{"schemaVersion":"jobsearcher.job.v1","id":"429be45e93aa3dae0998935c","url":"https://jobsearcher.com/jobs/429be45e93aa3dae0998935c","canonicalUrl":"https://jobsearcher.com/jobs/429be45e93aa3dae0998935c","title":"Enterprise Risk Analyst (remote)","description":"MKS2 Technologies, LLC, an award-winning high growth small business, creates innovative and customer-centric technology solutions in the areas of Cyber Security, Instructional Design and Training, Software Engineering and IT Support Services to improve the security and well-being of our clients. Our commitment to excellence and our \"Mission First\" orientation has resulted in steady growth and an expanding client base across government agencies. We have employees nationwide and for the past three consecutive years were named one of the fastest growing Veteran-owned companies in the nation. Please take a moment to browse through our website and learn more about what it means to serve with MKS2.\n\nEnterprise Risk Analyst\nPay Rate: $110,000-$120,000 based on experience - full benefits available\nDuration: currently funded through 01/2027 - extension process already ongoing up to 5 years additional\nSummary:\nThe experienced Risk Analyst role executes the VA Enterprise Risk Analysis process using a custom ERA tool to identify key cyber security risk factors in network connected medical devices and Special Purpose Systems (e.g., building automation systems, physical security systems, operational technology). These risk factors are summarized, evaluated, and reported using quantitative and qualitative scores to provide a VA authorizing official with awareness of the residual cyber risk prior to connecting these devices to the VA network. The Risk Analyst must acquire, review and leverage system documentation and data gathered through questionnaires and interviews with customers in the field and vendor/manufacturer representatives to accurately document critical security posture elements in a common reporting format. These elements include hardware/software inventory, communications profile, system interconnections, data types and stores, and the presence or lack of security controls, settings and mechanisms for a given device type. The Risk Analyst performs annual reviews to support effective continuous monitoring and to ensure documented residual risks are current, accurate, and complete. The analyst works within a Risk Management team and is expected to collaborate with Federal and contractor team mates to achieve best outcomes for the ERA process.\nYou Have:\nExperience with Cybersecurity, risk management, or risk assessment for complex systems\nExperience with NIST SP 800-53 and NIST SP 800-30\nExperience with documenting and depicting network topology and network protocols\nAbility to engage directly with clients, and third parties to facilitate enterprise risk analysis\nAbility to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements\nBachelor's degree in Computer Science, Mathematics, Engineering or technical discipline and 10 years of relevant work experience or 18 years of relevant work experience in lieu of degree\nNice If You Have:\nExperience with cybersecurity analysis of medical technology or Internet of Things (IoT)\nExperience with Governance, Risk, and Compliance (GRC)\nExperience with Assessment and Authorization (A&A) and eMASS\nExperience with Excel and Visio\nCompTIA Security+ or Certified Risk Management Professional (CRISC) or Certified in Risk and Information Systems Control (CRISC)\nPublic Trust clearance\n\nDiversity creates a healthier atmosphere: MKS2 Technologies is proud to be an Equal Employment Opportunity / Affirmative Action employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law.","company":"Mks2 Technologies","rawCompany":"mks2 technologies","isRemote":true,"isActive":false,"createdAt":"2026-08-15T13:11:48.497Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"13-2054.00","title":"Financial Risk Specialists","slug":"financial-risk-specialists"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"}],"industries":[{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541618","title":"Other Management Consulting Services","slug":"other-management-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Enterprise Risk Analyst (remote)","description":"MKS2 Technologies, LLC, an award-winning high growth small business, creates innovative and customer-centric technology solutions in the areas of Cyber Security, Instructional Design and Training, Software Engineering and IT Support Services to improve the security and well-being of our clients. Our commitment to excellence and our \"Mission First\" orientation has resulted in steady growth and an expanding client base across government agencies. We have employees nationwide and for the past three consecutive years were named one of the fastest growing Veteran-owned companies in the nation. Please take a moment to browse through our website and learn more about what it means to serve with MKS2.\n\nEnterprise Risk Analyst\nPay Rate: $110,000-$120,000 based on experience - full benefits available\nDuration: currently funded through 01/2027 - extension process already ongoing up to 5 years additional\nSummary:\nThe experienced Risk Analyst role executes the VA Enterprise Risk Analysis process using a custom ERA tool to identify key cyber security risk factors in network connected medical devices and Special Purpose Systems (e.g., building automation systems, physical security systems, operational technology). These risk factors are summarized, evaluated, and reported using quantitative and qualitative scores to provide a VA authorizing official with awareness of the residual cyber risk prior to connecting these devices to the VA network. The Risk Analyst must acquire, review and leverage system documentation and data gathered through questionnaires and interviews with customers in the field and vendor/manufacturer representatives to accurately document critical security posture elements in a common reporting format. These elements include hardware/software inventory, communications profile, system interconnections, data types and stores, and the presence or lack of security controls, settings and mechanisms for a given device type. The Risk Analyst performs annual reviews to support effective continuous monitoring and to ensure documented residual risks are current, accurate, and complete. The analyst works within a Risk Management team and is expected to collaborate with Federal and contractor team mates to achieve best outcomes for the ERA process.\nYou Have:\nExperience with Cybersecurity, risk management, or risk assessment for complex systems\nExperience with NIST SP 800-53 and NIST SP 800-30\nExperience with documenting and depicting network topology and network protocols\nAbility to engage directly with clients, and third parties to facilitate enterprise risk analysis\nAbility to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements\nBachelor's degree in Computer Science, Mathematics, Engineering or technical discipline and 10 years of relevant work experience or 18 years of relevant work experience in lieu of degree\nNice If You Have:\nExperience with cybersecurity analysis of medical technology or Internet of Things (IoT)\nExperience with Governance, Risk, and Compliance (GRC)\nExperience with Assessment and Authorization (A&A) and eMASS\nExperience with Excel and Visio\nCompTIA Security+ or Certified Risk Management Professional (CRISC) or Certified in Risk and Information Systems Control (CRISC)\nPublic Trust clearance\n\nDiversity creates a healthier atmosphere: MKS2 Technologies is proud to be an Equal Employment Opportunity / Affirmative Action employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, national origin, protected veteran status, disability status, sexual orientation, gender identity or expression, marital status, genetic information, or any other characteristic protected by law.","datePosted":"2026-08-15T13:11:48.497Z","dateModified":"2026-08-15T13:11:48.497Z","hiringOrganization":{"@type":"Organization","name":"Mks2 Technologies","sameAs":"https://jobsearcher.com"},"jobLocationType":"TELECOMMUTE","applicantLocationRequirements":{"@type":"Country","name":"US"},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"429be45e93aa3dae0998935c"},"url":"https://jobsearcher.com/jobs/429be45e93aa3dae0998935c"}}