ISSO – Vulnerability Management

JCS Solutions LLC

Andrews (MD)

On-site

USD 100,000 - 114,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health, dental, and vision insurance
Life insurance
Short- and long-term disability
PTO
401k with employer match
Professional Development Reimbursement

Job summary

JCS Solutions LLC seeks an Information System Security Officer (ISSO) - Vulnerability Management to support the AFNCR IT Services Program. The role focuses on vulnerability assessment, remediation, RMF compliance, and ensuring adherence to DoD cybersecurity requirements to protect mission-critical systems.

You will manage POA&Ms, analyze scan results across CAT I–III, and develop reports and dashboards for leadership, audits, and compliance.

Qualifications

  • Active DoD Secret Security Clearance is required.
  • 3+ years of cybersecurity, information assurance, vulnerability management, or system administration experience.
  • At least 1 year of hands-on experience with ACAS, Tenable, or related vulnerability management platforms.
  • CompTIA Security+ CE or higher DoD 8570/8140-compliant certification meeting current ISSO qualification requirements.
  • Experience managing POA&Ms, vulnerability remediation efforts, and cybersecurity compliance documentation.

Responsibilities

  • Manage the POA&M process for cybersecurity vulnerabilities and DISA STIG findings.
  • Analyze vulnerability scan results to identify CAT I, II, III findings, false positives, and config issues.
  • Track, document, and validate remediation activities and exceptions in alignment with RMF.
  • Review DISA STIG checklists and implement secure configurations with admins and engineers.
  • Prepare vulnerability reports, dashboards, and metrics for leadership and compliance reviews.
  • Support ACAS asset groupings, scan zones, credentialed scanning configurations, and scan tuning strategies.
  • Maintain data hygiene within ACAS and reporting structures.
  • Collaborate with ISSOs, system admins, and engineering teams to prioritize remediation.
  • Assist cybersecurity audits, inspections, accreditation activities, and security control assessments.
  • Develop and maintain documentation supporting vulnerability management and system security posture.

Skills

Security Clearance
Vulnerability Management
RMF/NIST compliance
POA&M management
DISA STIGs
Communication
Dashboard reporting
Team collaboration

Education

Bachelor's degree in Cybersecurity/IT/CS

Tools

ACAS
Tenable
DISA STIGs
DISPATCH
STIG Manager
PowerShell
Python
Nessus APIs

Job description

Grow, innovate, and generate progress: Harness your expertise to solve challenges and celebrate success!

Job Summary

JCS Solutions is seeking an Information System Security Officer (ISSO) - Vulnerability Management to support the Air Force National Capital Region (AFNCR) IT Services Program. This program provides mission-critical IT support for Headquarters Air Force (HAF), Air Force District of Washington (AFDW), the Office of the Secretary of Defense (OSD), the Joint Chiefs of Staff, and other Air Force organizations throughout the National Capital Region. The ISSO - Vulnerability Management will play a critical role in maintaining the cybersecurity posture of enterprise systems supporting national defense missions. This position is responsible for managing vulnerability assessment and remediation efforts, supporting Risk Management Framework (RMF) compliance activities, and ensuring adherence to Department of Defense (DoD), Air Force, and cybersecurity regulatory requirements. The successful candidate will thrive in a fast-paced, mission-focused environment where secure, reliable, and compliant IT operations are essential to mission success.

What’s in it for you:
  • Join a premier technology firm specializing in innovative solutions.
  • Be part of a collaborative, inclusive, and innovative work culture.
  • Enjoy tremendous growth potential in a high-performing team environment.
  • A robust benefits package:
    • Health, dental, and vision insurance
    • Life insurance
    • Short-and-long term disability
    • Paid time off (PTO)
    • 401k retirement plan with employer match
    • Annual Professional Development Reimbursement Program
    • And more!
What you will do:
  • Manage the Plan of Action and Milestones (POA&M) process for cybersecurity vulnerabilities and DISA STIG findings
  • Analyze vulnerability scan results to identify CAT I, CAT II, and CAT III findings, false positives, and system configuration issues
  • Track, document, and validate remediation activities, POA&Ms, risk acceptances, and exceptions in alignment with RMF requirements
  • Review and interpret DISA STIG checklists and work closely with system administrators and engineers to implement and maintain secure configurations
  • Prepare and deliver vulnerability reports, compliance dashboards, and cybersecurity metrics for leadership, inspection readiness, and compliance reviews, including CCRI and CORA activities
  • Support the development and maintenance of ACAS asset groupings, scan zones, credentialed scanning configurations, and scan tuning strategies
  • Maintain data hygiene within ACAS, ensuring consistent tagging, grouping, and reporting structures
  • Collaborate with Queue Managers, ISSOs, system administrators, and engineering teams to prioritize, track, and remediate critical vulnerabilities
  • Support continuous monitoring initiatives and maintain compliance with RMF, NIST, DoD, and Air Force cybersecurity requirements
  • Assist with cybersecurity audits, inspections, accreditation activities, and security control assessments
  • Develop and maintain documentation supporting vulnerability management, compliance efforts, and system security posture
What you will bring:
  • Active DoD Secret Security Clearance
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field. Additional years of relevant experience and certifications may be considered in lieu of a degree
  • 3+ years of cybersecurity, information assurance, vulnerability management, or system administration experience
  • At least 1 year of hands-on experience with ACAS, Tenable, or related vulnerability management platforms
  • CompTIA Security+ CE or higher DoD 8570/8140-compliant certification meeting current ISSO qualification requirements
  • Experience managing POA&Ms, vulnerability remediation efforts, and cybersecurity compliance documentationWorking knowledge of DISA STIGs, vulnerability severity classifications, risk assessment methodologies, and remediation strategies
  • Familiarity with NIST SP 800-53, the Risk Management Framework (RMF), and Air Force cybersecurity policies, including AFMAN 17-130
  • Experience analyzing vulnerability scan results and identifying CAT I, II, and III findings, false positives, and configuration issues
  • Strong understanding of cybersecurity principles, enterprise systems, networks, and secure configuration management
  • Exceptional attention to detail, documentation skills, and the ability to interpret technical vulnerability data and communicate recommendations effectively
  • Strong interpersonal and collaboration skills with the ability to work across technical and non-technical teams
How you will wow us:
  • Experience supporting U.S. Air Force, DISA, AFNCR, or other Department of Defense mission environments
  • Familiarity with ACAS, DISPATCH, EvaluateSTIG, STIG Manager, and related vulnerability management and compliance tools
  • Experience supporting CCRI, CORA, Command Cyber Readiness Inspections, or similar cybersecurity assessment and inspection activities
  • Proven success coordinating enterprise vulnerability remediation campaigns and driving closure of high-priority findings
  • Ability to communicate risk-based recommendations to technical teams, leadership, and non-technical stakeholders
  • Experience developing executive-level dashboards, cybersecurity metrics, and compliance reporting
  • Knowledge of automation and scripting technologies such as PowerShell, Python, or Nessus APIs to improve operational efficiency and reporting capabilities
  • Advanced cybersecurity certifications such as CISSP, CASP+, CISM, or equivalent credentials
  • A proactive, solutions-oriented mindset with a passion for strengthening cybersecurity posture and supporting mission-critical operations
  • Experience working in fast-paced environments supporting high-visibility customers where operational readiness and security are paramount

JCS Solutions (JCS) is a premier technology firm providing innovative solutions and high-quality services in defense, national security, and civilian sectors. JCS offers enterprise-wide solutions including cloud computing, software development, cybersecurity, digital modernization, and management consulting for the federal government. At JCS, we elevate our customers’ mission through the application of technology and professional services. Our commitment to investing in our workforce drives innovation and progress for our clients, employees, and communities.

JCS is both a Great Place to Work and a Top Places to Work certified company.

Our employees embody our core values, and we are looking for others who do too!

  • Customer Experience: Strive for excellence and delight our clients
  • Innovation: Embrace creative thinking to enable continual growth and powerful solutions
  • Accountability: Take ownership of and pride in our actions and service delivery
  • Inspire: Be inspired to be your best self and have fun in the process
  • Integrity: Do the right thing, the right way, every time!
  • Stewardship: The careful and responsible management of something entrusted to our care.

At JCS Solutions, compensation is based on a number of factors such as location, qualifications, and applicable contract terms. The general salary range for this position is as follows: $100,000.00 - $114,000.00.

Please Note:

Employment is contingent upon successfully passing a pre-employment drug screening and any other required background checks, consistent with applicable law.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to any protected status protected by applicable federal, state, or local laws.

NOTICE

Please be aware that all JCS Solutions communications related to job interviews and offers from our recruiting team will only come from @JCSSolutions.com. We want to emphasize that we do not conduct any interviews over Discord, Slack, Skype, Zoom, or any chat app.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer (RMF & Cross Domain Solutions)
Cybersecurity Engineer (RMF & Cross Domain Solutions)

JCS Solutions LLC • Fort Belvoir (VA)

On-site
USD 61,000 - 101,000
Health, dental, and vision insurance
Life insurance
Disability insurance
+3
IT Security Lead
IT Security Lead

JCS Solutions LLC • Bethesda (MD)

On-site
USD 135,000 - 170,000
Health, dental, and vision insurance
Life insurance
Disability insurance
+3
Information System Security Officer (ISSO) (Engineer Info Assurance 3) - 28730
Information System Security Officer (ISSO) (Engineer Info Assurance 3) - 28730

Huntington Ingalls Industries • Nellis Air Force Base Census-Designated Place (NV)

On-site
USD 95,626 - 135,012
Medical, dental, and vision coverage
401(k) savings plan
Tuition reimbursement
+1
Information System Security Officer
Information System Security Officer

Jacobs • Chantilly (VA)

On-site
USD 110,000 - 180,000
Training and certification support
401(k) plan with company stock purchase option
Competitive salary and benefits package
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

CGS Federal (Contact Government Services) • Austin (TX)

On-site
USD 90,000 - 120,000
Health, Dental, and Vision
Life Insurance
401k
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

CGS Federal (Contact Government Services) • Charlotte (NC)

On-site
USD 110,000 - 170,000
Health, Dental, and Vision insurance
401k
Flexible Spending Account
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

CGS Federal (Contact Government Services) • Tampa (FL)

On-site
USD 110,000 - 160,000
Health, Dental, and Vision
Life Insurance
401k
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

CGS Federal (Contact Government Services) • United States

On-site
USD 85,000 - 115,000
Health, Dental, and Vision
Life Insurance
401k
+2
Information Systems Security Officer (ISSO)
Information Systems Security Officer (ISSO)

CGS Federal (Contact Government Services) • Miami (FL)

On-site
USD 85,000 - 105,000
Health, Dental, and Vision
Life Insurance
401k
+2
Cyber Network Defense Analyst
Cyber Network Defense Analyst

JCS Solutions LLC • Arlington (VA)

On-site
USD 101,000 - 145,000
Health, dental, and vision insurance
Life insurance
Short-and-long term disability
+4