> Markdown version of [/jobs/ext/1399897-information-assurance-support-analyst](https://www.wearedevelopers.com/jobs/ext/1399897-information-assurance-support-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance Support Analyst - **Company:** ASTRION, INC. - **Location:** Rockville, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Apache Tomcat, Microsoft Azure, Software as a Service, Configuration Management, CompTIA Security+, Databases, Federal Information Processing Standards (FIPS), Infrastructure as a Service (IaaS), Internet Information Services (IIS), Information Security Management, Networking Hardware, Intrusion Detection and Prevention, Virtual Private Networks (VPN), Network Security, Microsoft Office, Microsoft SQL Server, Platform as a Service (PAAS), Windows PowerShell, Cloud Services, Security Content Automation Protocol, Virtualization Technology, Web Services, Network Routers, Scripting, Software Security, Firewalls (Computer Science), SC Clearance, Information Technology, Vba Programming Language, Malware Detection, CIS Benchmarks, Vulnerability Analysis - **Published:** July 23, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/85656738/1 ## About the Role * BA/BS or 5 years additional equivalent experience * 6 years IT experience, with 4 years specialized in Information Assurance * Secret Clearance; the ability to obtain an NRC Security Clearance; US citizenship required * Must hold at least one of the following certifications: CompTIA Security+, CISSP, ISACA CISA, GIAC GSEC, GIAC GSNA, GIAC GPEN, CEH, CAP, CASP+, CRISC, or CCSK, * A strong understanding of FISMA and NIST Special Publications, especially NIST SP 800-37 and NIST SP 800-53 * Excellent written and oral communication skills; attention to detail is a must * Experience with vulnerability scanning tools, such as Tenable Security Center * Working knowledge of DISA STIGs, SCAP content/ audit files, and CIS Benchmarks * Understanding of cloud service models (SaaS, PaaS, IaaS) and protections as described in FedRAMP security documentation * Experience reviewing FedRAMP authorization packages and understanding how to ensure customer responsibilities are addressed in accordance with the shared responsibility model * Experience with performing technical architecture reviews of complex systems with a strong understanding of a system's authorization * Knowledge of major cloud platforms (Azure/ Amazon Web Services [AWS]), virtualization, networking devices (e.g., routers and switches), web services (e.g., IIS, Apache Tomcat), network security appliances (e.g., firewalls, VPNs), databases (e.g., Microsoft SQL), and intrusion prevention/ anti-malware software * Knowledge of system and application security threats and vulnerabilities * Proficiency with Microsoft Office applications * Ability to prioritize and complete tasks efficiently and effectively * Comfortable working individually and as part of a team * Scripting ability (e.g., PowerShell, VBA) is a plus * Familiarity with the use of artificial intelligence (AI) tools such as chat technologies to enhance personal productivity ## Description * Work closely with all levels of personnel, including system administrators, Information System Security Officers (ISSOs), and Authorizing Official (AO), to support FISMA systems through the Security Assessment & Authorization (SA&A) * Assess the confidentiality, integrity, and availability impact levels of information stored, possessed, and transmitted by systems to determine the FIPS 199 security categorization * Develop and maintain system security documentation throughout all phases of the NIST Risk Management Framework (RMF). This includes security categorizations, digital identity risk assessments, system security plans, system policy and procedures, privacy impact assessments, contingency plans, configuration management plans, incident response plans, vulnerability assessment reports, deviation requests, and any other documents necessary to support systems' authorization and continuous monitoring * Analyze risks identified during security control assessments and continuous monitoring activities in accordance with NIST SP 800-30. This includes making a determination regarding the likelihood and impact of the risk being exploited, along with a supporting rationale, and providing recommendations for mitigation/remediation * Perform and document the results of vulnerability scans and configuration compliance checks against configuration standards such as DISA STIGs and CIS Benchmarks * Analyze FedRAMP security packages to document and assess customer responsibility for cloud-based * Assist in the review of monthly continuous monitoring deliverables produced by Cloud Service Providers (CSPs) and annual assessments (produced by third party assessors [3PAOs]) in support of FedRAMP requirements to ensure that cloud services maintain an appropriate risk * Create, track, and manage system Plans of Action and Milestones (POA&Ms) * Attend project meetings and collaborate with stakeholders to ensure security is addressed throughout the entire system lifecycle ## Related Videos - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Developer Time Is Valuable - Use the Right Tools - Kilian Valkhof](https://www.wearedevelopers.com/videos/1792-developer-time-is-valuable-use-the-right-tools-kilian-valkhof) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How to Become an AI Engineer](https://www.wearedevelopers.com/magazine/331-how-to-become-an-ai-engineer) - [What Industries Outside of AI Are Hiring The Most AI Experts?](https://www.wearedevelopers.com/magazine/98-what-industries-outside-of-ai-are-hiring-the-most-ai-experts)