TISTA Science and Technology logo

Cyber Security Risk Lead

TISTA Science and Technology

Hybrid Rockville, MDJob$193–201K/yrSeen 2 days agoSeen in employer's feed 2 days ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
$193–201K/yr
Location
Hybrid Rockville, MDHybrid
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

ISC2 CISSPISACA CISMGIAC Security Leadership Certification (GSLC)Bachelor's degree

Job overview

TISTA is seeking a Cyber Security Risk Lead to support the Department of Veterans Affairs (VA) Supply Chain Management DevSecOps program. This role will lead day-to-day Assessment and Authorization (A&A), Authority to Operate (ATO), cybersecurity risk, vulnerability management, and compliance activities across the product portfolio.

Skills & qualifications

RequiredNice to have

Skills

Information SecurityISSOISSMSecurity Control AssessorA&a LeadNIST RMFSystem Security PlansRisk AssessmentsPIAsSecurity Configuration ChecklistsISAsMOUsPOA&MsGRCVulnerability ManagementRemediation TrackingCloud-Hosted SystemsContainerized SystemsDevSecOps Security PracticesVA OITVHAVA Handbook 6500VA Critical Security ControlsVA Security Processes

Qualifications

ISC2 CISSPISACA CISMGIAC Security Leadership Certification (GSLC)Bachelor’s Degree in Cybersecurity or Related FieldMaster’s Degree PreferredTier 2 / Moderate Risk Background Investigation; Ability to Obtain VA PIV Credential

Benefits

Medical Insurance
Paid Time Off
Tuition Assistance
401(k) Match

Full job description

Overview

TISTA is seeking a Cyber Security Risk Lead to support the Department of Veterans Affairs (VA) Supply Chain Management DevSecOps program. This role will lead day-to-day Assessment and Authorization (A&A), Authority to Operate (ATO), cybersecurity risk, vulnerability management, and compliance activities across the product portfolio.

The Cyber Security Risk Lead will work closely with VA security stakeholders and delivery teams to maintain security authorizations, manage risk and compliance activities, and ensure security requirements and evidence are incorporated throughout the Agile delivery lifecycle.

At TISTA, you’ll do meaningful, mission‑driven work that improves lives alongside teammates you trust and leaders who are transparent and supportive. We invest in your learning and internal mobility so you can build a career that keeps advancing. We’re proud to serve and hire Veterans, and we put people first in everything we do.

TISTA associates enjoy above Industry Healthcare Benefits, Remote Working Options, Paid Time Off, Training/Certification opportunities, Healthcare Savings Account & Flexible Savings Account, Paid Life Insurance, Short-term & Long-term Disability, 401K Match, Tuition Reimbursement, Employee Assistance Program, Paid Holidays, Military Leave, and much more!

Responsibilities

  • Manage ATO activities, authorization status, security risks, and POA&M activities across supported products.

  • Develop and maintain A&A artifacts in accordance with NIST RMF and applicable VA security requirements.

  • Coordinate security assessments, evidence requests, findings, and remediation activities with VA security stakeholders and delivery teams.

  • Lead vulnerability tracking, risk assessments, remediation reporting, and security compliance activities.

  • Support privacy and security requirements for cloud, containerized, and integrated systems.

  • Ensure security authorization requirements and evidence are incorporated into release and Agile planning activities.

  • Support security incident response documentation and reporting.

  • Maintain reusable A&A templates, risk reporting standards, and security compliance practices.

  • Contribute to TISTA’s cybersecurity practice, business growth, and continuous improvement initiatives.

Qualifications

  • 8+ years of information security experience, including 4+ years as an ISSO, ISSM, Security Control Assessor, or A&A lead supporting federal IT programs.

  • Demonstrated experience authoring and maintaining complete A&A packages under the NIST Risk Management Framework, including System Security Plans, Risk Assessments, PIAs, Security Configuration Checklists, ISAs, and MOUs.

  • Hands-on experience managing POA&Ms, security control evidence, and federal GRC activities.

  • Experience with vulnerability management, remediation tracking, and security risk assessments.

  • Experience supporting cloud-hosted or containerized systems and inherited security controls.

  • Working knowledge of DevSecOps security practices and tools.

  • Experience with VA OIT, VHA, or other federal health cybersecurity environments, including familiarity with VA Handbook 6500, VA Critical Security Controls, and VA security processes, strongly preferred.

Certifications:

  • ISC2 CISSP required.

  • ISACA CISM required or must be obtained within 12 months of hire.

  • GIAC Security Leadership Certification (GSLC) required or must be obtained within 12 months of hire.

Education:

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, or a related field.

  • Master’s degree preferred.

Clearance:

  • Tier 2 / Moderate Risk Background Investigation; ability to obtain a VA PIV credential.

Location:

  • Rockville, MD / Remote (CONUS).

  • Up to 10% CONUS travel.

Pay Range:

  • The suggested pay for this position ranges from $192,546 to $200,875.

  • The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience, and location.

  • Also, certain positions are eligible for additional forms of compensation, such as bonuses.

  • TISTA associates are eligible to participate in our comprehensive benefits plan! More information can be found here: https://tistatech.com/working-at-tista/

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.