Information Assurance/ACAS Engineer

IPSecure

Chicago (IL)

On-site

USD 95,000 - 130,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical Insurance
Dental Insurance
Vision Insurance
401(k)
Education Reimbursement
Certification Reimbursement
Unlimited Vacation
Paid Holidays

Job summary

IPSecure is seeking an experienced Information Assurance/RMF Analyst to support DoD and USAF cyber operations. You will execute RMF across the A&A lifecycle, manage ACAS/Tenable scanners, and prepare SSPs, SARs, and POA&Ms.

Collaboration with system owners and engineers is essential to maintain authorization and compliance. The role requires hands-on RMF experience, proficiency with ACAS/Tenable, STIG/SRG familiarity, and strong communication skills.

Qualifications

  • 3+ years of Information Assurance, cybersecurity, or RMF experience.
  • Hands-on RMF experience with DoD or federal information systems.
  • Proven knowledge of NIST SP 800-53 security controls and RMF documentation requirements.
  • Proficiency with ACAS/Tenable, including vulnerability scanning, analysis, reporting, and remediation validation.
  • Experience with STIGs, SCAP, vulnerability management, and security compliance assessments.
  • Experience developing or maintaining RMF authorization packages and supporting artifacts.
  • Ability to analyze technical vulnerability findings and communicate remediation requirements to system administrators and engineers.
  • Experience supporting Windows, Linux, network, or enterprise infrastructure environments.
  • Strong written and verbal communication skills; ability to work in a government/contractor team.

Responsibilities

  • Execute and support the DoD RMF process throughout the system authorization lifecycle.
  • Develop, review, and maintain RMF and Assessment & Authorization artifacts.
  • Support SSPs, SARs, POA&Ms, risk assessments, and supporting evidence.
  • Implement and document applicable NIST SP 800-53 controls.
  • Perform continuous monitoring to maintain cybersecurity posture and authorization.
  • Operate and maintain ACAS, Nessus, and Tenable.sc; manage scans, policies, and credentials.
  • Configure and run authenticated/unauthenticated vulnerability scans across Windows, Linux, and network devices.
  • Analyze ACAS results to identify vulnerabilities and remediation requirements.
  • Collaborate with admins and engineers to track remediation activities.
  • Review findings and assist with determining operational and mission risk.
  • Track remediation and validate actions through rescans and evidence.
  • Support STIG/SRG compliance and vulnerability management activities.
  • Respond to cybersecurity directives and compliance requirements.
  • Prepare documentation and evidence for security control assessments and audits.
  • Coordinate with ISSM, SCAs, system owners, engineers, and government personnel.
  • Maintain accurate cybersecurity records and provide status reporting.

Skills

RMF Experience
ACAS/Tenable
Vulnerability Management
NIST 800-53
Documentation
Communication
Windows/Linux
STIGs/SCAP

Education

Bachelor's degree

Tools

ACAS
Nessus
Tenable.sc

Job description

Information Assurance/ACAS Engineer – TS/SCI Clearance Required – JBSA Lackland - San Antonio, TX

Job Description

IPSecure is seeking an experienced Information Assurance (IA)/Risk Management Framework Analyst to support Department of Defense and U.S. Air Force cybersecurity operations. The successful candidate will have hands‑on experience executing the Risk Management Framework (RMF) and supporting systems throughout the Assessment and Authorization (A&A) lifecycle.


The ideal candidate will be highly proficient with Assured Compliance Assessment Solution (ACAS) and experienced in vulnerability management, security control implementation and assessment, remediation tracking, and maintaining cybersecurity authorization documentation.


Job Responsibilities


  • Execute and support the DoD Risk Management Framework (RMF) process throughout the system authorization lifecycle.

  • Develop, review, and maintain RMF and Assessment & Authorization documentation and artifacts.

  • Support the development and maintenance of System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), Risk Assessment Reports, and supporting evidence.

  • Implement, assess, and document applicable NIST SP 800-53 security controls.

  • Perform continuous monitoring activities to maintain system cybersecurity posture and authorization.

  • Operate and maintain ACAS, including Nessus scanners, Security Center/Tenable.sc, repositories, scan zones, policies, and credentials as applicable.

  • Configure and execute authenticated and unauthenticated vulnerability scans across Windows, Linux, network devices, and other supported infrastructure.

  • Analyze ACAS vulnerability scan results to identify vulnerabilities, configuration deficiencies, false positives, and remediation requirements.

  • Work with system administrators, network engineers, and system owners to develop and track vulnerability remediation activities.

  • Review vulnerability findings and assist with determining operational and mission risk.

  • Track remediation activities and validate corrective actions through rescanning and supporting evidence.

  • Support STIG/SRG compliance, security configuration assessments, and vulnerability management activities.

  • Review and respond to applicable cybersecurity directives, vulnerability notifications, and compliance requirements.

  • Prepare cybersecurity documentation and evidence for security control assessments, authorization decisions, inspections, and audits.

  • Coordinate with ISSM, Security Control Assessors (SCAs), system owners, engineers, and government cybersecurity personnel.

  • Maintain accurate cybersecurity records and provide status reporting on vulnerabilities, POA&Ms, compliance, and authorization activities.


Basic Qualifications

Security Clearance: Active TS/SCI


Education: Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Engineering, or related discipline. Equivalentexperiencemay be substituted.


Certification: Candidate must meet applicable DoD 8140 cybersecurity workforce qualification requirements for the assigned position.


Experience:



  • 3+ years of Information Assurance, cybersecurity, or RMF experience supporting DoD or federal information systems.

  • Demonstrated hands‑on experience with the DoD Risk Management Framework (RMF).

  • Proven working knowledge of NIST SP 800-53 security controls and RMF documentation requirements.

  • Proficiency with ACAS/Tenable, including vulnerability scanning, analysis, reporting, and remediation validation.

  • Experience with STIGs, SCAP, vulnerability management, and security compliance assessments.

  • Experience developing or maintaining RMF authorization packages and supporting artifacts.

  • Ability to analyze technical vulnerability findings and communicate remediation requirements to system administrators and engineers.

  • Experience supporting Windows, Linux, network, or enterprise infrastructure environments.

  • Proven written and verbal communication skills.

  • Ability to work collaboratively within a government/contractor integrated team environment.


Preferred Qualifications

Certifications: CISSP, GSLC, GIAC certifications or other applicable DoD 8140 qualifications, or CCSP certification


Medical, Dental, Vision, Unlimited Vacation, Sick Leave, Paid Federal Holidays, Education and Certification Reimbursement Program, 401(k) retirement plan with safe harbor employer match after 3 months, Prepaid Legal Plan and Identity Protection Plan available, Accident Insurance, Critical Illness Insurance, and Hospital Indemnity Insurance available.


EEOC Statement

IPSecure does not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.


IPSecure is an Equal Opportunity Affiant Employer. EOE, Minorities, Females, Vet, Disabled, Sexual Orientation, Gender Identity or any other protected class. All qualified job seekers are encouraged to apply. IPSecure is committed to America's veterans by providing opportunities for them to continue contributing after service to our nation. We also work to provide reasonable accommodations to individuals with disabilities.
EEO Is The Law


Disability Accessibility Accommodation

If you have a disability and require assistance with our online application process, please tell us how we can help.
E-mail hr@ipsecureinc.com or call 210-877-1111.


Note:

Pay Transparency - The company will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Assurance/ACAS Engineer
Information Assurance/ACAS Engineer

IPSecure, Inc. • San Antonio (TX)

On-site
USD 100,000 - 150,000
Medical, Dental, Vision
Unlimited vacation
401(k) retirement plan
+3
Information Assurance Engineer III
Information Assurance Engineer III

IPSECURE, INC. • San Antonio (TX)

On-site
USD 120,000 - 160,000
Cyber Security Specialist (RMF)
Cyber Security Specialist (RMF)

IPSECURE, INC. • Albuquerque (NM)

On-site
USD 140,000 - 180,000
Medical
Dental
Vision
+5
Cybersecurity Systems Analyst (TS/SCI) - RMF/A&A Expert
Cybersecurity Systems Analyst (TS/SCI) - RMF/A&A Expert

TJ Consulting Group • Fort Bragg (NC)

On-site
USD 70,000 - 85,000
PTO
401K with a 4% Match
Medical Insurance
+4
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

D2 Consulting • Arnold (MO)

On-site
USD 120,000 - 130,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

D2 Technical Services • Springfield (VA)

On-site
USD 130,000 - 140,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Cyber Security Engineer - ACAS (Hybrid) at ASRC Federal Holding Company Seaside, CA
Cyber Security Engineer - ACAS (Hybrid) at ASRC Federal Holding Company Seaside, CA

ASRC Federal Holding Company • Seaside (CA)

Hybrid
USD 125,000 - 145,000
Medical, dental, and vision insurance
Paid leave and holidays
401(k) with company match
+2
Cyber Security Analyst II
Cyber Security Analyst II

Scientific Research Corporation • San Diego (CA)

On-site
USD 84,000 - 140,000
Medical, dental, and vision plans
401(k) with company match
Paid time off & holidays
+1
ACAS Administrator - Senior Level
ACAS Administrator - Senior Level

Agile Defense, LLC • Quantico (VA)

On-site
USD 135,000 - 145,000
Cyber Security Analyst II
Cyber Security Analyst II

Scientific Research Corporation • San Diego (CA)

On-site
USD 84,000 - 140,000