Position OverviewAleut Federal is seeking a Compliance, Asset, Security, & Configuration Management (CASC) Manager to own and mature the organization's compliance posture, IT asset lifecycle, security configuration standards, and change/configuration management practices. This is a full product-ownership role: the CASC Manager owns these areas end-to-end, from working day-to-day support tickets through to driving continuous improvement and maturity of the underlying processes. This is an individual-contributor role (no direct reports) requiring detailed, results-focused execution in a fully cloud-native, CMMC Level 2-obligated enterprise environment. The ideal candidate is highly organized, technically fluent across cyber, cloud, and compliance domains, and comfortable owning outcomes independently, from triaging a single ticket to redesigning a process.
Key Responsibilities:Compliance
- Own and maintain the organization's compliance posture against CMMC Level 2, NIST 800-171, and related federal contractor security requirements.
- Maintain and continuously improve the System Security Plan (SSP), policies, and control narratives, ensuring evidence and documentation stay audit-ready.
- Support C3PAO assessments and any follow-on assessments, coordinating evidence collection and remediation of findings.
- Track and manage POA&Ms (Plans of Action & Milestones) through closure.
- Monitor regulatory and contractual compliance changes and translate them into actionable internal requirements.
Asset Management
- Own the IT asset inventory (hardware, software, cloud resources) across commercial and GCC High environments, ensuring accuracy and completeness.
- Establish and maintain asset lifecycle processes: procurement, provisioning, tracking, and decommissioning/disposal.
- Conduct software inventory triage and licensing reviews to identify unauthorized or high-risk tools and reduce audit risk.
- Maintain shredding/disposal standards and documentation in accordance with applicable requirements (e.g., NSA/CSS EPL).
Security & Configuration Management
- Own baseline security configuration standards across endpoints, servers, and cloud environments, and monitor for drift.
- Manage the Change Control Board (CCB) process and associated risk-tiered change management framework.
- Partner with the Cloud Architect/Engineer and IT team on configuration hardening, sensitivity labeling, and access control alignment with compliance requirements.
- Support security incident response efforts by providing configuration, asset, and compliance context.
- Maintain Confluence/KB documentation for CASC processes, optimized for both human use and internal AI/RAG retrieval.
Ticket Ownership & Continuous Improvement
- Serve as the primary owner for compliance, asset, security configuration, and change management tickets in the IT service desk queue, from intake through resolution.
- Triage and resolve day-to-day requests (asset requests, access/configuration questions, compliance inquiries, change requests) within established SLAs.
- Use recurring ticket patterns and root-cause analysis to identify opportunities for process improvement, automation, and documentation.
- Own the full lifecycle of each CASC function as a "product" - from reactive ticket support up through proactive roadmap and maturity planning.
Cross-Functional
- Report on compliance, asset, and configuration risk posture to IT leadership on a regular cadence.
- Collaborate with Cloud Architecture and Program teams to ensure CASC practices are embedded in ongoing initiatives (e.g., dual-tenant M365 architecture, AI tooling governance).
- Drive process discipline and documentation rigor across all CASC areas.
Required Qualifications:- 10 years of related experience and a Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field.
- Must be a US Citizen.
- Strong technical proficiency across cybersecurity, cloud platforms (Microsoft Azure/M365 preferred), and compliance frameworks.
- Working knowledge of CMMC Level 2 / NIST 800-171 requirements and audit/assessment processes.
- Experience with IT asset management and lifecycle tracking.
- Experience with configuration/change management processes and tooling (e.g., Jira, ServiceNow, or similar).
- Highly detail-oriented, organized, and results-focused, with the ability to independently drive initiatives to completion.
- Strong written and verbal communication skills, including documentation and audit-facing materials.
- Comfortable working a service desk/ticket queue directly and balancing reactive support work with longer-term process ownership.
Preferred Qualifications:- 15 years of related experience and a Master's degree in Information Technology, Cybersecurity, or related field.
- Relevant IT/security certifications (e.g., CISSP, CISM, Security+, CySA+, CMMC-related certifications such as CCP/CCA, ITIL, or similar).
- Experience supporting a federal contractor or Alaska Native Corporation (ANC)/8(a) environment.
- Experience with dual-tenant Microsoft 365 environments (Commercial + GCC High).
- Familiarity with Microsoft Purview, Defender for Cloud, or similar governance/security tooling.
LocationHybrid with in person reporting at Colorado Springs CO, Reston VA, or Arlington VA
We will be accepting applications for this position until 4 October 2026.
Salary Range: $155K - $170K annually (final rate based on experience and location)
Aleut offers the following benefits to eligible employees:
- Health insurance
- Dental/Vision Insurance
- Paid Time Off
- Short- and Long-Term Disability
- Life insurance
- 401k, and match