This job was posted more than 40 days ago and might be expired.
Trilogy Federal logo

Cyber Security Analyst

Posted 3 months ago

OfficeArlington, VA103k - 118k USD
Trilogy Federal drives innovative solutions for complex business challenges across financial management, healthcare, and government industries. Our collaborative, client-first service approach, combined with our commitment to the rapid implementation of pragmatic solutions, has earned Trilogy an unparalleled reputation for delivering transformative results.

Trilogy Federal is seeking a Cyber Security Analyst to support the T4NG Consolidated Corporate Support Services (CCSS) program for the Department of Veterans Affairs (VA). This position is responsible for implementing and maintaining the security posture of VA enterprise systems and data, ensuring robust compliance with federal and VA security requirements, and supporting the ongoing authorization and risk management of critical VA platforms as part of a multi-disciplinary, agile technology team. 
 

Position Description: 

The Cyber Security Analyst is responsible for supporting the security posture of VA information systems and environments. This role ensures compliance with Federal, VA, and industry information security policies and standards, conducts continuous vulnerability identification and remediation, and participates in both internal and external security assessments. The position requires routine engagement with technical and program stakeholders to maintain and improve security controls and documentation, elevate incident response, and support the ongoing Authorization to Operate (ATO) for supported systems and applications. The Analyst operates within an agile, DevSecOps-focused environment, requiring proactive risk identification and collaboration with cross-functional teams to ensure the security and integrity of VA’s technical ecosystem. 

### Primary Responsibilities:
  • Perform ongoing vulnerability scanning, penetration testing, code review, and remediation in line with NIST SP 800-53 and related standards. 
  • Develop, document, review, and maintain Assessment & Authorization (A&A) artifacts, including security plans, risk assessments, and Plan of Action and Milestones (POA&M), supporting ATO submissions and renewals. 

  • Respond to, analyze, and report on security events and incidents, including notification to stakeholders within strict timeframes. Remediate security vulnerabilities within specified periods according to severity. 

  • Ensure compliance with Federal, VA, FISMA, NIST, HIPAA, Privacy Act, and organizational security and privacy directives. 

  • Complete mandatory and additional annual privacy and security training as required. 

  • Coordinate with VA technical staff, ISSOs, and integration teams to ensure proper migration, deployment, and operational support for new or updated systems. 

  • Provide support for the implementation of security controls on operating systems, application code, network infrastructure, and endpoints. Participate in audits and assessments, and provide evidence of compliance as requested. 

  • Monitor, track, and report on key security KPIs including vulnerability remediation timeframes, incident resolution metrics, and system security posture. 

  • Proactively apply OS and application patches; validate and report the effect of third-party patches. 

  • Develop and maintain robust operational and incident response documentation, participate in after-action reviews, and contribute to lessons learned for continuous process improvement 

  • ### Minimum Requirements:
    • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related discipline; equivalent practical experience may be considered. 

    • Minimum of 10 years of progressive experience in cyber security operations, risk assessment, vulnerability management, or information security compliance. 

    • Demonstrated knowledge of and experience with relevant federal cybersecurity standards. 

    • Experience conducting and reporting on vulnerability assessments, penetration testing, and security control testing. 

    • Familiarity with security tools including but not limited to Static Application Security Testing (SAST) tools (e.g., Micro Focus Fortify), penetration testing suites, SIEM/monitoring platforms. 

    • Experience supporting ATO and A&A processes, and maintaining compliance documentation in regulated environments. 

    • Understanding of DevSecOps practices and principles; collaborative experience with development, operations, and compliance teams. 

    • Ability to manage multiple applications. 

    • Ability to obtain a Public Trust Clearance. 

    ### Preferred Qualifications:
    • Familiarity with VA’s Governance, Risk and Compliance (GRC) tools and associated security workflows. 

    • Experience with security assurance for cloud platforms, including compliance with FedRAMP standards (AWS, Azure, etc.). 

    • Demonstrated expertise with application security, code quality assurance in large-scale and agile environments, and continuous delivery pipelines. 

    • Advanced knowledge of security and monitoring tools such as Jenkins, GitHub, SonarQube, AppDynamics, as well as experience with security architecture and incident response frameworks. 

    ### Benefits (including but not limited to):
  • Health, dental, and vision plans
  • Optional FSA
  • Paid parental leave
  • Safe Harbor 401(k) with employer contributions 100% vested from day 1
  • Paid time off and 11 paid holidays
  • No cost group term life/AD&D plan, and optional supplemental coverage
  • Pet insurance
  • Monthly phone and internet stipend
  • Tuition and training reimbursement
  • Trilogy Federal is an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics.
    Job details
    Workplace
    Office
    Location
    Arlington, VA
    Salary
    103k - 118k USD
    per year
    Trilogy Federal logo
    Trilogy Federal
    View company page

    Trilogy’s story began in 2009 when our founders decided to combine the best practices and lessons learned from working across both large and small organizations to launch a new company focused on delivering client-centric, high-quality solutions. Together, these leaders saw an opportunity to create a different type of company with the goal of supporting our Federal clients, with special emphasis on helping our nation’s Veterans. Influenced by two shared work experiences at other organizations, our company’s founders were determined to make the third chapter in their careers the very best it could be. They named this chapter Trilogy. Trilogy was founded with core value system that balances service delivery excellence with a people-centric culture. Building on our foundation of implementing, operating, and modernizing Financial Management systems, Trilogy has evolved to provide our clients and partners with a wide range of professional services via a collaborative, client-first approach to solving their most challenging problems. This approach, combined with our commitment to the rapid implementation of pragmatic solutions, has earned Trilogy an unparalleled reputation for delivering transformative results.

    Employees
    125
    Industry
    IT Services and IT Consulting
    Headquarters
    Arlington, Virginia
    Founded
    2009
    Company location
    Arlington, Virginia
    Specialties
    Data & Analytics, Systems Integration, Systems Implementation, Healthcare Transformation, Government Services, Benefits Optimization, Process & Resource Optimization, Policy Reform, Organizational Change Management, Audit Support Services, Financial Management Modernization, Financial Reporting, Risk & Compliance, Financial Management Operations, Enterprise Data Management, Digital Workplace, and Emerging Technologies

    Key team members

    Kim Nazi, Ph.D

    Kim Nazi, Ph.D

    Andre Adams

    Andre Adams

    Eric McNutt, PMP, CGFM

    Eric McNutt, PMP, CGFM

    Torsten Timm, CGFM, PMP, CMC, CSSBB

    Torsten Timm, CGFM, PMP, CMC, CSSBB

    Apply smarter with Jobr

    Jobr aggregates jobs directly from company career portals — no middlemen. Our team applies on your behalf with AI-tailored resumes, reviewed by a human before submission.

    Direct from company career pages
    AI-personalised cover letters
    Human review before every submit
    Application tracking & follow-ups