Information Assurance Specialist II
Vast is looking for an Information Assurance Engineer II, reporting to the Information Security Manager, to assist in the deployment and maintenance of the organization's growing information security compliance program. The Information Assurance Engineer II supports the development of security policies and procedures, ensuring compliance with pertinent regulations and security standards (i.e. NIST SP 800-171 Rev 2, NIST 800-53 Rev 5).
This will be a full-time, exempt position located in our Long Beach location.
Responsibilities:
Maintain compliance documentation across NIST 800-171r2, NIST SP 800-53r5, CMMC 2.0, and ITAR/EAR; support the buildout of Vast's compliance program for both corporate and mission environments
Design and maintain automated compliance workflows to include scripting policy checks, evidence collection, control validation, and audit prep
Build and maintain integrations between security tooling (EDR, SIEM, vulnerability scanners, asset inventory) and compliance/ticketing platforms using APIs and scripting
Leverage AI and machine learning tools to accelerate security analysis, documentation review, and compliance gap identification; evaluate and integrate new AI-assisted tools into the compliance pipeline
Create and maintain dashboards and automated reporting for compliance posture across multiple frameworks
Support change management, risk assessments, and all internal and external security assessments
Continuously monitor security systems, networks, and applications for compliance drift
Partner with Information Security Engineering to automate control implementation and validation
Provide Information Security related training as required
Minimum Qualifications:
2+ years of experience supporting compliance efforts in the Defense Industrial Base and/or within the broader commercial space industry
Previous experience implementing and documenting NIST standards (i.e. 800-53, 800-171, CSF)
Proficient understanding of cloud systems such as AWS, Google, and Azure
Experience in continuously monitoring controls and conducting remediations
Experience in supporting certification assessments, gap assessments, self-assessments, and/or compliance audits.
Proficiency in security tools such as SIEM, IDS/IPS, EDR, and vulnerability scanning to include their APIs and integration capabilities.
Experience integrating security tools and platforms through APIs, webhooks, or automation frameworks
Familiarity with workflow automation and orchestration tools (e.g., n8n, Tines, SOAR platforms, or similar)
Preferred Skills & Experience:
Possess an active certification listed under DoD 8140 IAM Level II and/or IAT Level II (i.e. Security+ CE, CISSP, etc.)
Experience using AI/LLM tools to augment security analysis, documentation, or compliance workflows
Experience building automated evidence collection pipelines or continuous compliance monitoring
Familiarity with infrastructure-as-code or configuration management tools (Terraform, Ansible, etc.) in a compliance context
Experience with MCP (Model Context Protocol) or similar AI integration patterns for security tooling
Prior experience automating GRC processes at scale in a rapidly growing environment
Additional Requirements:
Ability to travel up to 10% of the time
Willingness to work overtime, or weekends to support critical mission milestones
Ability to lift up to 25lbs unassisted
Specific certifications, as appropriate
Pay Range:
Information Assurance Specialist II: $91,000.00 - $130,000.00
Pay Range: California
$91,000—$130,000 USD