Logo for Sprezzatura

Security Analyst

Role overview

Qualifications

  • Ability to obtain and maintain a Public Trust clearance
  • Bachelor’s Degree
  • 4+ years of experience in cybersecurity, information security, security engineering, security compliance, or a related technical field
  • Strong understanding of federal cybersecurity requirements and risk-management principles

Responsibilities

  • Support the ongoing VA.gov Platform Authority to Operate (ATO) and the associated continuous monitoring activities
  • Develop, maintain, and coordinate security and privacy artifacts required to support the Platform authorization boundary
  • Support updates to artifacts such as Privacy Threshold Analyses (PTAs), Privacy Impact Assessments (PIAs), Business Impact Analyses (BIAs), system boundary diagrams, architecture diagrams, threat models, and related security documentation
  • Maintain clear and accurate security documentation, decision records, procedures, and implementation guidance

Key facts

  • Remote from: United States
  • Full time
  • Mid-level (2-5 years)
  • Security Analyst
  • English

Hard skills

Other skills

  • Security Policies
  • Communication
  • Collaboration
  • Problem Solving

About the company

Sprezzatura logo

Sprezzatura

IT Services & IT Consulting

Sprezzatura is a Washington, DC-based management consulting firm that supports federal projects by aligning people, processes, and technology to achieve outcomes. Founded in 2009, it brings together experienced advisers and senior technologists who navigate the complexities of government programs. Its core service areas include program management, integrated change management, IT services, and budget and acquisition support. The firm serves federal government clients seeking leadership and practical insight to solve process and performance challenges. Based in Arlington, Virginia, it positions itself as a mid-sized, specialized partner within the business consulting and services industry. In 2025, Sprezzatura announced a strategic partnership with Specra.AI to accelerate innovation and operational excellence.

Company details

IndustryIT Services & IT Consulting
Company size51 - 200

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Position Title: Security Analyst 
Location: Remote (In the U.S) 

Other Considerations: U.S. Citizen or Permanent Resident (Required) 

POSITION SUMMARY

We are seeking a Security Analyst to join our team supporting VA.gov Platform. In this role you will support the security, compliance, and ongoing Authority to Operate (ATO) of VA.gov Platform while helping engineering teams build and deliver secure digital services for Veterans. This role works across Platform infrastructure, applications, system integrations, and Veteran-Facing Services (VFS) teams to identify security risks, maintain required security documentation, support security assessments, and ensure changes to VA.gov align with federal security requirements and Platform security standards. 

This is an excellent opportunity for someone who is passionate about working closely with Security Engineers, DevOps Engineers, Site Reliability Engineers (SREs), Software Engineers, Product Managers, and government security stakeholders. The Security Analyst translates federal security requirements into actionable engineering guidance. The role supports the full security lifecycle—from architecture and design reviews through implementation, authorization, continuous monitoring, and incident response.

RESPONSIBILITIES

  • Support the ongoing VA.gov Platform Authority to Operate (ATO) and the associated continuous monitoring activities
  • Develop, maintain, and coordinate security and privacy artifacts required to support the Platform authorization boundary
  • Support updates to artifacts such as Privacy Threshold Analyses (PTAs), Privacy Impact Assessments (PIAs), Business Impact Analyses (BIAs), system boundary diagrams, architecture diagrams, threat models, and related security documentation
  • Support the creation and maintenance of Memoranda of Understanding/Interconnection Security Agreements (MOU/ISAs) for system-to-system integrations
  • Evaluate proposed system and architecture changes to determine potential security and ATO impacts
  • Coordinate with government security stakeholders and Authorizing Official Designated Representatives (AODRs) to validate security requirements and determine when additional security review is required
  • Support security assessments, audits, evidence collection, and remediation activities
  • Maintain accurate documentation and evidence demonstrating implementation of applicable security controls
  • Serve as a security resource for engineers, product teams, and Platform stakeholders
  • Translate complex federal security requirements into clear, actionable engineering guidance
  • Collaborate with government security stakeholders, engineering teams, and other security SMEs to resolve security and compliance issues
  • Maintain clear and accurate security documentation, decision records, procedures, and implementation guidance
  • Participate in Agile ceremonies, security planning activities, architecture reviews, and cross-team Platform initiatives
     

QUALIFICATIONS

  • Ability to obtain and maintain a Public Trust clearance
  • Bachelor’s Degree 
  • 4+ years of experience in cybersecurity, information security, security engineering, security compliance, or a related technical field
  • Strong understanding of federal cybersecurity requirements and risk-management principles
  • Experience supporting security assessments, authorization activities, compliance reviews, or continuous monitoring 
  • Working knowledge of NIST security controls and federal security frameworks
  • Experience assessing technical architectures, system integrations, data flows, and security risks
  • Understanding of Identity and Access Management concepts including authentication, authorization, identity lifecycle, roles, least privilege, separation of duties, and access management
  • Experience reviewing, tracking, and supporting remediation of security vulnerabilities
  • Familiarity with cloud environments and modern software development practices
  • Ability to work directly with engineers to translate security requirements into technical implementation guidance
  • Strong technical documentation and requirements-definition skills 
  • Excellent written and verbal communication skills
  • Ability to operate independently as a security subject matter expert while collaborating effectively across engineering and product teams
     

WORKING CONDITIONS

Standard Business hours are Monday through Friday. Occasional extended or weekend hours may be required based on operational needs. Must have reliable internet service that allows for effective telecommuting.  

PAY RANGE

The base salary range for this position is $100,000 to $120,000 annually, depending on geographic work location, relevant experience, skills, education, internal equity, security clearance, and contract requirements. Geographic salary ranges are determined in accordance with the company's compensation practices and represent a good-faith estimate of the compensation for this position at the time of posting.

BENEFITS

Sprezzatura offers a comprehensive and flexible benefit package to include:

  • Medical, Dental, and Vision
  • Health Saving Account (when enrolled in eligible plan) with Company contribution 
  • Company paid Life, Accidental Death, Short-term & Long-term Disability
  • Voluntary Accident, Hospital Indemnity, & Critical Care Insurance
  • Voluntary Medical & Dependent Care Flexible Spending Accounts
  • Accrued Paid Time Off & Company Paid Holidays
  • 401(k) Retirement Plan with Company match
     

WORK AUTHORIZATION

Sprezzatura participates in E-Verify and will provide the federal government with your I-9 information to confirm that you are authorized to work in the U.S.

Sprezzatura is a mission-driven, Service-Disabled Veteran-Owned Small Business (SDVOSB) that thrives at the intersection of technology, innovation, and impact. We specialize in secure, scalable, and human-centered digital solutions that accelerate government transformation. Our work spans DevSecOps, health IT modernization, intelligent automation, benefits delivery, and digital communications. We partner with agencies ready to evolve—delivering not just strategy, but measurable execution. Rooted in operational excellence and driven by curiosity, we help our clients navigate complexity with clarity—turning ambitious ideas into real-world outcomes. No buzzwords. Just impact.

EEO STATEMENT

Sprezzatura is an Equal Opportunity Employer. We do not discriminate on the basis of race, color, religion, sex (including pregnancy, sexual orientation, and gender identity), national origin, age, disability, genetic information, protected veteran status, or any other legally protected characteristic. Applicants have the right to discuss, disclose, or inquire about compensation without retaliation. Reasonable accommodations are available for qualified individuals with disabilities.

This job description is not intended to be an employment contract and does not guarantee employment for any specific duration.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Analyst Related jobs

Other jobs at Sprezzatura

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.