Compliance, Asset, Security Configuration Management; CASC) M Security Clearance
Job in
Colorado Springs, El Paso County, Colorado, 80919, USA
Listed on 2026-08-31
Listing for:
Aleut Federal LLC
Full Time
position Listed on 2026-08-31
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
About Aleut Federal At Aleut Federal, we believe the company and its mission is just as important as the job you are applying for. Aleut Federal is an Alaskan Native-owned enterprise whose purpose is to support our "Shareholders," the Unangax, the indigenous people of the Aleutian Islands of Alaska. People are at the core of everything we do. We support our Shareholders by providing excellent service and quality results to our Clients, the various branches of the federal government.
We engage in our local markets, so community service is embedded into our process. Our culture nurtures the strength of our workforce through mentorship and coaching, providing opportunities for growth, and competitive benefits. We support and encourage diversity, inclusion, and accountability at every level. The Aleut Federal motto is "We are One" because we truly believe that with one heart, one mind, and one purpose, we can accomplish our mission and be an organization anyone would be proud to be a part of.
Position Overview Aleut Federal is seeking a Compliance, Asset, Security, & Configuration Management (CASC) Manager to own and mature the organization's compliance posture, IT asset lifecycle, security configuration standards, and change/configuration management practices. This is a full product-ownership role: the CASC Manager owns these areas end-to-end, from working day-to-day support tickets through to driving continuous improvement and maturity of the underlying processes.
This is an individual-contributor role (no direct reports) requiring detailed, results-focused execution in a fully cloud-native, CMMC Level 2-obligated enterprise environment. The ideal candidate is highly organized, technically fluent across cyber, cloud, and compliance domains, and comfortable owning outcomes independently, from triaging a single ticket to redesigning a process.
Key Responsibilities:
Compliance
* Own and maintain the organization's compliance posture against CMMC Level 2, NIST 800-171, and related federal contractor security requirements.
* Maintain and continuously improve the System Security Plan (SSP), policies, and control narratives, ensuring evidence and documentation stay audit-ready.
* Support C3
PAO assessments and any follow-on assessments, coordinating evidence collection and remediation of findings.
* Track and manage POA&Ms (Plans of Action & Milestones) through closure.
* Monitor regulatory and contractual compliance changes and translate them into actionable internal requirements. Asset Management
* Own the IT asset inventory (hardware, software, cloud resources) across commercial and GCC High environments, ensuring accuracy and completeness.
* Establish and maintain asset lifecycle processes: procurement, provisioning, tracking, and decommissioning/disposal.
* Conduct software inventory triage and licensing reviews to identify unauthorized or high-risk tools and reduce audit risk.
* Maintain shredding/disposal standards and documentation in accordance with applicable requirements (e.g., NSA/CSS EPL). Security & Configuration Management
* Own baseline security configuration standards across endpoints, servers, and cloud environments, and monitor for drift.
* Manage the Change Control Board (CCB) process and associated risk-tiered change management framework.
* Partner with the Cloud Architect/Engineer and IT team on configuration hardening, sensitivity labeling, and access control alignment with compliance requirements.
* Support security incident response efforts by providing configuration, asset, and compliance context.
* Maintain Confluence/KB documentation for CASC processes, optimized for both human use and internal AI/RAG retrieval. Ticket Ownership & Continuous Improvement
* Serve as the primary owner for compliance, asset, security configuration, and change management tickets in the IT service desk queue, from intake through resolution.
* Triage and resolve day-to-day requests (asset requests, access/configuration questions, compliance inquiries, change requests) within established SLAs.
* Use recurring ticket patterns and root-cause analysis to identify opportunities for process improvement,…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×