Cybersecurity Analyst; Remote
Bloomington, Hennepin County, Minnesota, USA
Listed on 2026-07-08
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Location
Remote in any United States jurisdiction not excluded from this job advertisement (states excluded: AK, CA, CO, CT, DC, HI, LA, MA, MN, MO, NE, NV, NH, NJ, NM, NY, ND, OR, PR, RI, VT, WA, WY).
Future Need
- Actively Interviewing.
Protect the compliance posture of a mission‑critical Department of Veterans Affairs (VA) cloud platform. As a Cybersecurity Analyst, you will manage POA&Ms, TRM submissions, and security documentation across hundreds of applications in a multi‑tenant Amazon Web Services (AWS) Gov Cloud environment.
Position DescriptionThe Cybersecurity Analyst manages POA&M tracking, TRM submissions, Business Partner Extranet (BPE) connection management, and supports security documentation for the platform.
Tasks/Activities- Creates and maintains POA&M within Service Now (SNOW) Continuous Authorization Monitoring (CAM) ensuring proper alignment to relevant NIST security control families and CCI.
- Drafts and maintains POA&M verbiage aligning with findings and clearly depicting mitigation strategy and timeline as required by the portfolio Information System Owner.
- Ensures POA&Ms are closed out once overcome by events (OBE), mitigated, or no longer relevant to the system to which they are assigned.
- Drafts justification verbiage and attends TRM approval board meetings for software and application usage requests; submits requests for TRM entry removal as usage becomes unneeded.
- Submits and maintains BPE connection requests including information gathering and staffing all required BPE admin team meetings.
- Catalogs and maintains a complete list of all BPE connections used within the platform and manages removal of connections no longer needed.
- Maintains and updates security documentation including SIA, ISVMP, PIA, PTA, and Configuration Management Plan artifacts for hosted applications.
- Reports issues and approaching TRM authorization ends with potential to affect managed applications to the appropriate portfolio Information System Owner.
- Contributes POA&M status, TRM activity, and BPE connection updates to the monthly RMF, security, and Authorization to Operate (ATO) status report.
The annual projected pay range for this position is $90,897 – $118,016, with consideration given to qualifications, experience, job responsibilities, and geographic location.
- Medical, dental, vision, and prescription drug coverage for you and your family.
- Life Insurance, short‑term disability and long‑term disability paid for by the Company.
- Supplemental coverages including Accident, Critical Illness, and Hospital.
- Additional Life insurance coverage for you and your dependents.
- 401(k) plan with various options to select based on your retirement goals.
5 years of experience in cybersecurity and information assurance.
Minimum EducationBachelor's Degree in cybersecurity, information technology, or related field;
CompTIA Security+ or Certified Authorization Professional (CAP) certification (preferred).
- Excellent experience creating and maintaining POA&Ms (e.g., periodic review, milestone updates, and mitigation plan detail).
- Excellent ability to ensure POA&M alignment to National Institute of Standards and Technology (NIST) security control families and Control Correlation Identifiers (CCI).
- Excellent experience drafting and maintaining TRM submissions.
- Excellent ability to submit and maintain Business Partner Extranet (BPE) connection requests (e.g., information gathering, request submission, and BPE admin team coordination).
- Excellent knowledge of POA&M closure criteria.
- Above average experience maintaining security documentation (e.g., Security Impact Analysis (SIA), Information System Vulnerability Management Plan (ISVMP), Privacy Impact Assessment (PIA), Privacy Threshold Analysis (PTA), and Configuration Management Plan artifacts).
- Experience supporting a federal agency.
- Excellent verbal and written communication skills.
- Assignment Location
- Remote. - Sedentary work:
Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).