Compliance, Asset, Security, & Configuration Management (CASC) Manager

ARS Aleut Construction

$155K — $170K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10 years of related experience and a Bachelor's degree in IT, Cybersecurity, Computer Science, or related field.
  • Must be a US Citizen.
  • Strong technical proficiency in cybersecurity, cloud platforms (preferably Microsoft Azure/M365), and compliance frameworks.
  • Working knowledge of CMMC Level 2 / NIST 800-171 requirements and audit processes.
  • Experience with IT asset management and lifecycle tracking.
  • Proficient in configuration/change management processes and tools (e.g., Jira, ServiceNow).
  • Detail-oriented and organized with a focus on results, capable of driving initiatives independently.
  • Strong communication skills, with a focus on documentation and audit readiness.

Responsibilities

  • Own and enhance the compliance posture against CMMC Level 2 and NIST 800-171.
  • Maintain and improve the System Security Plan (SSP) and related documentation.
  • Support and coordinate C3PAO assessments and remediation efforts.
  • Manage the IT asset inventory for accuracy and completeness.
  • Establish asset lifecycle processes from procurement to disposal.
  • Own baseline security configuration standards and monitor for compliance drift.
  • Lead the Change Control Board process for managing risks in configuration changes.
  • Serve as the primary point of contact for compliance and asset management tickets, ensuring timely resolution.

Benefits

  • Health insurance
  • Dental/Vision Insurance
  • Paid Time Off
  • Short- and Long-Term Disability
  • Life insurance
  • 401k plan with company match
Full Job Description
Position Overview

Aleut Federal is seeking a Compliance, Asset, Security, & Configuration Management (CASC) Manager to own and mature the organization's compliance posture, IT asset lifecycle, security configuration standards, and change/configuration management practices. This is a full product-ownership role: the CASC Manager owns these areas end-to-end, from working day-to-day support tickets through to driving continuous improvement and maturity of the underlying processes. This is an individual-contributor role (no direct reports) requiring detailed, results-focused execution in a fully cloud-native, CMMC Level 2-obligated enterprise environment. The ideal candidate is highly organized, technically fluent across cyber, cloud, and compliance domains, and comfortable owning outcomes independently, from triaging a single ticket to redesigning a process.

Key Responsibilities:

Compliance

  • Own and maintain the organization's compliance posture against CMMC Level 2, NIST 800-171, and related federal contractor security requirements.
  • Maintain and continuously improve the System Security Plan (SSP), policies, and control narratives, ensuring evidence and documentation stay audit-ready.
  • Support C3PAO assessments and any follow-on assessments, coordinating evidence collection and remediation of findings.
  • Track and manage POA&Ms (Plans of Action & Milestones) through closure.
  • Monitor regulatory and contractual compliance changes and translate them into actionable internal requirements.


Asset Management

  • Own the IT asset inventory (hardware, software, cloud resources) across commercial and GCC High environments, ensuring accuracy and completeness.
  • Establish and maintain asset lifecycle processes: procurement, provisioning, tracking, and decommissioning/disposal.
  • Conduct software inventory triage and licensing reviews to identify unauthorized or high-risk tools and reduce audit risk.
  • Maintain shredding/disposal standards and documentation in accordance with applicable requirements (e.g., NSA/CSS EPL).


Security & Configuration Management

  • Own baseline security configuration standards across endpoints, servers, and cloud environments, and monitor for drift.
  • Manage the Change Control Board (CCB) process and associated risk-tiered change management framework.
  • Partner with the Cloud Architect/Engineer and IT team on configuration hardening, sensitivity labeling, and access control alignment with compliance requirements.
  • Support security incident response efforts by providing configuration, asset, and compliance context.
  • Maintain Confluence/KB documentation for CASC processes, optimized for both human use and internal AI/RAG retrieval.


Ticket Ownership & Continuous Improvement

  • Serve as the primary owner for compliance, asset, security configuration, and change management tickets in the IT service desk queue, from intake through resolution.
  • Triage and resolve day-to-day requests (asset requests, access/configuration questions, compliance inquiries, change requests) within established SLAs.
  • Use recurring ticket patterns and root-cause analysis to identify opportunities for process improvement, automation, and documentation.
  • Own the full lifecycle of each CASC function as a "product" - from reactive ticket support up through proactive roadmap and maturity planning.


Cross-Functional

  • Report on compliance, asset, and configuration risk posture to IT leadership on a regular cadence.
  • Collaborate with Cloud Architecture and Program teams to ensure CASC practices are embedded in ongoing initiatives (e.g., dual-tenant M365 architecture, AI tooling governance).
  • Drive process discipline and documentation rigor across all CASC areas.


Required Qualifications:

  • 10 years of related experience and a Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field.
  • Must be a US Citizen.
  • Strong technical proficiency across cybersecurity, cloud platforms (Microsoft Azure/M365 preferred), and compliance frameworks.
  • Working knowledge of CMMC Level 2 / NIST 800-171 requirements and audit/assessment processes.
  • Experience with IT asset management and lifecycle tracking.
  • Experience with configuration/change management processes and tooling (e.g., Jira, ServiceNow, or similar).
  • Highly detail-oriented, organized, and results-focused, with the ability to independently drive initiatives to completion.
  • Strong written and verbal communication skills, including documentation and audit-facing materials.
  • Comfortable working a service desk/ticket queue directly and balancing reactive support work with longer-term process ownership.


Preferred Qualifications:

  • 15 years of related experience and a Master's degree in Information Technology, Cybersecurity, or related field.
  • Relevant IT/security certifications (e.g., CISSP, CISM, Security+, CySA+, CMMC-related certifications such as CCP/CCA, ITIL, or similar).
  • Experience supporting a federal contractor or Alaska Native Corporation (ANC)/8(a) environment.
  • Experience with dual-tenant Microsoft 365 environments (Commercial + GCC High).
  • Familiarity with Microsoft Purview, Defender for Cloud, or similar governance/security tooling.


Location

Hybrid with in person reporting at Colorado Springs CO, Reston VA, or Arlington VA

We will be accepting applications for this position until 4 October 2026.

Salary Range: $155K - $170K annually (final rate based on experience and location)

Aleut offers the following benefits to eligible employees:

  • Health insurance
  • Dental/Vision Insurance
  • Paid Time Off
  • Short- and Long-Term Disability
  • Life insurance
  • 401k, and match


Similar Jobs

More Jobs at ARS Aleut Construction

More Information Technology Jobs

Find similar Compliance, Asset, Security, & Configuration Management (CASC) Manager jobs: