Risk Analyst- Remote Booz Allen; a federal client 6 months Video Need 10 Years of experience he ERA Analyst role executes the VA Enterprise RiskAnalysis process using a custom ERA tool to identify key cyber security riskfactors in network connected medical devices and Special Purpose Systems (e.g.,building automation systems, physical security systems, operationaltechnology These risk factors are summarized, evaluated, and reported usingquantitative and qualitative scores to provide a VA authorizing official withawareness of the residual cyber risk prior to connecting these devices to the VAnetwork. The ERA Analyst must acquire, review and leverage system documentationand data gathered through questionnaires and interviews with customers in thefield and vendor/manufacturer representatives to accurately document criticalsecurity posture elements in a common reporting format. These elements includehardware/software inventory, communications profile, system interconnections,data types and stores, and the presence or lack of security controls, settingsand mechanisms for a given device type. The analyst works within theSpecialized Device Security Division Risk Management team and is expected tocollaborate with Federal and contractor team mates to achieve best outcomes forthe ERA process. You Have: Experiencewith Cybersecurity, risk management, or risk assessment for complex systems Experiencewith NIST SP 800-53 and NIST SP 800-30 Experience with documenting and depicting network topologyand network protocols Ability to engage directly with clients, and third partiesto facilitate enterprise risk analysis BA or BS degree in CS, EE, Engineering, or Technology and10 years' experience in a professional work environment or 18 years ofexperience in a professional work environment lieu of education Nice If You Have: Experience with cybersecurity analysis of medicaltechnology or Internet of Things (IoT) Experience with Governance, Risk, and Compliance (GRC) Experience with Assessment and Authorization (A&A) andeMASS Experience with Excel and Visio CompTIA Security or Certified Risk Management Professional(CRISC) or Certified in Risk and Information Systems Control (CRISC)