Compliance, Asset, Security, & Configuration Management (CASC) Manager

Aleut FederalColorado Springs, VA
$155,000 - $170,000Hybrid

About The Position

Aleut Federal is seeking a Compliance, Asset, Security, & Configuration Management (CASC) Manager to own and mature the organization's compliance posture, IT asset lifecycle, security configuration standards, and change/configuration management practices. This is a full product-ownership role: the CASC Manager owns these areas end-to-end, from working day-to-day support tickets through to driving continuous improvement and maturity of the underlying processes. This is an individual-contributor role (no direct reports) requiring detailed, results-focused execution in a fully cloud-native, CMMC Level 2-obligated enterprise environment. The ideal candidate is highly organized, technically fluent across cyber, cloud, and compliance domains, and comfortable owning outcomes independently, from triaging a single ticket to redesigning a process.

Requirements

  • Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field.
  • Strong technical proficiency across cybersecurity, cloud platforms (Microsoft Azure/M365 preferred), and compliance frameworks.
  • Working knowledge of CMMC Level 2 / NIST 800-171 requirements and audit/assessment processes.
  • Experience with IT asset management and lifecycle tracking.
  • Experience with configuration/change management processes and tooling (e.g., Jira, ServiceNow, or similar).
  • Highly detail-oriented, organized, and results-focused, with the ability to independently drive initiatives to completion.
  • Strong written and verbal communication skills, including documentation and audit-facing materials.
  • Comfortable working a service desk/ticket queue directly and balancing reactive support work with longer-term process ownership.

Nice To Haves

  • Master's degree in Information Technology, Cybersecurity, or related field.
  • Relevant IT/security certifications (e.g., CISSP, CISM, Security+, CySA+, CMMC-related certifications such as CCP/CCA, ITIL, or similar).
  • Experience supporting a federal contractor or Alaska Native Corporation (ANC)/8(a) environment.
  • Experience with dual-tenant Microsoft 365 environments (Commercial + GCC High).
  • Familiarity with Microsoft Purview, Defender for Cloud, or similar governance/security tooling.

Responsibilities

  • Own and maintain the organization's compliance posture against CMMC Level 2, NIST 800-171, and related federal contractor security requirements.
  • Maintain and continuously improve the System Security Plan (SSP), policies, and control narratives, ensuring evidence and documentation stay audit-ready.
  • Support C3PAO assessments and any follow-on assessments, coordinating evidence collection and remediation of findings.
  • Track and manage POA&Ms (Plans of Action & Milestones) through closure.
  • Monitor regulatory and contractual compliance changes and translate them into actionable internal requirements.
  • Own the IT asset inventory (hardware, software, cloud resources) across commercial and GCC High environments, ensuring accuracy and completeness.
  • Establish and maintain asset lifecycle processes: procurement, provisioning, tracking, and decommissioning/disposal.
  • Conduct software inventory triage and licensing reviews to identify unauthorized or high-risk tools and reduce audit risk.
  • Maintain shredding/disposal standards and documentation in accordance with applicable requirements (e.g., NSA/CSS EPL).
  • Own baseline security configuration standards across endpoints, servers, and cloud environments, and monitor for drift.
  • Manage the Change Control Board (CCB) process and associated risk-tiered change management framework.
  • Partner with the Cloud Architect/Engineer and IT team on configuration hardening, sensitivity labeling, and access control alignment with compliance requirements.
  • Support security incident response efforts by providing configuration, asset, and compliance context.
  • Maintain Confluence/KB documentation for CASC processes, optimized for both human use and internal AI/RAG retrieval.
  • Serve as the primary owner for compliance, asset, security configuration, and change management tickets in the IT service desk queue, from intake through resolution.
  • Triage and resolve day-to-day requests (asset requests, access/configuration questions, compliance inquiries, change requests) within established SLAs.
  • Use recurring ticket patterns and root-cause analysis to identify opportunities for process improvement, automation, and documentation.
  • Own the full lifecycle of each CASC function as a "product" — from reactive ticket support up through proactive roadmap and maturity planning.
  • Report on compliance, asset, and configuration risk posture to IT leadership on a regular cadence.
  • Collaborate with Cloud Architecture and Program teams to ensure CASC practices are embedded in ongoing initiatives (e.g., dual-tenant M365 architecture, AI tooling governance).
  • Drive process discipline and documentation rigor across all CASC areas.

Benefits

  • Health insurance
  • Dental/Vision Insurance
  • Paid Time Off
  • Short- and Long-Term Disability
  • Life insurance
  • 401k, and match
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service