> Markdown version of [/jobs/ext/3140870-information-assurance-compliance-analyst-30426](https://www.wearedevelopers.com/jobs/ext/3140870-information-assurance-compliance-analyst-30426). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance Compliance Analyst - 30426 - **Company:** HII Mission Technologies - **Location:** Virginia Beach, VA, United States (Remote available) - **Experience:** Experienced - **Salary:** $74,074.0 - $105,820.0 - **Contract:** Permanent contract - **Skills:** Cloud Computing, Configuration Management, Cyber Security, Information Security Management, SAP (Applications), Software Vulnerability Management, Information Technology, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9202106/information-assurance-compliance-analyst-30426 ## About the Role * 2 years relevant experience with Bachelors in related field; 0 years experience with Masters in related field; or High School Diploma or equivalent and 6 years relevant experience. * Demonstrated foundational experience in Information Assurance compliance * Knowledge of RMF processes and A & A procedures. * Experience working with Information Assurance tools such as eMASS and ACAS. * DoD 8140 (formerly 8570) IAT Level II certification such as CCNA, CAP, Security+ CE, or ENSA required. * Current or active DoD Secret clearance. * Ability to work onsite at Dam Neck, Virginia Beach, VA hybrid schedule. Remote/telework is at the discretion of the government., * Experience supporting Navy shore-based training systems or cloud-based environments. * Knowledge of Navy cybersecurity policies, Federal Information Security Modernization Act (FISMA) reporting, and continuous monitoring requirements. * Familiarity with NIST SP 800-53 security controls and assessment procedures. * Experience with STIG compliance validation and vulnerability remediation tracking. * Strong analytical and documentation skills. * U.S. Navy background with information assurance or cybersecurity experience. * Ability to communicate effectively with technical and non-technical audiences. * Attention to detail and commitment to compliance accuracy. Physical Requirements May require working in an office, industrial, shipboard, or laboratory environment. Capable of climbing ladders and tolerating confined spaces and extreme temperature variances. ## Description HII's Mission Technologies division is currently seeking a Information Assurance Compliance Analyst to support Naval Surface Warfare Center Dahlgren Division (NSWCDD) Dam Neck Activity (DNA) cybersecurity programs for Shore-Based Training Systems. This position will provide compliance and auditor support for Risk Management Framework (RMF) Assessment & Authorization (A&A) processes supporting approximately 80 cloud and shore-based training systems across PMS339, DRPM SUBS (SEA07TR), and RRL sponsors., * Oversee, evaluate, and support documentation, validation, and accreditation processes necessary to ensure Information Technology (IT) systems meet the organization's information assurance (IA) and security requirements. * Provide Auditor support for RMF packages and continuous monitoring purposes as needed in RMF Steps 0-6. Provide security controls risk assessments and validations. * Assist in performing annual security reviews and annual testing of security controls. * Assess quality of security control implementation against requirements using NIST SP 800-53 and Navy cybersecurity guidelines. * Review and validate security artifacts including System Security Plans (SSP), Security Assessment Plans (SAP), Security Assessment Reports (SAR), and Plan of Action and Milestones (POA&M). * Support preparation and maintenance of RMF documentation including objective quality evidence (OQE) for security control validation. * Conduct reviews of Security Technical Implementation Guide (STIG) compliance results and Assured Compliance Assessment Solution (ACAS) vulnerability scan outputs; validate remediation activities. * Assist in tracking POA&M entries and ensuring vulnerabilities are properly documented, tracked, and resolved. * Support continuous monitoring activities by reviewing security control compliance status and identifying gaps or deficiencies. * Participate in coordination efforts with Information System Security Managers (ISSM), Technical Area Experts (TAE), Security Control Assessors (SCA), and Authorizing Officials (AO). * Review technical documentation including engineering change proposals, baseline descriptions, and configuration management artifacts for security compliance. * Assist in preparation of briefing materials for TAE, SCA, and AO checkpoint meetings. * Support development of security policies, procedures, and compliance reports. * Ensure appropriate treatment of risk, compliance, and monitoring assurance from internal and external perspectives. * Maintain knowledge of current Navy cybersecurity policies, instructions, and RMF guidance. * Utilize Enterprise Mission Assurance Support Service (eMASS) to track authorization packages and upload compliance artifacts. * Support cross-sponsor activities for PMS339, SUBS, and RRL programs as workload demands. * Attend DOW, Navy Authorizing Official (NAO), and PAE Maritime RMF meetings to stay current on RMF processes and procedures. * Utilize SIPRnet access 25-60% of the time depending on specific work assignments. * Expected travel up to 10-15% of time for approximately one week per trip to support authorization briefings or stakeholder coordination. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Independently together: how micro-applications improve developer experience + app performance](https://www.wearedevelopers.com/videos/452-independently-together-how-micro-applications-improve-developer-experience-app-performance) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)