‑on experience with the full RMF lifecycle, categorization through authorization, and the ability to create and maintain SSPs, control implementation statements, POA&Ms, and FISMA security documentation independently. Working knowledge of NIST SP 800‑53 is a hard requirement. Ability to read authorization documentation, identify gaps, build plans to address them, and communicate clearly to non‑security audiences.
Capacity to manage multiple open items simultaneously across systems, deadlines, and expiration windows while keeping everything current and accurate. Experience supporting secure product installation planning and working with stakeholders through the ATO process is essential.
Must be able to obtain and maintain a VA Public Trust or Suitability/Fitness determination. U.S. citizenship required.
Comfortable using AI tools to assist with documentation drafting, artifact review, and compliance gap analysis. Understanding that AI accelerates RMF documentation work, but accuracy and human review are non‑negotiable in an authorization context.
Remote, U.S.-based. Occasional travel may be required to support program needs.
In the first 90 days, establish working relationships with VA ISOs and ISSOs, get current on open ATO packages, and take ownership of POA&M tracking. By six months, the systems you support will have no overdue authorization milestones, and you will be the first point of contact for compliance questions. In the long run, your work ensures VA research systems remain authorized and operational, directly enabling Veterans to access care through modernized VA tools.
IronArch Technology is an equal‑opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law.
In alignment with applicable state and local pay transparency laws, IronArch includes a salary range in our job descriptions to support equity and transparency in our hiring process. The compensation range provided reflects what we reasonably expect to offer for this role, with the final offer determined by a variety of factors including skills, experience, and scope of responsibilities.