user avatar

Compliance, Asset, Security, & Configuration Management (CASC) M

Aleut Federal LLC

Posted today

Job Requirements

Colorado Springs, CO
Intel Agency (NSA, CIA, FBI, etc) Polygraph Unspecified
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries

Job Description

About Aleut Federal

At Aleut Federal, we believe the company and its mission is just as important as the job you are applying for. Aleut Federal is an Alaskan Native-owned enterprise whose purpose is to support our "Shareholders," the Unangax, the indigenous people of the Aleutian Islands of Alaska. People are at the core of everything we do. We support our Shareholders by providing excellent service and quality results to our Clients, the various branches of the federal government. We engage in our local markets, so community service is embedded into our process.

Our culture nurtures the strength of our workforce through mentorship and coaching, providing opportunities for growth, and competitive benefits. We support and encourage diversity, inclusion, and accountability at every level.

The Aleut Federal motto is "We are One" because we truly believe that with one heart, one mind, and one purpose, we can accomplish our mission and be an organization anyone would be proud to be a part of.

Position Overview

Aleut Federal is seeking a Compliance, Asset, Security, & Configuration Management (CASC) Manager to own and mature the organization's compliance posture, IT asset lifecycle, security configuration standards, and change/configuration management practices. This is a full product-ownership role: the CASC Manager owns these areas end-to-end, from working day-to-day support tickets through to driving continuous improvement and maturity of the underlying processes. This is an individual-contributor role (no direct reports) requiring detailed, results-focused execution in a fully cloud-native, CMMC Level 2-obligated enterprise environment. The ideal candidate is highly organized, technically fluent across cyber, cloud, and compliance domains, and comfortable owning outcomes independently, from triaging a single ticket to redesigning a process.

Key Responsibilities:

Compliance
  • Own and maintain the organization's compliance posture against CMMC Level 2, NIST 800-171, and related federal contractor security requirements.
  • Maintain and continuously improve the System Security Plan (SSP), policies, and control narratives, ensuring evidence and documentation stay audit-ready.
  • Support C3PAO assessments and any follow-on assessments, coordinating evidence collection and remediation of findings.
  • Track and manage POA&Ms (Plans of Action & Milestones) through closure.
  • Monitor regulatory and contractual compliance changes and translate them into actionable internal requirements.

Asset Management
  • Own the IT asset inventory (hardware, software, cloud resources) across commercial and GCC High environments, ensuring accuracy and completeness.
  • Establish and maintain asset lifecycle processes: procurement, provisioning, tracking, and decommissioning/disposal.
  • Conduct software inventory triage and licensing reviews to identify unauthorized or high-risk tools and reduce audit risk.
  • Maintain shredding/disposal standards and documentation in accordance with applicable requirements (e.g., NSA/CSS EPL).

Security & Configuration Management
  • Own baseline security configuration standards across endpoints, servers, and cloud environments, and monitor for drift.
  • Manage the Change Control Board (CCB) process and associated risk-tiered change management framework.
  • Partner with the Cloud Architect/Engineer and IT team on configuration hardening, sensitivity labeling, and access control alignment with compliance requirements.
  • Support security incident response efforts by providing configuration, asset, and compliance context.
  • Maintain Confluence/KB documentation for CASC processes, optimized for both human use and internal AI/RAG retrieval.

Ticket Ownership & Continuous Improvement
  • Serve as the primary owner for compliance, asset, security configuration, and change management tickets in the IT service desk queue, from intake through resolution.
  • Triage and resolve day-to-day requests (asset requests, access/configuration questions, compliance inquiries, change requests) within established SLAs.
  • Use recurring ticket patterns and root-cause analysis to identify opportunities for process improvement, automation, and documentation.
  • Own the full lifecycle of each CASC function as a "product" - from reactive ticket support up through proactive roadmap and maturity planning.

Cross-Functional
  • Report on compliance, asset, and configuration risk posture to IT leadership on a regular cadence.
  • Collaborate with Cloud Architecture and Program teams to ensure CASC practices are embedded in ongoing initiatives (e.g., dual-tenant M365 architecture, AI tooling governance).
  • Drive process discipline and documentation rigor across all CASC areas.

Required Qualifications:
  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field.
  • Strong technical proficiency across cybersecurity, cloud platforms (Microsoft Azure/M365 preferred), and compliance frameworks.
  • Working knowledge of CMMC Level 2 / NIST 800-171 requirements and audit/assessment processes.
  • Experience with IT asset management and lifecycle tracking.
  • Experience with configuration/change management processes and tooling (e.g., Jira, ServiceNow, or similar).
  • Highly detail-oriented, organized, and results-focused, with the ability to independently drive initiatives to completion.
  • Strong written and verbal communication skills, including documentation and audit-facing materials.
  • Comfortable working a service desk/ticket queue directly and balancing reactive support work with longer-term process ownership.

Preferred Qualifications:
  • Master's degree in Information Technology, Cybersecurity, or related field.
  • Relevant IT/security certifications (e.g., CISSP, CISM, Security+, CySA+, CMMC-related certifications such as CCP/CCA, ITIL, or similar).
  • Experience supporting a federal contractor or Alaska Native Corporation (ANC)/8(a) environment.
  • Experience with dual-tenant Microsoft 365 environments (Commercial + GCC High).
  • Familiarity with Microsoft Purview, Defender for Cloud, or similar governance/security tooling.

Location

Hybrid with in person reporting at Colorado Springs CO, Reston VA, or Arlington VA

We will be accepting applications for this position until 4 September 2026.

Salary Range: $155 - $170 annually (final rate based on experience and location)

Aleut offers the following benefits to eligible employees:
  • Health insurance
  • Dental/Vision Insurance
  • Paid Time Off
  • Short- and Long-Term Disability
  • Life insurance
  • 401k, and match

Aleut Federal, LLC provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, sexual orientation, gender identity, or genetics. In addition to federal law requirements, AF complies with applicable state and local laws governing nondiscrimination in employment in every location where the company has facilities. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. AF prohibits workplace harassment based on race, color, sex, religion, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status.

#AF
group id: 10228809
Find Aleut Federal LLC on Social Media
Recruiters
user avatar
About Us
Aleut Federal, LLC, has staffing and labor expertise in DOD professional, scientific, and technical services, including ,but not limited to, Space Research and Technology, Satellite Telecommunications, Space Force Instruction, Data Processing, Computer Programming, Computer Facilities Management, Engineering, Administrative Management and General Management Consulting.