OverviewTISTA is seeking a Cyber Security Risk Lead to support the Department of Veterans Affairs (VA) Supply Chain Management DevSecOps program. This role will lead day-to-day Assessment and Authorization (A&A), Authority to Operate (ATO), cybersecurity risk, vulnerability management, and compliance activities across the product portfolio.
The Cyber Security Risk Lead will work closely with VA security stakeholders and delivery teams to maintain security authorizations, manage risk and compliance activities, and ensure security requirements and evidence are incorporated throughout the Agile delivery lifecycle.
Responsibilities
- Manage ATO activities, authorization status, security risks, and POA&M activities across supported products.
- Develop and maintain A&A artifacts in accordance with NIST RMF and applicable VA security requirements.
- Coordinate security assessments, evidence requests, findings, and remediation activities with VA security stakeholders and delivery teams.
- Lead vulnerability tracking, risk assessments, remediation reporting, and security compliance activities.
- Support privacy and security requirements for cloud, containerized, and integrated systems.
- Ensure security authorization requirements and evidence are incorporated into release and Agile planning activities.
- Support security incident response documentation and reporting.
- Maintain reusable A&A templates, risk reporting standards, and security compliance practices.
- Contribute to TISTA’s cybersecurity practice, business growth, and continuous improvement initiatives.
Qualifications
- 8+ years of information security experience, including 4+ years as an ISSO, ISSM, Security Control Assessor, or A&A lead supporting federal IT programs.
- Demonstrated experience authoring and maintaining complete A&A packages under the NIST Risk Management Framework, including System Security Plans, Risk Assessments, PIAs, Security Configuration Checklists, ISAs, and MOUs.
- Hands-on experience managing POA&Ms, security control evidence, and federal GRC activities.
- Experience with vulnerability management, remediation tracking, and security risk assessments.
- Experience supporting cloud-hosted or containerized systems and inherited security controls.
- Working knowledge of DevSecOps security practices and tools.
- Experience with VA OIT, VHA, or other federal health cybersecurity environments, including familiarity with VA Handbook 6500, VA Critical Security Controls, and VA security processes, strongly preferred.
Certifications:
- ISC2 CISSP required.
- ISACA CISM required or must be obtained within 12 months of hire.
- GIAC Security Leadership Certification (GSLC) required or must be obtained within 12 months of hire.
Education:
- Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field.
- Master’s degree preferred.
Clearance:
- Tier 2 / Moderate Risk Background Investigation; ability to obtain a VA PIV credential.
Location:
- Rockville, MD / Remote (CONUS).
- Up to 10% CONUS travel.
Pay Range:
- The suggested pay for this position ranges from $192,546 to $200,875.
- The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience, and location.
- Also, certain positions are eligible for additional forms of compensation, such as bonuses.
- TISTA associates are eligible to participate in our comprehensive benefits plan! More information can be found here: https://tistatech.com/working-at-tista/