> Markdown version of [/jobs/ext/2987947-information-assurance-analyst](https://www.wearedevelopers.com/jobs/ext/2987947-information-assurance-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance Analyst - **Company:** CareerCircle - **Location:** Alexandria, VA, United States - **Experience:** Experienced - **Salary:** $87,100.0 - $157,450.0 - **Contract:** Permanent contract - **Skills:** Xacta, Microsoft Windows, CompTIA Security+, Cyber Security, Information Systems, Linux, Identity and Access Management, Networking Hardware, Microsoft Software, Comptia Pentest+ CE, Security Content Automation Protocol, Security Information and Event Management, Virtualization Technology, Software Vulnerability Management, Network Switches, Firewalls (Computer Science), Information Technology, Nessus, Network Server, Wsus, Cisco, Vulnerability Analysis, Vmware - **Published:** September 18, 2026 - **Apply:** https://www.careercircle.com/jobs/all/all/usa/va/alexandria/eb46dd86-dec8-41c3-8e91-00bf0645a37b ## About the Role Xacta Nessus Writing Research Firewall Equities Hardening Innovation Market Data NIST 800-53 Coordinating Cyber Security Remote Sensing Data Collection Train Teammates Network Switches Image Resolution Security Controls CompTIA Security+ Information Systems Geospatial Analysis Top Secret Clearance Information Assurance Continuous Monitoring Vulnerability Management Risk Management Framework IAM Level II Certification Security Requirements Analysis Windows Server Update Services Host Based Security System (HBSS), * Bachelor's degree with 4+ years of relevant experience (additional experience may substitute for degree). * US Citizen; Currently possessing an active DoD Top Secret clearance with ability to upgrade to a TS/SCI clearance upon hire. * Current DoD 8140 IAT/IAM Level II certification, or ability to obtain Security+ within 6 months of hire. * Ability to obtain a second professional certification within 6 months (Cisco, VMware, Microsoft, etc.). * Proficiency with NIST SP 800-53 RMF. * Experience supporting IA Assess and Authorize (A&A) processes and implementing DoD/NIST/CNSS IA guidance and directives. * Strong knowledge of DISA STIGs and SRGs and experience hardening workstations, servers, applications, and network devices. * Ability to recommend additional security requirements and safeguards as needed. * Ability to work independently and collaboratively with on-site personnel and remote customers. * Excellent oral and written communication skills. * Broad IT knowledge with ability to identify issues and research corrective actions. * Currently possess or ability to obtain a passport and international travel visa. * Ability to successfully complete the CONUS Replacement Center deployment training and medical requirements. * Willingness to work long, irregular hours in hardship or hazardous OCONUS locations., * Master's degree with 2+ years of relevant experience. * Active TS/SCI clearance. * AMSOPP1Certifications such as Security+ and PenTest+. * Experience with RMF, A&A processes, Xacta IA Manager, or eMASS. * Experience with Windows and Linux operating systems, virtualized environments, and networking devices. ## Description * Apply NIST and DoD standards in support of the Risk Management Framework (RMF). * Develop, update, and maintain accreditation packages, documentation, and RMF artifacts for ATO and IATT activities. * Implement Information Assurance Vulnerability Management (IAVM) and continuous monitoring processes. * Conduct compliance and vulnerability assessments. * Implement security controls based on Nessus and SCAP scan results aligned with DISA STIG requirements. * Apply Collaborative Security Solution (CS2) scripts to applicable systems. * Configure and interpret reports from SIEM tools, HBSS/HIPS, DLP, WSUS, workstations/servers, network switches, firewalls, and related security systems. * Support design, development, and implementation of solutions that meet network and system security requirements. * Perform vulnerability and risk analyses across systems, networks, and applications in coordination with cyber professionals, network staff, teammates, and Government stakeholders. * Provide cross-functional support across multiple systems and environments within a complex, interconnected network. * Brief Program Managers and customer Contract Officials on IA and cybersecurity issues, achievements, incidents, and challenges. * Cross-train teammates on department-specific responsibilities. * Administer Information System environment changes to ensure compliance with security best practices., Linux Xacta Nessus Writing Research Firewall Equities Hardening Innovation Market Data NIST 800-53 Coordinating Cyber Security Remote Sensing Data Collection Train Teammates Network Switches Image Resolution Security Controls CompTIA Security+ Information Systems Geospatial Analysis Top Secret Clearance Information Assurance Continuous Monitoring Vulnerability Management Risk Management Framework IAM Level II Certification Security Requirements Analysis Windows Server Update Services Host Based Security System (HBSS) Security Information And Event Management (SIEM) Information Assurance Vulnerability Management (IAVM) Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) +0 ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Your Infrastructure Is Not a Playground: AI Agents for Infra Done Right](https://www.wearedevelopers.com/videos/2084-your-infrastructure-is-not-a-playground-ai-agents-for-infra-done-right) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)