Senior Information Assurance (IA) Analyst
Description

 

Title: Senior Information Assurance (IA) Analyst.

Location: Fort Meade MD

Clearance required: Active Secret Clearance or Higher

Certification required by project: IAT Level 2 or willing to obtain within 3 Months of joining    

Requirements

  

Position Summary

CompQsoft is seeking a Senior Information Assurance (IA) Analyst to join our DISA program team in Fort Meade, MD. The successful candidate will perform and analyze vulnerability assessments using Assured Compliance Assessment Solution (ACAS) and Security Content Automation Protocol (SCAP) tools, identify security risks, and collaborate with system engineers, administrators, and cybersecurity personnel to develop and implement effective remediation strategies.

This role requires a strong understanding of cybersecurity best practices, vulnerability management, RMF processes, and the ability to communicate technical findings to both technical and non-technical stakeholders.

Key Responsibilities

  • Examine internal IT controls, evaluate the design and operational effectiveness, determine exposure to risk and develop remediation  strategies for System Administrator (SA) implementation.
  • Perform recurring and on-demand  vulnerability assessments using ACAS (Tenable Security Center/Nessus) and      SCAP Compliance Checker.
  • Analyze vulnerability scan results to  identify security weaknesses, misconfigurations, and compliance gaps.
  • Prioritize vulnerabilities based on severity, exploitability, mission impact, and organizational risk.
  • Partner with system engineers, network  engineers, system administrators, and application owners to develop  practical remediation and mitigation strategies.
  • Test and identify network and system vulnerabilities and assist  in creating counteractive strategies to protect the network.
  • Validate remediation efforts through  follow-up scans and technical analysis.
  • Review scan findings to distinguish true  positives from false positives and provide supporting technical  justification.
  • Prepare vulnerability assessment reports,  risk summaries, metrics, and executive-level briefings.
  • Track vulnerabilities through remediation lifecycle to ensure timely resolution.
  • Support Risk Management Framework (RMF) activities, continuous monitoring, Authority to Operate (ATO) sustainment,  and cybersecurity compliance initiatives.
  • Assist with implementation and validation of DISA Security Technical Implementation Guides (STIGs) and Security      Requirements Guides (SRGs).
  • Coordinate with Information System  Security Managers (ISSMs), Information System Security Officers (ISSOs),  engineering teams, and system owners to resolve security findings.
  • Maintain documentation supporting  POA&Ms, vulnerability tracking, and audit readiness.
  • Review  and monitor system security posture and requirements primarily outlined  but not limited to CTOs, TASKORD,      OPORD, IAVAs, STIGs and other downward  directed orders for system hardening

Required Qualifications

  • Bachelor’s degree in Cybersecurity,  Computer Science, Information Technology, or related discipline.
  • 10+ years of experience in cybersecurity,  vulnerability management, or information assurance.
  • Experience performing and analyzing ACAS  (Tenable Security Center/Nessus) vulnerability scans 
  • Experience executing and interpreting SCAP  Compliance Checker scans.
  • Knowledge of vulnerability management  processes and remediation lifecycle.
  • Familiarity with networking fundamentals  including TCP/IP, DNS, Active Directory, routing, and firewalls.
  • Experience supporting RMF, Continuous   Monitoring or ATO sustainment.
  • Strong analytical and troubleshooting   skills.
  • Excellent written and verbal communication  skills with the ability to clearly explain technical findings and      remediation recommendations.
  • Ability to work collaboratively with engineers, administrators, and security teams      to resolve vulnerabilities.
  • Strong communication skills (verbally and in writing).

Preferred Qualifications

  • Experience supporting DoW, DHS, or other Federal cybersecurity environments.
  • Familiarity with DISA STIGs, SRGs, and  Security Compliance Guides.
  • Experience using eMASS or similar RMF documentation tools.
  • Experience with Tenable Security Center,  Nessus Manager, or Tenable.sc.
  • Experience with PowerShell, Bash, or  Python scripting to automate vulnerability management tasks.
  • Experience  supporting security audits, inspections, or CCRI/CORAs

CompQsoft provides equal opportunity in all aspects of employment and in the working environment to all employees and applicants. CompQsoft does not take any non-merit factors like race, color, religion, sex (gender), mental/physical disability, and age into account for purposes of recruitment, hiring and development