Experience performing Information Assurance (IA) controls analysis, testing, and risk assessments
Experience with Nessus, Nmap, BurpSuite, Linux security (RHEL7), and AWS cloud security
Experience with the Authority to Operate (ATO) process
Working knowledge of eMASS (Enterprise Mission Assurance Support Service)
Requirements:
Track and perform tasks related to AA activities within the VA
Ensure systems, devices, and networks obtain and maintain Authorization to Operate (ATO)
Plan, coordinate, and lead teams in conducting information system and network assessments
Identify vulnerabilities, risks, and security requirements in compliance with VA AA processes
Job description
Summary:
Razor is looking for (2) Junior and Senior level Information Assurance Analysts responsible for managing Assessment and Authorization (A&A) activities within the Department of Veterans Affairs (VA) to ensure systems maintain Authorization to Operate (ATO). This role involves leading security assessments, identifying vulnerabilities, managing eMASS packages, and supporting VA cybersecurity leadership in executing Risk Management Framework (RMF) processes.
Clearance Requirements:
Ability to obtain a Medium level VA Public Trust Security Clearance required
Responsibilities:
Track and perform tasks related to A&A activities within the VA
Ensure systems, devices, and networks obtain and maintain Authorization to Operate (ATO)
Plan, coordinate, and lead teams in conducting information system and network assessments
Identify vulnerabilities, risks, and security requirements in compliance with VA A&A processes
Test Common Control Indicators (CCIs) and validate Security Plans
Provide weekly status updates on security activities
Perform extensive work within eMASS packages
Support VA Security Control Assessors (SCAs) and cybersecurity leadership
Assist in execution and enforcement of VA cybersecurity and RMF processes
Provide risk analysis and recommendations to ISO, ISSO, and cybersecurity leadership
Qualifications:
Experience performing Information Assurance (IA) controls analysis, testing, and risk assessments
Experience with Nessus, Nmap, BurpSuite, Linux security (RHEL7), and AWS cloud security
Experience with the Authority to Operate (ATO) process
Senior-level experience obtaining ATO from scratch with minimal oversight
Working knowledge of eMASS (Enterprise Mission Assurance Support Service)
Knowledge of NIST SP 800-53, NIST SP 800-37, CNSSI 1254, and VA Risk Management policies
Ability to evaluate applications, infrastructure, and enterprise environments based on accreditation boundaries
Knowledge of defense-in-depth and information security principles
Experience with vulnerability scanning and assessment tools
Ability to analyze risk and recommend mitigation strategies and process improvements
Desired Skills:
Experience with VA cybersecurity environments
Ability to work independently and collaboratively within a small security team
Strong verbal and written communication skills
Ability to translate technical information for non-technical audiences
Experience with Prisma Cloud/Twistlock and containerization technologies
Employer Information:
Razor is an Equal Opportunity Employer and considers all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status, or any other protected characteristic.
Benefits Overview:
Razor offers a comprehensive benefits package which may include medical, dental, and vision insurance, paid time off, holidays, 401(k) with company match, professional development opportunities, and other competitive benefits designed to support the health and well-being of our employees.