About this role
Employment Type: Full-Time
** This position is contingent upon award of the contract.
About the Company
Athena Technology Group, Inc. (ATG) is a Service-Disabled Veteran Owned Small Business (SDVOSB) focused on Information Technology and Communications consulting, system engineering, integration, deployment and operation of state of the art command and control and information systems that deliver critical network centric solution to the warfighter. With a proven track record of technical support to our customers, we are looking for innovative industry professionals to join our team.
ATG is an Equal Opportunity/Affirmative Action Employer Minorities/Females/Vets/Disability
Job Summary
We are seeking a Risk and Compliance Analyst to join our team supporting the end-to-end security lifecycle across the VA enterprise. You will support the design and development of security reference architectures, solution architects, architectural analysis, models, security patterns, and governance frameworks. You will also support technical workstreams to ensure consistent delivery of security outcomes and architectural alignment.
Key Responsibilities
- Actively support and coordinate activities associated with the VAs Cybersecurity Supply Chain Risk Management (C-SCRM) program, ensuring robust risk mitigation across hardware, software, services, and vendor relationships.
- Identify and document data coverage gaps and overlaps between tools; recommend prioritization; and execute remediation actions to ensure full alignment with VA reporting requirements.
- Provide support for the VAs Quarterly and Annual FISMA reporting to CISA and OMB, including preparation and validation of all CDM required data.
- Ensure all network-connected assets, including managed, unmanaged, IoT, IoMT, and OT devices, are accurately discovered, inventoried, and classified/tagged in accordance with standards.
- Implement rigorous data validation, cleansing, and reconciliation processes to maintain accuracy, completeness, consistency, and integrity of asset data.
Qualifications
Required:
- Minimum of 7 years of Information Security Experience of which at least 5 years are of risk and compliance experience at a large company or Government agency similar in size/scope to GSA, IRS, DoD or VA.
An advanced degree (e.g. Masters or PhD) in related field may substitute for up to 2 years of the required experience.
- Bachelors degree in Business Administration, Business Management, Cybersecurity, Computer Science, Information Systems, Information Assurance, Information Security, Information Resource Management, or related fields.
- Certification in one or more of the following: IAT III, IAM III or IASAE III certifications.
IAT III/ IAM III / IASAE III certifications may be substituted for a relevant Bachelors degree or 4 years of relevant experience
- Expertise in risk management, compliance, audit, or related roles within an organization.
- Expertise conducting internal and external audits to assess compliance with regulatory requirements and organizational policies.
- Expertise developing and implementing risk management programs, including risk assessments, risk mitigation strategies, and continuous monitoring.
- Expertise policy development, documentation, and enforcement.
- Expertise handling and reporting compliance issues and coordinating with regulatory bodies.
- Must be a US citizen
Physical and Environmental Conditions
- Normal Office Environment. Requires Sitting, Standing, Near Acuity, Speaking with colleagues and customers, Listening, Sight, Use of hands/fingers.
Additional Benefits
- Performance Bonuses and annual salary reviews
- Health, dental, and vision insurance
- Short Term Disability, Long Term Disability, and Life Insurance
- 401(k) plan with company match
- Opportunities for professional growth and development
- A collaborative and inclusive work environment
ATG is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, religion, creed, color, national origin, ancestry, sex (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, medical condition, marital or domestic partner status, sexual orientation, gender, gender identity, gender expression and transgender status, mental disability or physical disability, genetic information, military or veteran status, citizenship, low-income status or any other status or characteristic protected by applicable law. Learn more about your rights under Federal EEO laws and supplemental language.