VA Cybersecurity and Compliance Specialist

Posted Yesterday
Be an Early Applicant
Hiring Remotely in United States
Remote
Entry level
Information Technology • Consulting
The Role
Lead federal and VA cybersecurity compliance activities for HSM and post-quantum cryptography environments. Support RMF, ATO preparation and renewal, continuous monitoring, FIPS 140-3 and CMVP evidence, vulnerability and patch compliance, security reviews, incident response, and authorization documentation. Translate technical HSM, PKI, and cryptographic configurations into compliance artifacts and coordinate with VA security stakeholders, including ISSOs, OIS, CORs, and program teams. The role is primarily remote with limited customer-site travel.
Summary Generated by Built In

Iron Bow Technologies is for people who believe trust is paramount, transformation is embraced, and the future is here, because "What we do matters!"

We are a next generation solutions provider, delivering mission success across government, healthcare, and commercial industries. Iron Bow relies on our passionate people, long standing partnerships, and strategic thinking to solve your most critical challenges.

Whether we team with clients, colleagues, or partners, we put each other first. It’s The Iron Bow Way.

THE OPPORTUNITY

The VA Cybersecurity and Compliance Specialist will lead cybersecurity compliance, RMF, ATO-support, FIPS compliance, and security documentation activities for the HSM and post-quantum cryptography environment. The position will serve as the principal interface between technical engineering activities and the customer’s cybersecurity/authorization requirements. Primarily remote. Limited travel to customer facility.

The candidate shall demonstrate experience supporting VA or Federal agency ATO processes, NIST SP 800-37 RMF, FIPS 140-3 compliance, ATO packages, CMVP documentation, and cryptographic compliance artifacts

HOW YOU'LL MAKE AN IMPACT

  • Support VA cybersecurity, RMF, ATO, continuous monitoring, and compliance activities.
  • Develop, review, and maintain cybersecurity and authorization artifacts supporting VA systems.
  • Support RMF activities consistent with NIST SP 800-37 and applicable NIST SP 800-53 controls.
  • Maintain and validate FIPS 140-3 CMVP evidence for HSM platforms.
  • Review CMVP/CAVP validation certificates, algorithm support matrices, OEM security attestations, and cryptographic compliance evidence.
  • Support VA ISSO, OIS, COR, and program stakeholders with technical evidence required for ATO and ATO renewal.
  • Evaluate proposed HSM configuration, firmware, integration, and architectural changes for security/compliance impact.
  • Support vulnerability and patch compliance, including CISA KEV/BOD requirements.
  • Coordinate security review of HSM upgrades, migrations, and production changes.
  • Ensure alignment with VA Handbook 6500, VA Critical Security Controls, FICAM/ICAM, PIV/CAC, Zero Trust, and applicable VA security policies.
  • Support security incident response, documentation, root-cause analysis, and corrective actions.
  • Review technical deliverables for Federal and VA cybersecurity compliance.
  • Support compliance documentation associated with FedRAMP-authorized cloud components, if included in the solution.

The candidate supports ATO renewal to provide current FIPS 140-3 CMVP certificates, algorithm-support matrices, vendor security attestations, and technical evidence packages for the VA ISSO, OIS, and formal ATO submissions. 

SKILLS THAT DRIVE SUCCESS

  • Federal cybersecurity compliance and RMF experience.
  • Experience supporting Federal or VA ATO processes.
  • Working knowledge of NIST SP 800-37 and NIST SP 800-53.
  • FIPS 140-3 compliance experience.
  • Experience preparing or supporting ATO packages.
  • Experience with CMVP documentation and cryptographic compliance artifacts.
  • Ability to translate highly technical HSM/PKI/cryptographic configurations into security and authorization evidence.

WHAT SETS YOU APART

  • Prior VA OIT cybersecurity experience.
  • CISSP, CAP/CGRC, CISM, Security+, or comparable cybersecurity credentials.
  • Experience with VA Handbook 6500 and VA security/authorization processes.
  • Experience with FedRAMP and Federal Zero Trust requirements.

WHY YOU'LL LOVE IT!

  • You will be part of a company that is growing quickly and values your voice, ideas, and experience
  • You will be a key contributor to Iron Bow’s transformational shift in how we deliver value to both customers and employees.
  • You will have the pleasure of working with passionate professionals in a culture that fosters a workplace where everyone feels respected, supported and empowered to succeed.

OUR EQUAL OPPORTUNITY EMPLOYER COMMITMENT

Iron Bow Technologies is an Equal Opportunity Employer and is committed to the principle of equal employment opportunity for all employees and to providing employees with a work environment free of discrimination and harassment.  All employment decisions at Iron Bow are based on relevant business considerations, such as operational needs, job requirements and individual qualifications, without regard to race, color, religion, sex, sexual orientation, gender identity and/or gender expression, pregnancy, national origin, age, disability, status as a protected veteran or any other characteristic prohibited by law. Iron Bow will not tolerate discrimination or harassment based on any of these characteristics.   

Skills Required

  • Experience supporting VA or federal agency ATO processes
  • Experience with NIST SP 800-37 Risk Management Framework
  • Working knowledge of NIST SP 800-53 controls
  • Experience with FIPS 140-3 compliance
  • Experience preparing or supporting ATO packages
  • Experience with CMVP documentation and cryptographic compliance artifacts
  • Ability to translate technical HSM, PKI, and cryptographic configurations into security and authorization evidence
  • Prior VA OIT cybersecurity experience
  • CISSP, CAP/CGRC, CISM, Security+, or comparable cybersecurity credential
  • Experience with VA Handbook 6500 and VA security and authorization processes
  • Experience with FedRAMP and Federal Zero Trust requirements

Iron Bow Technologies Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Iron Bow Technologies and has not been reviewed or approved by Iron Bow Technologies.

  • Healthcare Strength Health coverage is characterized as comprehensive across medical, dental, and vision, alongside life and disability protection. Health insurance is also framed as a strong point, with family premiums sometimes described as reasonable.
  • Leave & Time Off Breadth Time-off offerings are positioned as flexible, supported by remote and hybrid-work programs. The overall package includes a range of leave benefits that can support work–life needs.
  • Parental & Family Support Family-related leave is portrayed as a differentiator, including parental leave and even “grandparents’ leave.” These elements broaden support beyond standard time-off programs.

Iron Bow Technologies Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Herndon, Virginia
1,017 Employees
Year Founded: 1983

What We Do

We deliver mission success through next-generation solutions across government, healthcare, and commercial markets. Iron Bow relies on our passionate people, long-standing partnerships, and strategic thinking to solve your most critical challenges. At Iron Bow, our people believe in a culture of transformation and that the future of technology is here to deliver our clients’ missions. When it comes to our people, we care about the customer's mission, value a culture of teamwork, and believe deeply in the power of technology to transform lives and communities. #WhatWeDoMatters Disclaimer: Your privacy and security are important to us. Iron Bow Technologies does not request payment information, personal financial information, or any form of processing fees as part of our recruitment process. Please be cautious of any requests for such information as they may be scams. Our interviews and communications are conducted through official channels only. This includes emails from verified company domains and phone calls or video conferences scheduled through our official systems. If you are ever in doubt about the legitimacy of any communication purportedly from us, please do not hesitate to contact us directly at our official contact points for verification. The only domain we use is ironbow.com

Similar Jobs

Nexthink Logo Nexthink

Client Director- North Central

Artificial Intelligence • Big Data • Cloud • Information Technology • Machine Learning • Software
Remote or Hybrid
Chicago, IL, USA
1200 Employees
140K-176K Annually

Nexthink Logo Nexthink

Client Director- North Central

Artificial Intelligence • Big Data • Cloud • Information Technology • Machine Learning • Software
Remote or Hybrid
Minneapolis, MN, USA
1200 Employees
140K-176K Annually
Remote or Hybrid
2 Locations
289097 Employees
Easy Apply
Remote
United States
900 Employees
175K-195K Annually

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account