Demo

Senior Cybersecurity A&A Risk Analyst

Cherokee Federal
Tulsa, OK Full Time
POSTED ON 4/16/2026
AVAILABLE BEFORE 6/15/2026

Senior Cybersecurity A&A Risk Analyst

Position Summary

The Senior Cybersecurity Assessment & Authorization (A&A) Risk Analyst provides advanced governance, risk, and compliance (GRC) support to federal information systems in alignment with the Federal Information Security Modernization Act (FISMA) and the NIST Risk Management Framework (RMF).

This position is responsible for managing external service authorization activities, conducting security risk assessments, and supporting NSF's continuous monitoring efforts. The role requires strong analytical, documentation, and stakeholder engagement skills to ensure federal systems maintain compliance with applicable federal laws, regulations, and NSF directives.

Essential Duties and Responsibilities

Assessment & Authorization (A&A)

  • Manage full lifecycle Risk Management Framework (RMF) activities in accordance with NIST Special Publication 800-37.

  • Develop, review, and maintain security authorization documentation, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POA&Ms).

  • Review and assess FedRAMP authorization packages, and package updates, to support the evaluation and use of cloud services.

  • Monitor ATO packages in the FedRAMP Secure Repository

  • Communicate with system owners, information systems security officers (ISSOs), Cloud Service Providers, and security stakeholders frequently to review significant system changes and ensure continued compliance with federal security requirements.

  • Evaluate and validate implementation of security controls defined in NIST Special Publication 800-53 Rev. 5, including inherited and agency-implemented controls.

  • Conduct risk assessments using methodologies consistent with NIST Special Publication 800-30 and provide risk analysis and recommendations to Authorizing Officials and senior stakeholders.

  • Support continuous monitoring and ongoing authorization activities by reviewing vulnerability scans, tracking POA&Ms, and coordinating remediation efforts.

Governance, Risk & Compliance (GRC)

  • Peer review cybersecurity policies, standards, procedures, and implementation guidance.

  • Perform regulatory and policy analysis to ensure alignment with federal requirements and agency directives.

  • Conduct gap analyses to assess compliance posture and recommend remediation strategies.

  • Assist in development of control overlays, baseline updates, and security control tailoring guidance.

  • Provide subject matter expertise in governance discussions.

  • Support enterprise reporting activities, including risk metrics and compliance dashboards in ServiceNow.

Compliance & Oversight Support

  • Provide documentation and analysis support for internal and external reviews, including FISMA reporting activities.

  • Assist in preparing responses to oversight inquiries and tracking corrective actions.

  • Perform quality assurance reviews of security documentation to ensure accuracy and consistency.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Public Policy, or related discipline (or equivalent experience).

  • Professional certification(s) such as CISSP, CISM, or CAP.

  • Minimum of 7 years of progressive cybersecurity experience, including at least 4 years supporting federal RMF/A&A efforts.

  • Demonstrated experience implementing the NIST Risk Management Framework.

  • Strong knowledge of:

  • Federal Risk and Authorization Management Program (FedRAMP)

  • NIST Special Publication 800-53 Rev. 5

  • Federal Information Security Modernization Act (FISMA)

  • Federal Zero Trust Strategy (OMB M-22-09)

  • Familiarity with federal cloud security requirements and FedRAMP-authorized environments.

  • Experience supporting Moderate and/or High impact systems.

  • Experience with Microsoft 365 office applications.

  • Excellent written and verbal communication skills.

  • Ability to engage effectively with technical teams and executive leadership.

  • Active Public Trust clearance or ability to obtain.

Preferred Qualifications

  • Experience with ServiceNow, CSAM and/or comparable GRC tools.

  • Familiarity with Atlassian Confluence and JIRA.

  • Experience contributing to enterprise-level cybersecurity policy initiatives.

  • Familiarity with guidance pertaining to responsible AI usage by federal agencies (e.g., Executive Order 13960, OMB M-25-21 and M-25-22).

  • Experience supporting federal research or grant-management systems.

Core Competencies

  • Federal Cybersecurity Governance

  • Risk Assessment & Analysis

  • Policy Development & Regulatory Interpretation

  • Technical Documentation & Quality Assurance

  • Stakeholder Engagement

  • Analytical Problem Solving

Work Environment

This is a full-time remote position supporting Cherokee Federal's cybersecurity contract with the U.S. National Science Foundation in Alexandria, VA. This position reports to the Cybersecurity Oversight and Compliance Lead, operates within a structured federal compliance environment, and requires collaboration with system owners, security personnel, program offices, and senior stakeholders. The role supports ongoing authorization, governance initiatives, and periodic oversight reviews to maintain a strong cybersecurity posture across NSF systems.

About Criterion Systems

Criterion Systems LLC is a part of Cherokee Federal - the division of tribally owned federal contracting companies owned by Cherokee Nation Businesses. As a trusted partner for more than 60 federal clients, Cherokee Federal LLCs are focused on building a brighter future, solving complex challenges, and serving the government's mission with compassion and heart. To learn more about Criterion, visit cherokee-federal.com.

Cherokee Federal is a military-friendly employer. Veterans and active military transitioning to civilian status are encouraged to apply.

  • Cybersecurity RMF Analyst

  • Cybersecurity GRC Analyst

  • Information Security Risk Analyst

  • Cybersecurity Compliance Analyst

  • NIST RMF / NIST 800-53

  • FedRAMP / ATO Authorization

  • FISMA Compliance

  • Security Authorization (A&A)

  • ServiceNow GRC / Cyber Risk Management

  • Federal Cybersecurity Risk Management

#CherokeeFederal #LI-SM2 #AppC

Legal Disclaimer:All qualified applicants will receive consideration for employment without regard to protected veteran status, disability or any other status protected under applicable federal, state or local law.


We are an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected Veteran status, gender identity and sexual orientation. If you’d like more information about your EEO rights as an applicant under the law, please copy and paste the links to the following two sites: EEO Statement | EEO Poster

If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process, or are limited in the ability or unable to access or use this online application process and need an alternative method for applying, you may email “CNB.Compliance@cn-bus.com” for assistance. This email address is for accommodation requests only and cannot be used to inquire about the application process or status.

 

Salary.com Estimation for Senior Cybersecurity A&A Risk Analyst in Tulsa, OK
$95,307 to $120,616
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Senior Cybersecurity A&A Risk Analyst?

Sign up to receive alerts about other jobs on the Senior Cybersecurity A&A Risk Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Cherokee Federal

  • Cherokee Federal Washington, DC
  • Senior Construction Manager Work Location: Joint Base Andrews CNDS is seeking an experienced Construction Manager to support the planning, design, and cons... more
  • 8 Days Ago

  • Cherokee Federal Tulsa, OK
  • Compile and analyze basic financial information for the organization. Assist with the development of revenue/expense analyses, projections, and reports. En... more
  • 8 Days Ago

  • Cherokee Federal Tulsa, OK
  • Corridor Specialist This position requires an active Public Trust clearance or the ability to obtain a Public Trust clearance to be considered. The Corrido... more
  • 8 Days Ago

  • Cherokee Federal Tulsa, OK
  • Junior Healthcare IT Project Manager ***As required by our governmental client, this position requires being a US Citizen AND an active Public Trust or the... more
  • 8 Days Ago


Not the job you're looking for? Here are some other Senior Cybersecurity A&A Risk Analyst jobs in the Tulsa, OK area that may be a better fit.

  • GO SECURITY PRO Tulsa, OK
  • Position/Salary: Cybersecurity Consultant – Governance, Risk, and Compliance. Go Security Pro is seeking a full-time cybersecurity professional for our Gov... more
  • 21 Days Ago

  • EY Tulsa, OK
  • Location: Anywhere in Country At EY, we’re all in to shape your future with confidence. We’ll help you succeed in a globally connected powerhouse of divers... more
  • 20 Days Ago

AI Assistant is available now!

Feel free to start your new journey!