Information Assurance Analyst

NexGen Data Systems

$95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Active Department of Defense Top Secret security clearance required.
  • Certification meeting DoD 8570/8140 IAM Level II requirements (e.g., CompTIA CASP+, CISM, CISSP) needed.
  • Minimum of five years dedicated experience in Information Assurance or Cybersecurity required.
  • Hands-on application of the Risk Management Framework (RMF) essential.
  • Experience with vulnerability assessments using tools like ACAS or Nessus necessary.
  • At least two years securing cloud environments (e.g., AWS, Azure) with knowledge of FedRAMP controls needed.

Responsibilities

  • Manage and maintain security posture of enterprise cloud and network services throughout the RMF lifecycle.
  • Conduct regular vulnerability scans of network and cloud assets and prioritize remediation actions with technical teams.
  • Perform continuous monitoring and compliance validation against STIGs and agency benchmarks.
  • Analyze compliance within the enterprise cloud environment ensuring FedRAMP control alignment.
  • Develop, update, and maintain RMF documentation, including the System Security Plan and POA&M.
  • Act as primary contact for internal and external security audits, providing evidence to auditors.
  • Track and report on Information Assurance Vulnerability Management directives, ensuring timely remediation.

Benefits

  • 100% company coverage for employee medical, dental, and vision insurance premiums.
  • Short and long term disability plans provided by the company.
  • 401(k) match up to 10% of employee's salary contributions offered.
  • Comprehensive training and development program available.
  • 11 paid holidays plus 15 days PTO annually.
Full Job Description
Job Type

Full-time

Description

The Information Assurance (IA) Analyst is responsible for ensuring the confidentiality, integrity, and availability of information systems by managing the security and compliance framework across the enterprise cloud and network infrastructure. This role serves as the subject matter expert on risk management and compliance, translating federal and DoD security directives into actionable controls and procedures. The IA Analyst continuously monitors the security posture, manages vulnerabilities, and maintains the formal documentation required to achieve and sustain the Authority to Operate (ATO). This individual acts as the critical link between operational/engineering teams and the formal security accreditation process for both on-premise network services and cloud environments.

Roles & Responsibilities:
  • Shall manage and maintain the security posture of enterprise cloud and network services throughout all phases of the Risk Management Framework (RMF) lifecycle.
  • Shall conduct regular vulnerability scans of network and cloud assets using government-approved tools, analyze scan results, and coordinate with technical teams to prioritize remediation actions.
  • Shall perform continuous monitoring and compliance validation of network devices, servers, and cloud resources against Security Technical Implementation Guides (STIGs) and other agency-specific benchmarks.
  • Shall analyze and verify compliance within the enterprise cloud environment (e.g., AWS, Azure), ensuring alignment with FedRAMP controls and proper implementation of the shared responsibility model.
  • Shall develop, update, and maintain all necessary RMF documentation, including the System Security Plan (SSP), security control traceability matrices, and Plans of Action and Milestones (POA&M).
  • Shall serve as a primary point of contact for internal and external security audits, responsible for gathering and presenting evidence of control implementation to auditors.
  • Shall track, interpret, and report on Information Assurance Vulnerability Management (IAVM) directives, coordinating with technical teams to ensure timely remediation and reporting.
  • Shall provide information assurance expertise and guidance to network and cloud engineering teams to ensure security controls are integrated into the design and implementation of new services ("security by design").

Other Duties: Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice.

Requirements

Desired/Required Skills:
  • Active Department of Defense Top Secret security clearance required.
  • Must hold a certification meeting DoD 8570/8140 IAM Level II requirements (e.g., CompTIA CASP+, CISM, or CISSP).
  • Must have a minimum of five (5) years of dedicated experience in Information Assurance or Cybersecurity. This experience must include:
  • Direct, hands-on application of the Risk Management Framework (RMF) from initiation to continuous monitoring.
  • Experience conducting vulnerability assessments using tools such as ACAS, Nessus, or equivalent systems.
  • Experience implementing and auditing systems against Security Technical Implementation Guides (STIGs).
  • At least two (2) years of experience must involve securing cloud environments (e.g., AWS, Azure) and a working knowledge of FedRAMP controls.

Benefits:
  • Company covers 100% of premiums for the employee's medical, dental, and vision insurance and subsidizes premiums for spouse and dependents.
  • Company provides short and long term disability plans.
  • 401(k) match up to 10% of the employee's salary contributions to 401(K) plan.
  • Comprehensive training and development program.
  • 11 paid holidays and paid time off (PTO) accrual level starts at 15 days annually.

Similar Jobs

More Jobs at NexGen Data Systems

More Information Technology Jobs

Find similar Information Assurance Analyst jobs: