ISSO Security Analyst (SSA)
Who We Are
Known for being a Best Place to Work and a People First company, IronArch Technology is an award-winning Service-Disabled Veteran-Owned Small Business (SDVOSB) specializing in providing innovative solutions and world class services to Federal Government clients.
Our employees have voted us as a 'Best Place to Work' 9 times and we are an INC 5000 recipient for being one of the fastest growing businesses in the United States.
Our Values: Deliver Outcomes with Speed | Own the Work and the Results | Respect People. Speak Directly. | Stay Curious. Enjoy the Journey.
What You’ll Do
IronArch Technology is seeking an ISSO Security Analyst (SSA) to support Department of Veterans Affairs (VA) cybersecurity initiatives by assisting with Risk Management Framework (RMF) and Authorization to Operate (ATO) activities for mission-critical information systems.
As a member of our cybersecurity team, you will work closely with VA Information System Owners (ISOs), Information System Security Officers (ISSOs), site managers, engineers, and system stakeholders to support the successful execution of RMF lifecycle activities while ensuring compliance with Federal cybersecurity requirements.
You will help maintain the appropriate operational security posture of information systems throughout their lifecycle—from acquisition and implementation through production operations and eventual decommissioning. You will prepare and maintain security documentation, coordinate authorization activities, identify cybersecurity risks, and assist with implementing secure, compliant IT solutions.
This is an excellent opportunity for a cybersecurity professional looking to expand their expertise in RMF, ATO, and Federal information security while supporting one of the nation's largest healthcare organizations.
Work Location: Remote (U.S.-based). Occasional travel to VA or customer locations may be required for meetings, security reviews, or program activities.
Key Responsibilities
Risk Management Framework (RMF) & Authorization Support
- Support RMF Steps 0–6 activities for Authorization to Operate (ATO) packages.
- Assist Information System Owners (ISOs), ISSOs, and system stakeholders throughout the authorization lifecycle.
- Support compliance with VA cybersecurity policies, FISMA, NIST, and agency authorization requirements.
- Assist with system authorizations, continuous monitoring, annual assessments, and security reviews.
- Track authorization milestones, documentation updates, and artifact expiration dates across multiple information systems.
Security Documentation & Compliance
- Develop, update, and maintain System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action & Milestones (POA&Ms), Security Impact Analyses (SIAs), and other RMF documentation.
- Document NIST SP 800-53 security control implementations and assist with validating compliance.
- Analyze authorization documentation to identify gaps and support remediation efforts.
- Maintain complete, accurate, and audit-ready security documentation throughout the system lifecycle.
Risk Assessment & Security Advisory
- Assist in identifying cybersecurity risks associated with system implementations, upgrades, and operational environments.
- Support the development of mitigation strategies in collaboration with technical and business stakeholders.
- Provide security guidance for system installations, major changes, cloud implementations, and application development efforts.
- Support presentations of security findings and authorization status to government stakeholders.
Client Engagement & Collaboration
- Support assigned information systems as part of the cybersecurity team.
- Participate in customer meetings involving RMF, ATO, and security compliance activities.
- Collaborate with engineers, developers, project managers, system owners, and cybersecurity teams to achieve authorization objectives.
- Translate cybersecurity requirements into practical recommendations for technical and non-technical stakeholders.
Continuous Improvement
- Support Continuous Authorization and Monitoring (CAM) initiatives.
- Recommend improvements to security documentation and RMF processes.
- Stay current with evolving VA cybersecurity guidance, NIST publications, and Federal security requirements.