ATO Manager- HEDX - VHA

Remote • Posted 4 hours ago • Updated 4 hours ago
Full Time
Remote
Company Branding Image
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Information Assurance
  • Electronic Data Interchange
  • Health Care
  • Microsoft Exchange
  • SAP GRC
  • Quality Assurance
  • System Security
  • SSP
  • Configuration Management
  • Documentation
  • Auditing
  • Systems Architecture
  • Privacy
  • Collaboration
  • Information System Security
  • Information Security
  • Risk Management Framework
  • RMF
  • Facilitation
  • Continuous Monitoring
  • Security Controls
  • Risk Assessment
  • Reporting
  • Status Reports
  • Leadership
  • Regulatory Compliance
  • Network
  • Cloud Computing
  • Internet
  • Intrusion Detection
  • PKI
  • Authentication
  • Agile
  • Conflict Resolution
  • Problem Solving
  • Security Clearance
  • Management
  • Authorization
  • eMASS
  • HIPAA
  • HITECH
  • Cyber Security
  • DoD
  • CISSP
  • CISM
  • Computer Science
  • Software Engineering
  • Software Development
  • DICE
  • Law

Summary

ATO Manager / Sr. Cyber Security Engineer

Location: Remote

Description:

Seeking ahighly skilled ATO Manager to lead our compliance and information assurance initiatives for the Department of Veterans Affairs (VA) Health Electronic Data Interchange (EDI) Xchange (HEDX) program.

Leveraging extensive IT experience across a vast array of IT systems-involving both end-user health applications and enterprise-level EDI networks-you will serve as the principal cybersecurity authority driving HEDX through the federal Risk Management Framework (RMF). You will design, implement, and assess systems to ensure they meet agency Cyber Security policy and HIPAA regulations. As the primary liaison between technical teams and VA Authorizing Officials, you will utilize your deep expertise in CAM, cybersecurity tools, network topologies, intrusion detection, PKI, and secured networks to achieve and sustain the ATO for this critical healthcare data exchange.

Job Responsibilities:

VA Authorization Artifacts & GRC, CAM Management
  • Lead the development, review, maintenance, and quality assurance of comprehensive VA security authorization packages within the Continuous Authorization and Monitor (CAM) system.
  • Develop and maintain required RMF and ATO artifacts, including the System Security Plan (SSP), Configuration Management Plan (CMP), Privacy Impact Assessment (PIA), Plans of Action and Milestones (POA&Ms), security control implementation narratives, assessment evidence, and supporting documentation.
  • Ensure authorization artifacts remain accurate, complete, audit-ready, and perfectly aligned with the system architecture, network topologies, secured networks, implemented security controls, and current risk posture.


VA Stakeholder & Agency Coordination
  • Serve as a principal cybersecurity and authorization liaison between the HEDX program and VA security, privacy, technical, and program stakeholders.
  • Collaborate with Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), Security Control Assessors (SCAs), Authorizing Officials (AOs), the VA Office of Information Security (OIS), system owners, and engineering teams to coordinate RMF activities across a vast array of IT systems involving end-user as well as enterprise-level networks.
  • Design and implement systems that meet agency Cyber Security policy and regulations, resolving compliance issues, addressing assessment findings, and facilitating successful authorization decisions.


Continuous Monitoring (ConMon) & ATO Sustainment
  • Establish and lead a comprehensive Continuous Monitoring (ConMon) program to maintain HEDX's security and compliance posture throughout the authorization lifecycle.
  • Monitor security controls, vulnerabilities, assessment findings, configuration and system changes, POA&Ms, and remediation activities. Ensure critical defensive measures-including Intrusion Detection systems and PKI implementations-are continuously evaluated so cybersecurity risks are identified and addressed within established timelines.
  • Proactively manage authorization dependencies and emerging risks to support ATO maintenance, renewal, and continued operational authorization.

POA&M, Vulnerability & Remediation Management
  • Own and manage the lifecycle of cybersecurity findings and POA&Ms, from initial risk assessment and assignment through remediation, evidence validation, and closure.
  • Partner with application, infrastructure, network, cloud, engineering, and security teams to prioritize vulnerabilities and control deficiencies, leveraging enterprise Cyber Security Tools to establish corrective actions.
  • Ensure remediation is completed in accordance with applicable VA and federal cybersecurity requirements.

Authorization Readiness, Risk Reporting & Governance
  • Lead ATO readiness reviews, security assessments, and authorization preparation activities to ensure the HEDX environment remains prepared for VA security reviews and authorization decisions.
  • Develop and communicate cybersecurity status reports, risk summaries, security metrics, outstanding findings, POA&M status, remediation progress, and authorization milestones to program leadership and VA stakeholders.
  • Provide clear visibility into the system's overall security posture, residual risk, compliance status, and ATO readiness.

Required Skills:

Designing and implementing systems that strictly meet Veterans Affairs Cyber Security policies and regulations.

Administration, assessment, or engineering of enterprise Cyber Security Tools.

Designing and securing complex network topologies and secured networks (e.g., VA Enterprise Cloud, Trusted Internet Connections (TIC)).

Deploying and managing Intrusion Detection systems.

Implementing and managing PKI (Public Key Infrastructure) for user authentication and secure data transmission.

Experience working in a fast-paced, Agile software development environment

Must possess excellent problem-solving skills


Must be able to obtain and maintain a Public Trust Security clearance.

Desired Skills and Experience:

Extensive direct experience with VA Continuous Authorization and Monitor (CAM) and eMASS.

Deep understanding of VA Directive 6500, VA Handbook 6500.3 (Certification and Accreditation), and HIPAA/HITECH security standards.

Active cybersecurity certifications aligned with DoD 8140/8570 or VA equivalents (e.g., CISSP, CISM, CASP+, or CGRC).

Education and Experience:

Masters's degree in computer science, Software Engineering, or a related field (or equivalent experience) 10+ years of experience in software development.

10 years of additional relevant experience may be substituted for education

#dice

#CJ

About HigherEchelon, Inc.

HigherEchelon, Inc. (HE) is a service-disabled veteran-owned small business (SDVOSB) with offerings in Engineering, Gaming, Human Capital, Enterprise Technology, and Cyber Solutions. HigherEchelon aims to be the premier trusted partner in organizational excellence and achieves this through sustained investment in talent and the employee experience. HigherEchelon puts the employee first to better serve customer needs and sustain excellence.

HigherEchelon offers competitive full-time benefits including paid vacation and holidays, 401(k) matching, full health/dental/vision coverage, plus much more. For on-site and remote employees, flexible work schedules are offered when authorized.

By joining our team, you are choosing to embark on a journey towards excellence as a valued team member and trusted partner. We appreciate your inquiry and look forward to discussing the opportunity further.

EOE/Minorities/Females/Veterans/Disabled:

HigherEchelon, Inc. is an Equal Employment Opportunity employer and provides reasonable accommodation for qualified individuals with disabilities and disabled veterans in its job application procedures.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, genetic information, citizenship, ancestry, marital status, protected veteran status, disability status or any other status protected by federal, state, or local law. HigherEchelon, Inc. participates in E-Verify.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 90832636
  • Position Id: 006Qr00000mcbXZIAY
  • Posted 4 hours ago

Company Info

About HigherEchelon

Today's rapidly changing world requires resilient and adaptive leaders armed with efficient processes and modern technology to be effective. As trusted partners in organizational excellence, HE invests in people, processes, and technology to drive organizational performance to a higher level. Founded on performance psychology and coupled with human capital, and technological service offerings, we work with organizations to address the most complex and ambiguous challenges. HE's competitive edge resides in our ability to bring these three domains together to maximize human and organizational excellence.
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

Today

Full-time

Remote

Today

Full-time

Remote

Today

Full-time

Remote

Today

Full-time

Search all similar jobs