Title: Senior Information Assurance (IA) Analyst.
Location: Fort Meade MD
Clearance required: Active Secret Clearance or Higher
Certification required by project: IAT Level 2 or willing to obtain within 3 Months of joining
Position Summary
CompQsoft is seeking a Senior Information Assurance (IA) Analyst to join our DISA program team in Fort Meade, MD. The successful candidate will perform and analyze vulnerability assessments using Assured Compliance Assessment Solution (ACAS) and Security Content Automation Protocol (SCAP) tools, identify security risks, and collaborate with system engineers, administrators, and cybersecurity personnel to develop and implement effective remediation strategies.
This role requires a strong understanding of cybersecurity best practices, vulnerability management, RMF processes, and the ability to communicate technical findings to both technical and non-technical stakeholders.
Key Responsibilities
- Examine internal IT controls, evaluate the design and operational effectiveness, determine exposure to risk and develop remediation strategies for System Administrator (SA) implementation.
- Perform recurring and on-demand vulnerability assessments using ACAS (Tenable Security Center/Nessus) and SCAP Compliance Checker.
- Analyze vulnerability scan results to identify security weaknesses, misconfigurations, and compliance gaps.
- Prioritize vulnerabilities based on severity, exploitability, mission impact, and organizational risk.
- Partner with system engineers, network engineers, system administrators, and application owners to develop practical remediation and mitigation strategies.
- Test and identify network and system vulnerabilities and assist in creating counteractive strategies to protect the network.
- Validate remediation efforts through follow-up scans and technical analysis.
- Review scan findings to distinguish true positives from false positives and provide supporting technical justification.
- Prepare vulnerability assessment reports, risk summaries, metrics, and executive-level briefings.
- Track vulnerabilities through remediation lifecycle to ensure timely resolution.
- Support Risk Management Framework (RMF) activities, continuous monitoring, Authority to Operate (ATO) sustainment, and cybersecurity compliance initiatives.
- Assist with implementation and validation of DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs).
- Coordinate with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), engineering teams, and system owners to resolve security findings.
- Maintain documentation supporting POA&Ms, vulnerability tracking, and audit readiness.
- Review and monitor system security posture and requirements primarily outlined but not limited to CTOs, TASKORD, OPORD, IAVAs, STIGs and other downward directed orders for system hardening
Required Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related discipline.
- 10+ years of experience in cybersecurity, vulnerability management, or information assurance.
- Experience performing and analyzing ACAS (Tenable Security Center/Nessus) vulnerability scans
- Experience executing and interpreting SCAP Compliance Checker scans.
- Knowledge of vulnerability management processes and remediation lifecycle.
- Familiarity with networking fundamentals including TCP/IP, DNS, Active Directory, routing, and firewalls.
- Experience supporting RMF, Continuous Monitoring or ATO sustainment.
- Strong analytical and troubleshooting skills.
- Excellent written and verbal communication skills with the ability to clearly explain technical findings and remediation recommendations.
- Ability to work collaboratively with engineers, administrators, and security teams to resolve vulnerabilities.
- Strong communication skills (verbally and in writing).
Preferred Qualifications
- Experience supporting DoW, DHS, or other Federal cybersecurity environments.
- Familiarity with DISA STIGs, SRGs, and Security Compliance Guides.
- Experience using eMASS or similar RMF documentation tools.
- Experience with Tenable Security Center, Nessus Manager, or Tenable.sc.
- Experience with PowerShell, Bash, or Python scripting to automate vulnerability management tasks.
- Experience supporting security audits, inspections, or CCRI/CORAs
CompQsoft provides equal opportunity in all aspects of employment and in the working environment to all employees and applicants. CompQsoft does not take any non-merit factors like race, color, religion, sex (gender), mental/physical disability, and age into account for purposes of recruitment, hiring and development