Cyber Security Risk Lead

Tista Science And Technology Corporation

• $192K — $200K *
US-AnywhereRemote in Rockville, MD
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience in information security, with at least 4 years in a lead role for federal IT programs.
  • Proven ability to develop and manage complete A&A packages per the NIST Risk Management Framework.
  • Hands-on experience with managing POA&Ms and federal governance, risk, and compliance activities.
  • Familiarity with vulnerability management and risk assessment methodologies.
  • Experience with cloud and containerized systems security controls.
  • Understanding of DevSecOps security practices and tools.
  • Knowledge of VA cybersecurity environments is strongly preferred.

Responsibilities

  • Manage day-to-day ATO activities and security compliance across products.
  • Develop A&A artifacts in line with NIST RMF and VA security requirements.
  • Coordinate security assessments and remediation activities with stakeholders and delivery teams.
  • Lead vulnerability tracking and reporting of security compliance activities.
  • Ensure security requirements are integrated into Agile delivery processes.
  • Support documentation and reporting for security incident responses.
  • Contribute to reusable A&A templates and security compliance practices.

Benefits

  • Comprehensive benefits plan including health and wellness options.
  • Opportunities for certification reimbursements and professional development.
  • Flexible working arrangements including remote options.
  • Support for career growth and advancement within cybersecurity initiatives.
  • Engagement in business growth and continuous improvement projects.
Full Job Description
Overview

TISTA is seeking a Cyber Security Risk Lead to support the Department of Veterans Affairs (VA) Supply Chain Management DevSecOps program. This role will lead day-to-day Assessment and Authorization (A&A), Authority to Operate (ATO), cybersecurity risk, vulnerability management, and compliance activities across the product portfolio.

 The Cyber Security Risk Lead will work closely with VA security stakeholders and delivery teams to maintain security authorizations, manage risk and compliance activities, and ensure security requirements and evidence are incorporated throughout the Agile delivery lifecycle.  Responsibilities
  • Manage ATO activities, authorization status, security risks, and POA&M activities across supported products.
  • Develop and maintain A&A artifacts in accordance with NIST RMF and applicable VA security requirements.
  • Coordinate security assessments, evidence requests, findings, and remediation activities with VA security stakeholders and delivery teams.
  • Lead vulnerability tracking, risk assessments, remediation reporting, and security compliance activities.
  • Support privacy and security requirements for cloud, containerized, and integrated systems.
  • Ensure security authorization requirements and evidence are incorporated into release and Agile planning activities.
  • Support security incident response documentation and reporting.
  • Maintain reusable A&A templates, risk reporting standards, and security compliance practices.
  • Contribute to TISTA’s cybersecurity practice, business growth, and continuous improvement initiatives.
Qualifications
  • 8+ years of information security experience, including 4+ years as an ISSO, ISSM, Security Control Assessor, or A&A lead supporting federal IT programs.
  • Demonstrated experience authoring and maintaining complete A&A packages under the NIST Risk Management Framework, including System Security Plans, Risk Assessments, PIAs, Security Configuration Checklists, ISAs, and MOUs.
  • Hands-on experience managing POA&Ms, security control evidence, and federal GRC activities.
  • Experience with vulnerability management, remediation tracking, and security risk assessments.
  • Experience supporting cloud-hosted or containerized systems and inherited security controls.
  • Working knowledge of DevSecOps security practices and tools.
  • Experience with VA OIT, VHA, or other federal health cybersecurity environments, including familiarity with VA Handbook 6500, VA Critical Security Controls, and VA security processes, strongly preferred.
Certifications:
  • ISC2 CISSP required.
  • ISACA CISM required or must be obtained within 12 months of hire.
  • GIAC Security Leadership Certification (GSLC) required or must be obtained within 12 months of hire.

Education:

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field.
  • Master’s degree preferred.

Clearance:

  • Tier 2 / Moderate Risk Background Investigation; ability to obtain a VA PIV credential.

Location:

  • Rockville, MD / Remote (CONUS).
  • Up to 10% CONUS travel.

Pay Range:

  • The suggested pay for this position ranges from $192,546 to $200,875.
  • The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience, and location.
  • Also, certain positions are eligible for additional forms of compensation, such as bonuses.
  • TISTA associates are eligible to participate in our comprehensive benefits plan! More information can be found here: https://tistatech.com/working-at-tista/

Similar Jobs

More Jobs at Tista Science And Technology Corporation

  • DevSecOps Engineer
    $161K — $176K *
    Remote
    Information Technology
    Remote in United States
  • PMO Lead
    $180K — $198K *
    Remote
    Education, Government & Non-Profit
    Remote in Rockville, MD
  • Deputy IT Program Manager
    $172K — $187K *
    Rockville, MD 20852 (Montgomery County)
    Education, Government & Non-Profit
    Hybrid
  • Test Automation Lead
    $166K — $178K *
    Remote
    Education, Government & Non-Profit
    Remote in Rockville, MD
  • Solution System Architect
    $171K — $183K *
    Remote
    Enterprise Technology
    Remote in Rockville, MD

More Information Technology Jobs

Find similar Cyber Security Risk Lead jobs: