Disruptive Solutions logo
Hiring from
United States
Work type
Remote
Posted
Oct 2, 2026
Is this job info correct?

Job Description

This is a remote position.

Information Assurance Analyst

Location: Remote
Clearance Requirement: Active Secret
Employment Type: Full-Time

About Company

Disruptive Solutions, a Service-Disabled Veteran-Owned Small Business (SDVOSB) delivering mission-focused cybersecurity and technology solutions for federal and commercial clients. We specialize in advanced cybersecurity operations, AI/ML integration, cloud modernization, data governance, and risk management. With a proven track record supporting agencies like the Department of Defense (DoD), Department of Homeland Security (DHS), Cybersecurity and Infrastructure Security Agency (CISA), and the Department of Treasury, we deliver innovative solutions that maximize efficiency and strengthen cyber resilience. At our core, we are dedicated partners committed to securing the mission with innovation, integrity, and measurable impact.

Job Summary

Disruptive Solutions is seeking an experienced Information Assurance (IA) Analyst to support cybersecurity, Risk Management Framework (RMF), and continuous monitoring activities for State. The IA Analyst will work closely with ISSOs, system owners, security engineers, SCAs, and other cybersecurity stakeholders to maintain system authorization documentation, collect and validate security control evidence, track vulnerabilities and remediation activities, and help ensure information systems remain compliant and audit-ready.

Key Responsibilities

  • Support ISSOs with implementation and ongoing execution of the NIST Risk Management Framework (RMF) for assigned information systems.
  • Develop, maintain, and update authorization artifacts including System Security Plans (SSPs), security control implementation statements, POA&Ms, system inventories, Security Impact Analyses (SIAs), Contingency Plans (CPs), Incident Response Plans (IRPs), Configuration Management Plans (CMPs), and supporting security documentation.
  • Build and maintain security control evidence packages, including evidence indexes, inherited control matrices, system boundary documentation, and network and data-flow diagrams.
  • Collect and organize security evidence including configuration baselines, SOPs, access control lists, screenshots, system configurations, and log samples.
  • Review continuous monitoring results and identify findings contributing to elevated system risk.
  • Track vulnerability findings, remediation activities, and findings remaining open beyond established remediation timelines.
  • Maintain POA&Ms entries within the applicable GRC platform and collect supporting evidence for finding closure and ISSO validation.
  • Review vulnerability and compliance scan results and track critical and high-risk findings through remediation.
  • Interpret security and compliance findings from technologies including Tenable/Nessus, Wiz, STIG Viewer, SCAP, and comparable security platforms.
  • Support compliance with applicable CISA Binding Operational Directives (BODs) and vulnerability remediation requirements.
  • Support Security Control Assessments (SCAs) by preparing assessment materials, collecting requested artifacts, and assisting with security control demonstrations.
  • Support annual Contingency Plan testing and security control assessments, including preparation of test plans, coordination of participants, documentation of results, and tracking lessons learned.
  • Register and maintain system records within applicable GRC and continuous monitoring platforms, including ArchAngel, iPost, or comparable technologies.
  • Support system asset inventory and application grouping accuracy.
  • Prepare cybersecurity meeting materials, document meeting minutes, and maintain action-item and remediation trackers.
  • Assemble audit and data-call response packages containing SSPs, POA&Ms, vulnerability reports, assessment results, contingency plan test results, and supporting documentation.
  • Support FISMA metrics, High Value Asset (HVA) activities, OMB/OIG requests, BOD reporting, CDM data calls, and other cybersecurity compliance requirements.
  • Maintain disciplined document management and version control of cybersecurity and RMF artifacts.

Required Qualifications

  • 3+ years of information assurance, cybersecurity compliance, or related cybersecurity experience, including hands-on exposure to federal RMF/FISMA authorization activities.
  • Working knowledge of NIST SP 800-53 Rev. 5, NIST SP 800-37 Rev. 2, and FIPS 199.
  • Understanding of SSPs, POA&Ms, security controls, continuous monitoring, and contingency planning.
  • Experience developing, maintaining, or supporting federal cybersecurity authorization documentation.
  • Experience collecting and validating security control implementation evidence.
  • Familiarity with vulnerability management, remediation tracking, and continuous monitoring.
  • Experience or familiarity with enterprise Governance, Risk, and Compliance (GRC) platforms.
  • Ability to interpret vulnerability and compliance scan results.
  • Strong written communication and attention to detail with the ability to produce professional government documentation.
  • Proficiency with Microsoft Word, Excel, PowerPoint, Visio, and SharePoint.
  • Active Secret security clearance.
  • U.S. Citizenship required.
  • Must possess or be able to obtain within six months of hire an applicable DoD 8140/8570 IAT Level II or IAM Level I baseline certification. Applicable certifications may include Security+ CE, CySA+, SSCP, CGRC (formerly CAP), or other qualifying certifications based on program requirements.

Preferred Qualifications

  • CISSP, Associate of ISC2, CGRC, CISA, or other relevant cybersecurity certification.
  • Previous experience supporting State.
  • Experience with ArchAngel and iPost or comparable GRC and continuous monitoring platforms.
  • Experience interpreting Tenable/Nessus, Wiz, STIG, or SCAP vulnerability and compliance results.
  • Familiarity with AWS and/or Azure security concepts and environments.
  • Familiarity with FedRAMP and cloud security control inheritance.
  • Experience supporting High Value Asset (HVA) systems.
  • Experience working collaboratively with ISSOs, SCAs, vulnerability management teams, and security engineers.
  • Education: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Information Systems, or a related field is preferred.

Equal Opportunity Statement

Disruptive Solutions, LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender identity, or any other characteristic protected by law.



Similar jobs

Apply for this job