{"schemaVersion":"jobsearcher.job.v1","id":"1ea8d5f2f2adae41beee92ea","url":"https://jobsearcher.com/jobs/1ea8d5f2f2adae41beee92ea","canonicalUrl":"https://jobsearcher.com/jobs/1ea8d5f2f2adae41beee92ea","title":"ISSO Security Analyst (SSA)","description":"Description:\nWho We Are\nKnown for being a Best Place to Work and a People First company, IronArch Technology is an award-winning Service-Disabled Veteran-Owned Small Business (SDVOSB) specializing in providing innovative solutions and world class services to Federal Government clients.\nOur employees have voted us as a 'Best Place to Work' 9 times and we are an INC 5000 recipient for being one of the fastest growing businesses in the United States.\nOur Values: Deliver Outcomes with Speed | Own the Work and the Results | Respect People. Speak Directly. | Stay Curious. Enjoy the Journey.\nWhat You’ll Do\n\nIronArch Technology is seeking an ISSO Security Analyst (SSA) to support Department of Veterans Affairs (VA) cybersecurity initiatives by assisting with Risk Management Framework (RMF) and Authorization to Operate (ATO) activities for mission-critical information systems.\nAs a member of our cybersecurity team, you will work closely with VA Information System Owners (ISOs), Information System Security Officers (ISSOs), site managers, engineers, and system stakeholders to support the successful execution of RMF lifecycle activities while ensuring compliance with Federal cybersecurity requirements.\nYou will help maintain the appropriate operational security posture of information systems throughout their lifecycle—from acquisition and implementation through production operations and eventual decommissioning. You will prepare and maintain security documentation, coordinate authorization activities, identify cybersecurity risks, and assist with implementing secure, compliant IT solutions.\nThis is an excellent opportunity for a cybersecurity professional looking to expand their expertise in RMF, ATO, and Federal information security while supporting one of the nation's largest healthcare organizations.\nWork Location: Remote (U.S.-based). Occasional travel to VA or customer locations may be required for meetings, security reviews, or program activities.\n\nKey Responsibilities\nRisk Management Framework (RMF) & Authorization Support\nSupport RMF Steps 0–6 activities for Authorization to Operate (ATO) packages.\nAssist Information System Owners (ISOs), ISSOs, and system stakeholders throughout the authorization lifecycle.\nSupport compliance with VA cybersecurity policies, FISMA, NIST, and agency authorization requirements.\nAssist with system authorizations, continuous monitoring, annual assessments, and security reviews.\nTrack authorization milestones, documentation updates, and artifact expiration dates across multiple information systems.\nSecurity Documentation & Compliance\nDevelop, update, and maintain System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action & Milestones (POA&Ms), Security Impact Analyses (SIAs), and other RMF documentation.\nDocument NIST SP 800-53 security control implementations and assist with validating compliance.\nAnalyze authorization documentation to identify gaps and support remediation efforts.\nMaintain complete, accurate, and audit-ready security documentation throughout the system lifecycle.\nRisk Assessment & Security Advisory\nAssist in identifying cybersecurity risks associated with system implementations, upgrades, and operational environments.\nSupport the development of mitigation strategies in collaboration with technical and business stakeholders.\nProvide security guidance for system installations, major changes, cloud implementations, and application development efforts.\nSupport presentations of security findings and authorization status to government stakeholders.\nClient Engagement & Collaboration\nSupport assigned information systems as part of the cybersecurity team.\nParticipate in customer meetings involving RMF, ATO, and security compliance activities.\nCollaborate with engineers, developers, project managers, system owners, and cybersecurity teams to achieve authorization objectives.\nTranslate cybersecurity requirements into practical recommendations for technical and non-technical stakeholders.\nContinuous Improvement\nSupport Continuous Authorization and Monitoring (CAM) initiatives.\nRecommend improvements to security documentation and RMF processes.\nStay current with evolving VA cybersecurity guidance, NIST publications, and Federal security requirements.\nRequirements:\nBachelor's degree in Computer Science, Cybersecurity, Information Technology, Electronics Engineering, or a related field with 5+ years of professional Information Technology experience; or\n13+ years of professional Information Technology experience in lieu of a degree.\nExperience supporting Risk Management Framework (RMF) activities and Authorization to Operate (ATO) processes.\nExperience creating, updating, and maintaining FISMA security documentation and RMF artifacts.\nWorking knowledge of NIST SP 800-53 security controls, Risk Management Framework (RMF), FISMA, and Federal cybersecurity compliance requirements.\nExperience supporting secure product implementations, system major changes, and development lifecycle security activities.\nExperience analyzing authorization documentation and supporting remediation efforts.\nAbility to lead or actively participate in client meetings involving RMF and ATO activities.\nStrong organizational skills with the ability to manage multiple authorization packages, documentation sets, and project timelines.\nAbility to obtain and maintain a VA Public Trust Clerance.\nAI Capabilities\nExperience using AI-assisted tools responsibly to improve cybersecurity documentation, security assessments, risk analysis, and operational efficiency.\nFamiliarity with AI-enabled cybersecurity capabilities while ensuring compliance with federal security and privacy requirements.\n\nClearance Requirements\nU.S. Citizenship is required.\nAbility to obtain and maintain a VA Public Trust Clearance.\nCandidates with an active VA Public Trust, current Federal Public Trust, or recently completed VA background investigation are strongly preferred, as they can significantly reduce onboarding timelines.\nPreferred Experience\nPrior experience supporting the U.S. Department of Veterans Affairs (VA) is strongly preferred.\nExperience supporting Continuous Authorization and Monitoring (CAM).\nExperience supporting Authorization to Operate (ATO) packages for specialized devices, enterprise applications, or cloud environments.\nExperience with the VA Enterprise Cybersecurity Program (ECP) and VA Risk Management Framework (RMF) processes.\nExperience using VA security tools such as eMASS, Archer, and ServiceNow.\nExcellent written, verbal, and presentation communication skills.\nAbility to effectively communicate with technical teams, executive leadership, and government stakeholders.\nProfessional certifications such as Security+, CAP, CISSP (Associate), CASP+, CISM, or equivalent are highly desirable.\nActive VA Public Trust or recently adjudicated Federal Public Trust is highly desirable.\n(#LI-remote)\nWhy IronArch Technology?\nAwarded Best Place to Work 9 times!\nCompetitive compensation and market-leading bonus opportunities\nMedical, dental and vision benefits where a significant portion of the premium is subsidized by IronArch. For qualifying high deductible health plans, IronArch also contributes towards a Health Reimbursement Account to cover eligible medical expenses\nCompany-provided healthcare concierge assistance to help explain your coverage in plain language; help you find, choose, and schedule quality care; and address billing, benefit, or claims concerns, potentially saving hours of your time\n401(k) retirement plan where the company contributes dollar for dollar up to 3 percent, and 50 cents on the dollar for the 4th and 5th percent with immediate entry and immediate vesting\n20 days of PTO accumulated per calendar year\n11paid holidays\nBereavement, jury duty, parental (maternity/paternity/adoption), and military leaves\nSabbatical programs\nCompany-paid short- and long-term disability\nCompany-paid life insurance\nVoluntary life, accidental and indemnity income replacement benefits\nProfessional development reimbursement\nHealth club reimbursement\nMatching donation program and annual philanthropic activities\nPet insurance\nAnd more!\nApply today to learn why IronArch Technology has been recognized as “Best Place to Work” for 9 years!\nIronArch Technology is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law.\nIn alignment with applicable state and local pay transparency laws, IronArch includes a salary range in our job descriptions to support equity and transparency in our hiring process. The compensation range provided reflects what we reasonably expect to offer for this role, with the final offer determined by a variety of factors including skills, experience, and scope of responsibilities.","company":"Ironarchtechnology","rawCompany":"ironarchtechnology","city":"Denver","state":"CO","isRemote":false,"isActive":false,"createdAt":"2026-08-15T13:44:18.396Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"13-1199.07","title":"Security Management Specialists","slug":"security-management-specialists"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541618","title":"Other Management Consulting Services","slug":"other-management-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"ISSO Security Analyst (SSA)","description":"Description:\nWho We Are\nKnown for being a Best Place to Work and a People First company, IronArch Technology is an award-winning Service-Disabled Veteran-Owned Small Business (SDVOSB) specializing in providing innovative solutions and world class services to Federal Government clients.\nOur employees have voted us as a 'Best Place to Work' 9 times and we are an INC 5000 recipient for being one of the fastest growing businesses in the United States.\nOur Values: Deliver Outcomes with Speed | Own the Work and the Results | Respect People. Speak Directly. | Stay Curious. Enjoy the Journey.\nWhat You’ll Do\n\nIronArch Technology is seeking an ISSO Security Analyst (SSA) to support Department of Veterans Affairs (VA) cybersecurity initiatives by assisting with Risk Management Framework (RMF) and Authorization to Operate (ATO) activities for mission-critical information systems.\nAs a member of our cybersecurity team, you will work closely with VA Information System Owners (ISOs), Information System Security Officers (ISSOs), site managers, engineers, and system stakeholders to support the successful execution of RMF lifecycle activities while ensuring compliance with Federal cybersecurity requirements.\nYou will help maintain the appropriate operational security posture of information systems throughout their lifecycle—from acquisition and implementation through production operations and eventual decommissioning. You will prepare and maintain security documentation, coordinate authorization activities, identify cybersecurity risks, and assist with implementing secure, compliant IT solutions.\nThis is an excellent opportunity for a cybersecurity professional looking to expand their expertise in RMF, ATO, and Federal information security while supporting one of the nation's largest healthcare organizations.\nWork Location: Remote (U.S.-based). Occasional travel to VA or customer locations may be required for meetings, security reviews, or program activities.\n\nKey Responsibilities\nRisk Management Framework (RMF) & Authorization Support\nSupport RMF Steps 0–6 activities for Authorization to Operate (ATO) packages.\nAssist Information System Owners (ISOs), ISSOs, and system stakeholders throughout the authorization lifecycle.\nSupport compliance with VA cybersecurity policies, FISMA, NIST, and agency authorization requirements.\nAssist with system authorizations, continuous monitoring, annual assessments, and security reviews.\nTrack authorization milestones, documentation updates, and artifact expiration dates across multiple information systems.\nSecurity Documentation & Compliance\nDevelop, update, and maintain System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action & Milestones (POA&Ms), Security Impact Analyses (SIAs), and other RMF documentation.\nDocument NIST SP 800-53 security control implementations and assist with validating compliance.\nAnalyze authorization documentation to identify gaps and support remediation efforts.\nMaintain complete, accurate, and audit-ready security documentation throughout the system lifecycle.\nRisk Assessment & Security Advisory\nAssist in identifying cybersecurity risks associated with system implementations, upgrades, and operational environments.\nSupport the development of mitigation strategies in collaboration with technical and business stakeholders.\nProvide security guidance for system installations, major changes, cloud implementations, and application development efforts.\nSupport presentations of security findings and authorization status to government stakeholders.\nClient Engagement & Collaboration\nSupport assigned information systems as part of the cybersecurity team.\nParticipate in customer meetings involving RMF, ATO, and security compliance activities.\nCollaborate with engineers, developers, project managers, system owners, and cybersecurity teams to achieve authorization objectives.\nTranslate cybersecurity requirements into practical recommendations for technical and non-technical stakeholders.\nContinuous Improvement\nSupport Continuous Authorization and Monitoring (CAM) initiatives.\nRecommend improvements to security documentation and RMF processes.\nStay current with evolving VA cybersecurity guidance, NIST publications, and Federal security requirements.\nRequirements:\nBachelor's degree in Computer Science, Cybersecurity, Information Technology, Electronics Engineering, or a related field with 5+ years of professional Information Technology experience; or\n13+ years of professional Information Technology experience in lieu of a degree.\nExperience supporting Risk Management Framework (RMF) activities and Authorization to Operate (ATO) processes.\nExperience creating, updating, and maintaining FISMA security documentation and RMF artifacts.\nWorking knowledge of NIST SP 800-53 security controls, Risk Management Framework (RMF), FISMA, and Federal cybersecurity compliance requirements.\nExperience supporting secure product implementations, system major changes, and development lifecycle security activities.\nExperience analyzing authorization documentation and supporting remediation efforts.\nAbility to lead or actively participate in client meetings involving RMF and ATO activities.\nStrong organizational skills with the ability to manage multiple authorization packages, documentation sets, and project timelines.\nAbility to obtain and maintain a VA Public Trust Clerance.\nAI Capabilities\nExperience using AI-assisted tools responsibly to improve cybersecurity documentation, security assessments, risk analysis, and operational efficiency.\nFamiliarity with AI-enabled cybersecurity capabilities while ensuring compliance with federal security and privacy requirements.\n\nClearance Requirements\nU.S. Citizenship is required.\nAbility to obtain and maintain a VA Public Trust Clearance.\nCandidates with an active VA Public Trust, current Federal Public Trust, or recently completed VA background investigation are strongly preferred, as they can significantly reduce onboarding timelines.\nPreferred Experience\nPrior experience supporting the U.S. Department of Veterans Affairs (VA) is strongly preferred.\nExperience supporting Continuous Authorization and Monitoring (CAM).\nExperience supporting Authorization to Operate (ATO) packages for specialized devices, enterprise applications, or cloud environments.\nExperience with the VA Enterprise Cybersecurity Program (ECP) and VA Risk Management Framework (RMF) processes.\nExperience using VA security tools such as eMASS, Archer, and ServiceNow.\nExcellent written, verbal, and presentation communication skills.\nAbility to effectively communicate with technical teams, executive leadership, and government stakeholders.\nProfessional certifications such as Security+, CAP, CISSP (Associate), CASP+, CISM, or equivalent are highly desirable.\nActive VA Public Trust or recently adjudicated Federal Public Trust is highly desirable.\n(#LI-remote)\nWhy IronArch Technology?\nAwarded Best Place to Work 9 times!\nCompetitive compensation and market-leading bonus opportunities\nMedical, dental and vision benefits where a significant portion of the premium is subsidized by IronArch. For qualifying high deductible health plans, IronArch also contributes towards a Health Reimbursement Account to cover eligible medical expenses\nCompany-provided healthcare concierge assistance to help explain your coverage in plain language; help you find, choose, and schedule quality care; and address billing, benefit, or claims concerns, potentially saving hours of your time\n401(k) retirement plan where the company contributes dollar for dollar up to 3 percent, and 50 cents on the dollar for the 4th and 5th percent with immediate entry and immediate vesting\n20 days of PTO accumulated per calendar year\n11paid holidays\nBereavement, jury duty, parental (maternity/paternity/adoption), and military leaves\nSabbatical programs\nCompany-paid short- and long-term disability\nCompany-paid life insurance\nVoluntary life, accidental and indemnity income replacement benefits\nProfessional development reimbursement\nHealth club reimbursement\nMatching donation program and annual philanthropic activities\nPet insurance\nAnd more!\nApply today to learn why IronArch Technology has been recognized as “Best Place to Work” for 9 years!\nIronArch Technology is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law.\nIn alignment with applicable state and local pay transparency laws, IronArch includes a salary range in our job descriptions to support equity and transparency in our hiring process. The compensation range provided reflects what we reasonably expect to offer for this role, with the final offer determined by a variety of factors including skills, experience, and scope of responsibilities.","datePosted":"2026-08-15T13:44:18.396Z","dateModified":"2026-08-15T13:44:18.396Z","hiringOrganization":{"@type":"Organization","name":"Ironarchtechnology","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Denver","addressRegion":"CO","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"1ea8d5f2f2adae41beee92ea"},"url":"https://jobsearcher.com/jobs/1ea8d5f2f2adae41beee92ea"}}