All roles

Cyber Security Analyst

Remote · USA Full-time New today
Trilogy Federal drives innovative solutions for complex business challenges across financial management, healthcare, and government industries. Our collaborative, client-first service approach, combined with our commitment to the rapid implementation of pragmatic solutions, has earned Trilogy an unparalleled reputation for delivering transformative results. Trilogy Federal is seeking a Cyber Security Analyst to support the T4NG Consolidated Corporate Support Services (CCSS) program for the Department of Veterans Affairs (VA). This position is responsible for implementing and maintaining the security posture of VA enterprise systems and data, ensuring robust compliance with federal and VA security requirements, and supporting the ongoing authorization and risk management of critical VA platforms as part of a multi-disciplinary, agile technology team.

Position Description

The Cyber Security Analyst is responsible for supporting the security posture of VA information systems and environments. This role ensures compliance with Federal, VA, and industry information security policies and standards, conducts continuous vulnerability identification and remediation, and participates in both internal and external security assessments. The position requires routine engagement with technical and program stakeholders to maintain and improve security controls and documentation, elevate incident response, and support the ongoing Authorization to Operate (ATO) for supported systems and applications. The Analyst operates within an agile, DevSecOps-focused environment, requiring proactive risk identification and collaboration with cross-functional teams to ensure the security and integrity of VA’s technical ecosystem.

Trilogy Federal is seeking a Cyber Security Analyst to support the T4NG Consolidated Corporate Support Services (CCSS) program for the Department of Veterans Affairs (VA). This position is responsible for implementing and maintaining the security posture of VA enterprise systems and data, ensuring robust compliance with federal and VA security requirements, and supporting the ongoing authorization and risk management of critical VA platforms as part of a multi-disciplinary, agile technology team.

Position Description

The Cyber Security Analyst is responsible for supporting the security posture of VA information systems and environments. This role ensures compliance with Federal, VA, and industry information security policies and standards, conducts continuous vulnerability identification and remediation, and participates in both internal and external security assessments. The position requires routine engagement with technical and program stakeholders to maintain and improve security controls and documentation, elevate incident response, and support the ongoing Authorization to Operate (ATO) for supported systems and applications. The Analyst operates within an agile, DevSecOps-focused environment, requiring proactive risk identification and collaboration with cross-functional teams to ensure the security and integrity of VA’s technical ecosystem.

Trilogy Federal is seeking a Cyber Security Analyst to support the T4NG Consolidated Corporate Support Services (CCSS) program for the Department of Veterans Affairs (VA). This position is responsible for implementing and maintaining the security posture of VA enterprise systems and data, ensuring robust compliance with federal and VA security requirements, and supporting the ongoing authorization and risk management of critical VA platforms as part of a multi-disciplinary, agile technology team.    Position Description:  The Cyber Security Analyst is responsible for supporting the security posture of VA information systems and environments. This role ensures compliance with Federal, VA, and industry information security policies and standards, conducts continuous vulnerability identification and remediation, and participates in both internal and external security assessments. The position requires routine engagement with technical and program stakeholders to maintain and improve security controls and documentation, elevate incident response, and support the ongoing Authorization to Operate (ATO) for supported systems and applications. The Analyst operates within an agile, DevSecOps-focused environment, requiring proactive risk identification and collaboration with cross-functional teams to ensure the security and integrity of VA’s technical ecosystem.  This range is not a guarantee of compensation or salary, as Trilogy Federal conducts an individual equity review for every candidate based on experience, location, education, industry experience, and comparisons to internal pay bands. In addition to salary, Trilogy offers robust benefits including medical/dental/vision insurance coverage, 401(k) match, paid holidays, paid time off, tuition reimbursement, and a very supportive work/life balance. Primary Responsibilities:
  • Perform ongoing vulnerability scanning, penetration testing, code review, and remediation in line with NIST SP 800-53 and related standards.
  • Develop, document, review, and maintain Assessment & Authorization (A&A) artifacts, including security plans, risk assessments, and Plan of Action and Milestones (POA&M), supporting ATO submissions and renewals.

  • Respond to, analyze, and report on security events and incidents, including notification to stakeholders within strict timeframes. Remediate security vulnerabilities within specified periods according to severity.

  • Ensure compliance with Federal, VA, FISMA, NIST, HIPAA, Privacy Act, and organizational security and privacy directives.

  • Complete mandatory and additional annual privacy and security training as required.

  • Coordinate with VA technical staff, ISSOs, and integration teams to ensure proper migration, deployment, and operational support for new or updated systems.

  • Provide support for the implementation of security controls on operating systems, application code, network infrastructure, and endpoints. Participate in audits and assessments, and provide evidence of compliance as requested.

  • Monitor, track, and report on key security KPIs including vulnerability remediation timeframes, incident resolution metrics, and system security posture.

  • Proactively apply OS and application patches; validate and report the effect of third-party patches.

  • Develop and maintain robust operational and incident response documentation, participate in after-action reviews, and contribute to lessons learned for continuous process improvement

  • Minimum Requirements:
    • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related discipline; equivalent practical experience may be considered.

    • Minimum of 10 years of progressive experience in cyber security operations, risk assessment, vulnerability management, or information security compliance.

    • Demonstrated knowledge of and experience with relevant federal cybersecurity standards.

    • Experience conducting and reporting on vulnerability assessments, penetration testing, and security control testing.

    • Familiarity with security tools including but not limited to Static Application Security Testing (SAST) tools (e.g., Micro Focus Fortify), penetration testing suites, SIEM/monitoring platforms.

    • Experience supporting ATO and A&A processes, and maintaining compliance documentation in regulated environments.

    • Understanding of DevSecOps practices and principles; collaborative experience with development, operations, and compliance teams.

    • Ability to manage multiple applications.

    • Ability to obtain a Public Trust Clearance.

    Preferred Qualifications:
    • Familiarity with VA’s Governance, Risk and Compliance (GRC) tools and associated security workflows.

    • Experience with security assurance for cloud platforms, including compliance with FedRAMP standards (AWS, Azure, etc.).

    • Demonstrated expertise with application security, code quality assurance in large-scale and agile environments, and continuous delivery pipelines.

    • Advanced knowledge of security and monitoring tools such as Jenkins, GitHub, SonarQube, AppDynamics, as well as experience with security architecture and incident response frameworks.

    Benefits (including but not limited to):
  • Health, dental, and vision plans
  • Optional FSA
  • Paid parental leave
  • Safe Harbor 401(k) with employer contributions 100% vested from day 1
  • Paid time off and 11 paid holidays
  • No cost group term life/AD&D plan, and optional supplemental coverage
  • Pet insurance
  • Monthly phone and internet stipend
  • Tuition and training reimbursement
  • Trilogy Federal is an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. Apply To This Job

    Related roles

    Angular Developer

    Remote · USA Full-time

    [Remote] Financial Services Marketing and Event Coordinator

    Remote · USA Full-time

    Partner Growth Director, Digital Commerce

    Remote · USA Full-time

    Sales Account Executive (Greenville, SC)

    Remote · USA Full-time

    Sales Account Executive (Virginia Beach, VA)

    Remote · USA Full-time

    Experienced Tax Associate

    Remote · USA Full-time

    Outside Plant Engineer

    Remote · USA Full-time

    Retail Merchandiser

    Remote · USA Full-time

    Retail Merchandiser

    Remote · USA Full-time

    Sr Mgr, Portfolio Management (LAKE FOREST, IL, US, 60045-5202)

    Remote · USA Full-time

    Coordinator, Research Data - Leukemia

    Remote · USA Full-time

    Multi-Line Claims Adjuster - Florida/ Miami Area

    Remote · USA Full-time

    Communications and Public Relations Spring 2025 Intern - Remote

    Remote · USA Full-time

    Sr Category Manager, Blink

    Remote · USA Full-time

    Experienced Online Chat Operator – Delivering Exceptional Customer Support and Driving Client Satisfaction through Effective Communication and Problem-Solving Skills

    Remote · USA Full-time

    Customer Support Specialist (9:30 AM - 6:00 PM Hybrid/Remote)

    Remote · USA Full-time

    Data Entry Assistant – Remote Database Management, Customer Information Coordination, and Accuracy‑Focused Record Keeping Specialist

    Remote · USA Full-time

    Experienced Full Stack Data Entry Specialist – Remote Data Management and Compliance

    Remote · USA Full-time

    Thought Leader Liaison, PAH / PH-ILD

    Remote · USA Full-time

    Experienced Jr Data Entry Clerk – Remote Opportunity to Thrive in arenaflex's Dynamic Environment

    Remote · USA Full-time