
Information Assurance Analyst
- Vulnerability Management
- RMF
- Oracle
- .NET
- Azure
- Windows
- STIGs
- FISMA
- Incident Response
- HIPAA
- Technical Writing
Employment Type: Full-time, contingent upon contract award
Salary Range:$105,000–$135,000 annually
Estimated Start Date: November 1st, 2026
Estimated Level of Effort:1,920 productive hours annually
Work Location:Remote/contractor office, with access to Pentagon Network and DPRR resources in the Arlington, Virginia area as required.
Core Hours: Available for an 8-hour duty day between 7:30 a.m. and 4:30 p.m. Eastern Time, Monday through Friday, excluding Federal holidays and Government-directed closures.
Travel: No travel is authorized or anticipated.
Position summary
The Information Assurance (IA) Analyst supports cybersecurity, information assurance, vulnerability management, RMF, and continuous-monitoring operations for DAMIS. The Analyst will work within an environment that hosts Oracle databases and .NET web applications and will support the DAMIS system’s security posture across Azure, Red Hat, and Windows technologies. The position works under the direction of the System Owner/COR and the Senior IA Analyst/Program Manager, while providing timely technical analysis, compliance documentation, and risk-based recommendations.
Essential responsibilities
Support the overall DAMIS information assurance program and comply with applicable Army, Department of War/DoD, and local cybersecurity policies and procedures.
Conduct, document, analyze, and report weekly, monthly, and annual vulnerability scans in accordance with Army best practices.
Submit scan results to the System Owner/COR and P-ISSM and support upload of results to eMASS within one week of scan completion.
Execute and assess Government STIG checklists; identify findings, track remediation, and support compliance reporting.
Support continuous monitoring of ATO requirements, STIGs, CCIs, vulnerability compliance, and system security controls.
Assess and report system vulnerabilities across Oracle, .NET, Red Hat, Windows, and Azure-based environments.
Review system change requests and recommend secure alternatives or support implementation within two business days, while recognizing that final approval remains with the Government System Owner/COR.
Support RMF package development, maintenance, documentation routing, annual contingency/security/recovery testing, and eMASS updates.
Support IAVA monitoring, analysis, reporting, and preparation of corrective-action recommendations for Government decision.
Contribute to FISMA-compliant reporting, APMS/AVTR/eMASS data updates, monthly status reporting, emergency planning, incident response, and CERT activities.
Participate in recurring DAMIS technical meetings and IA working groups; prepare accurate meeting minutes, action items, and technical recommendations.
Protect Government information and comply with CUI, PII, HIPAA, OPSEC, cybersecurity awareness, and data-handling requirements.
Minimum required qualifications
A minimum of 3 years of progressive professional experience in information technology, cybersecurity, information assurance, systems security, vulnerability management, or closely related technical disciplines.
Current certification meeting the Department of War/DoD IAT Level II baseline requirement at the time of hire and throughout employment on the contract.
Demonstrated IA/cybersecurity experience in an environment hosting Oracle databases and .NET web applications.
Solid Red Hat and Windows security and administration experience sufficient to assess, document, and report system vulnerabilities.
Demonstrated proficiency conducting weekly, monthly, and annual vulnerability scans and communicating results.
Demonstrated experience executing Government STIG checklists for system compliance.
Ability to review system changes, identify IA vulnerabilities, and provide an implementation recommendation or secure alternative within a two-business-day turnaround.
Strong technical writing, documentation, analytical, communication, and collaboration skills.
Familiarity with Azure administration is strongly preferred.
Compensation
The anticipated base-salary range is $105,000–$135,000 annually. Final compensation will be based on demonstrated Oracle/.NET security experience, Red Hat and Windows security administration, vulnerability management, STIG/RMF/eMASS experience,IAT Level II certification, Azure familiarity, verified Government access eligibility, and the candidate’s overall qualifications. This position is expected to be exempt.
Citizenship, clearance, and access requirements
U.S. citizenship required.
Candidate must have previously held a U.S. Government security clearance or a favorably adjudicated Tier 3 National Agency Check with Inquiries (NACI), or an equivalent or higher investigation.
Candidate must be able to provide information necessary for Government verification of a favorably adjudicated Tier 3 NACI/equivalent or higher investigation, as required for proposal submission and contract performance.
Must be eligible to obtain and maintain a Department of War CAC, Pentagon Network/cArmy Cloud access, and all other Government system and facility access required for assigned duties.
Must comply with all applicable Government security, privacy, CUI, PII, HIPAA, OPSEC, cyber awareness, and acceptable-use requirements.
Contingent offer conditions
Any offer of employment is contingent upon contract award to SnapIT Solutions; verification of stated certifications, experience, citizenship/work authorization, and prior clearance/investigation status; and satisfaction of all Government access, suitability, and onboarding requirements. The selected individual may be designated as Government-recognized key personnel. Accordingly, replacement, reassignment, or removal may be subject to Government written concurrence under the resulting contract.
Information Assurance Analyst · SnapIT Solutions