Senior ATO Security Analyst
IronArch TechnologyAbout the role
Who We Are
Known for being a Best Place to Work and a People First company, IronArch Technology is an award-winning Service-Disabled Veteran-Owned Small Business (SDVOSB) specializing in providing innovative solutions and world class services to Federal Government clients.
Our employees have voted us as a 'Best Place to Work' 9 times and we are an INC 5000 recipient for being one of the fastest growing businesses in the United States.
Our Values: Deliver Outcomes with Speed | Own the Work and the Results | Respect People. Speak Directly. | Stay Curious. Enjoy the Journey.
What You’ll Do
As a Senior ATO Security Analyst, you will support the Department of Veterans Affairs (VA) by guiding systems through the full Risk Management Framework (RMF) lifecycle and ensuring compliance with VA security policies and authorization requirements. In this role, you’ll partner with Information System Owners (ISOs), Information System Security Officers (ISSOs), and other stakeholders to coordinate Authorization to Operate (ATO) activities, identify and mitigate risks, and maintain the security posture of systems from acquisition and deployment through decommissioning. You will serve as a trusted security advisor, translating complex cybersecurity requirements into practical recommendations that enable secure and compliant IT system implementation.
Key Responsibilities
- Coordinate and support RMF Steps 0–6 activities required to obtain and maintain system Authorizations to Operate (ATO).
- Collaborate with Information System Owners (ISOs), Information System Security Officers (ISSOs), and system stakeholders to ensure security requirements are implemented and documented.
- Develop, update, and maintain detailed security documentation and authorization artifacts in accordance with VA policies and processes.
- Identify, assess, and help mitigate security risks and vulnerabilities, escalating critical risks to leadership when necessary.
- Provide information system security guidance throughout the system lifecycle, including acquisition, installation, operations, and decommissioning.
- Translate complex cybersecurity and RMF requirements into actionable recommendations to support secure system deployment and operations.
- Support security reviews of IT systems, networks, hardware, and software across a variety of environments and installation sites.
- Experience in proactively and independently managing complex system records in the Enterprise Mission Assurance Support Service (eMASS) tool.
- Experience with supporting all RMF steps, security categorizations, creating and updating security artifacts and FISMA security documents, control implementation details, and Plan of Action and Milestones (POA&M)
- Experience with National Institute of Standards and Technology (NIST) SP 800-53 security controls, RMF, and system authorizations and security compliance standards and processes
- Experience in creating plans and approaches for executing product installation securely in accordance with agency authorization policy requirements for system major changes and development lifecycle, while identifying potential risks and working with system stakeholders to create mitigation strategies to reduce or eliminate risks
- Analyze authorization documents and associated artifacts against authorization requirements to identify gaps, establish a schedule to address outstanding authorization requirements, and coordinate directly with system stakeholders to address identified gaps in accordance with required deadlines
- Excellent oral and written communication skills and the ability to independently lead client-facing meetings and present complex ATO topics to the client
- Ability to organize, manage, and maintain large amounts of discrete data with various expiration dates across multiple systems simultaneously
- Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements.
- Bachelor’s degree in Computer Science, Electronics Engineering or other Engineering or technical discipline and 5 years of relevant work experience or 13 years of relevant work experience in lieu of degree
Preferred Experience
- Experience working with VA
- Ability to engage with varying levels of staff/leadership
- Experience supporting ATOs for specialized devices
Location
- This position is open to remote delivery anywhere within the U.S., to include the District of Columbia.
- (#LI-remote)
Why IronArch Technology?
- Awarded Best Place to Work 9 times!
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s