
Senior Information Assurance Analyst / Program Manager
- Azure
- Risk Management Framework
- RMF
- Information Systems Security
- .NET
- Windows
- Oracle
- IAM
- Data Architecture
- HIPAA
Employment Type: Full-time, contingent upon contract award
Salary Range: $150,000–$175,000 annually
Expected Start Date: November 1. 2026
Estimated Level of Effort: 1,920 productive hours annually
Work Location: Remote/contractor office, with access to Pentagon Network and Directorate of Prevention, Resilience and Readiness (DPRR) resources in the Arlington, Virginia area as required.
Core Hours: Available for an 8-hour duty day between 7:30 a.m. and 4:30 p.m. Eastern Time, Monday through Friday, excluding Federal holidays and Government-directed closures.
Travel: No travel is authorized or anticipated.
Position summary
The Senior Information Assurance (IA) Analyst / Program Manager serves as the Information Assurance Security Officer (IASO) and SnapIT’s principal point of contact for performance of Information Assurance and cybersecurity support for the Drug and Alcohol Management Information System (DAMIS). The role leads the contract team and supports the DAMIS security posture in a Microsoft Azure Infrastructure-as-a-Service environment. The position is responsible for management controls, quality, continuity, Risk Management Framework (RMF) execution, continuous monitoring, Authority to Operate (ATO) sustainment, and communication with the Government System Owner/Contracting Officer’s Representative (COR), Program Information Systems Security Manager (P-ISSM), and technical stakeholders.
Essential responsibilities
Serve as the contractor’s senior technical lead, IASO, and primary point of contact to the Government COR for daily contract performance.
Provide program leadership, supervision, accountability, quality control, staffing continuity, escalation management, and timely status communication.
Manage the DAMIS information assurance/cybersecurity program in a Microsoft Azure IaaS environment, including systems involving .NET, Windows, Azure, Oracle, and Red Hat.
Direct and support RMF activities, continuous monitoring, security documentation, vulnerability compliance reporting, contingency/security/recovery testing, and eMASS package maintenance.
Maintain DAMIS’s current ATO and lead planning and documentation required to obtain a renewed ATO before expiration.
Implement and audit Security Technical Implementation Guide (STIG) requirements; monitor Control Correlation Identifiers (CCIs), assess compliance gaps, and develop remediation recommendations.
Oversee weekly, monthly, and annual vulnerability scanning; ensure scan findings are reported to the System Owner/COR and P-ISSM and uploaded to eMASS within required timeframes.
Evaluate Information Assurance Vulnerability Alerts (IAVAs), assess applicable risks and courses of action, and submit recommendations to the System Owner/COR for Government decision and execution.
Review and coordinate system change requests; ensure implementation or IA-based alternatives are provided within the required two-business-day turnaround.
Prepare and deliver weekly ATO/security-status updates, monthly status reports, RMF plans and timelines, emergency-operations planning updates, meeting minutes, and other contract deliverables.
Participate in the agency Computer Emergency Response Team (CERT); support timely incident acknowledgment, mitigation coordination following Government approval, and follow-up reporting.
Attend and support IA working groups, technical meetings, and recurring DAMIS coordination sessions; provide actionable minutes and recommendations after meetings.
Ensure orderly phase-in, credentialing, access readiness, staff onboarding, and continuity of operations.
Minimum required qualifications
Bachelor’s degree in computer science, cybersecurity, information technology, or a closely related discipline.
At least15 years ofprogressive professional experience in information technology, cybersecurity, information assurance, systems security, or closely related technical disciplines.
Of the required experience, at leastsix years oftechnical and compliance experiencemaintaining system security posture and managing security in aMicrosoft Azure IaaS environment.
At least two years of experience leading technical or cybersecurity teams.
Current certification meeting the Department of War/DoD IAM Level II baseline requirement at the time of hire and throughout employment on the contract.
Demonstrated IA/cybersecurity experience supporting systems using .NET, Windows, Azure, Oracle, and Red Hat.
Strong knowledge of data architecture, the Software Development Life Cycle (SDLC), Red Hat and Windows security/administration, RMF, continuous monitoring, STIG implementation, and STIG auditing.
Demonstrated ability to manage ATO sustainment and support ATO renewal activities.
Strong written, oral, stakeholder-management, analytical, and problem-resolution skills.
Compensation
Final compensation will be based on demonstrated depth of experience in Azure IaaS security, RMF/eMASS, ATO sustainment, STIG compliance, IAM Level II certification, technical leadership, verified Government access eligibility, and the candidate’s overall qualifications. This position is expected to be exempt.
Citizenship, clearance, and access requirements
U.S. citizenship required.
Candidate must have previously held a U.S. Government security clearance or a favorably adjudicated Tier 3 National Agency Check with Inquiries (NACI), or an equivalent or higher investigation.
Candidate must be able to provide information necessary for Government verification of a favorably adjudicated Tier 3 NACI/equivalent or higher investigation, as required for proposal submission and contract performance.
Must be eligible to obtain and maintain a Department of War Common Access Card (CAC), Pentagon Network/cArmy Cloud access, and all other Government system and facility access required for assigned duties.
Must comply with all applicable Government security, privacy, Controlled Unclassified Information (CUI), Personally Identifiable Information (PII), HIPAA, OPSEC, cyber awareness, and acceptable-use requirements.
Contingent offer conditions
Any offer of employment is contingent upon contract award to SnapIT Solutions; verification of stated education, certifications, experience, citizenship/work authorization, and prior clearance/investigation status; and satisfaction of all Government access, suitability, and onboarding requirements. The selected individual may be designated as Government-recognized key personnel. Accordingly, replacement, reassignment, or removal may be subject to Government written concurrence under the resulting contract.
Senior Information Assurance Analyst / Program Manager · SnapIT Solutions