USAF - ACAS Engineer

cFocus Software Incorporated

Linthicum (MD)

On-site

USD 90,000 - 120,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

cFocus Software seeks an ACAS Engineer to support the United States Air Force (USAF). The position is on-site in Linthicum Heights, MD and requires an active TS/SCI clearance.

You will configure, operate, and maintain enterprise vulnerability scanning, coordinate remediation with system owners, and produce CORA-based vulnerability reports for authorization activities.

Qualifications

  • Active TS/SCI clearance required.
  • B.S. Computer Science, Information Technology, or a related field.
  • Experience administering ACAS or comparable enterprise vulnerability assessment tools, including scan configuration, scheduling, credentialed scanning, and reporting.
  • Ability to diagnose scan failures and authentication issues, assess coverage, validate findings, and verify remediation through follow‑up scanning.
  • Working knowledge of enterprise networks, server operating systems, applications, virtual infrastructure, and cloud or hybrid environments.
  • Experience interpreting vulnerability findings and coordinating patching, secure configuration changes, and STIG remediation with technical teams.
  • Ability to prepare accurate vulnerability reports, maintain assessment records, and provide technical evidence for cybersecurity compliance and authorization activities.
  • Clear communication skills for explaining findings, coordinating remediation, and working with system owners and operations personnel.]

Responsibilities

  • Configure, operate, and maintain assigned ACAS and Government-approved enterprise vulnerability scanning capabilities, following approved designs, security baselines, and change procedures.
  • Perform weekly vulnerability scans of DC3 networks and applications. Coordinate credentialed scanning across scoped IT and operational technology assets, including approved scan windows and access arrangements.
  • Maintain scan scope and asset coverage records; identify missed assets, failed scans, and authentication problems, and coordinate corrective action to improve coverage.
  • Analyze scan results, validate findings, investigate suspected false positives, and prioritize vulnerabilities for remediation in coordination with system owners and cybersecurity personnel.
  • Prepare and submit the Vulnerability Report using the CORA scoring model to the Government no later than 5 p.m. Eastern Time every Friday. Check report accuracy, completeness, and technical quality before submission.
  • Track identified vulnerabilities through remediation and verification. Recommend corrective actions, coordinate patching and secure configuration changes, and perform follow‑up scans to validate closure.
  • Support continuous vulnerability monitoring and secure configuration management. Provide findings and technical evidence for compliance reviews and security posture reporting.
  • Coordinate with systems administrators and engineers to support timely remediation of critical infrastructure vulnerabilities and implementation of Government‑directed security requirements.
  • Support the automated Vulnerability Management Program through approved CI/CD workflows, scan analysis, remediation recommendations, and patch verification.
  • Support Infrastructure as Code and Configuration as Code processes by evaluating security findings and proposed changes before authorized deployment to production.
  • Assist with enterprise scanning engine deployment for Initial Operational Capability (IOC), due 180 calendar days after the transition‑in period, and support continued scanning during NOC/SOC sustainment.
  • Provide vulnerability data, scan records, and technical evidence supporting Risk Management Framework assessments and Authorization to Operate or continuous ATO activities.
  • Maintain scanning procedures and troubleshooting documentation.
  • Coordinate with NOC, SOC, and incident response personnel when findings indicate potential compromise or urgent security exposure.

Skills

Active TS/SCI clearance
BS in CS/IT or related field
ACAS administration
Vulnerability scanning & reporting
Network and enterprise knowledge
Remediation coordination
Clear communication

Education

Bachelor of Science in Computer Science, Information Technology, or related field

Tools

ACAS

Job description

cFocus Software seeks a ACAS Engineer to join our program supporting the United States Air Force (USAF). This position is on-site in Linthicum Heights, MD. This position requires an Active TS/SCI clearance.

Qualifications:
  • Active TS/SCI clearance
  • B.S. Computer Science, Information Technology, or a related field
  • Experience administering ACAS or comparable enterprise vulnerability assessment tools, including scan configuration, scheduling, credentialed scanning, and reporting.
  • Ability to diagnose scan failures and authentication issues, assess coverage, validate findings, and verify remediation through follow‑up scanning.
  • Working knowledge of enterprise networks, server operating systems, applications, virtual infrastructure, and cloud or hybrid environments.
  • Experience interpreting vulnerability findings and coordinating patching, secure configuration changes, and STIG remediation with technical teams.
  • Ability to prepare accurate vulnerability reports, maintain assessment records, and provide technical evidence for cybersecurity compliance and authorization activities.
  • Clear communication skills for explaining findings, coordinating remediation, and working with system owners and operations personnel.
Duties:
  • Configure, operate, and maintain assigned ACAS and Government-approved enterprise vulnerability scanning capabilities, following approved designs, security baselines, and change procedures.
  • Perform weekly vulnerability scans of DC3 networks and applications. Coordinate credentialed scanning across scoped IT and operational technology assets, including approved scan windows and access arrangements.
  • Maintain scan scope and asset coverage records; identify missed assets, failed scans, and authentication problems, and coordinate corrective action to improve coverage.
  • Analyze scan results, validate findings, investigate suspected false positives, and prioritize vulnerabilities for remediation in coordination with system owners and cybersecurity personnel.
  • Prepare and submit the Vulnerability Report using the CORA scoring model to the Government no later than 5 p.m. Eastern Time every Friday. Check report accuracy, completeness, and technical quality before submission.
  • Track identified vulnerabilities through remediation and verification. Recommend corrective actions, coordinate patching and secure configuration changes, and perform follow‑up scans to validate closure.
  • Support continuous vulnerability monitoring and secure configuration management. Provide findings and technical evidence for compliance reviews and security posture reporting.
  • Coordinate with systems administrators and engineers to support timely remediation of critical infrastructure vulnerabilities and implementation of Government‑directed security requirements.
  • Support the automated Vulnerability Management Program through approved CI/CD workflows, scan analysis, remediation recommendations, and patch verification.
  • Support Infrastructure as Code and Configuration as Code processes by evaluating security findings and proposed changes before authorized deployment to production.
  • Assist with enterprise scanning engine deployment for Initial Operational Capability (IOC), due 180 calendar days after the transition‑in period, and support continued scanning during NOC/SOC sustainment.
  • Provide vulnerability data, scan records, and technical evidence supporting Risk Management Framework assessments and Authorization to Operate or continuous ATO activities.
  • Maintain scanning procedures and troubleshooting documentation.
  • Coordinate with NOC, SOC, and incident response personnel when findings indicate potential compromise or urgent security exposure.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

ACAS Engineer with Security Clearance
ACAS Engineer with Security Clearance

ICS Nett, Inc. (ICS) • Quantico (VA)

Hybrid
USD 110,000 - 140,000
Telework
Onsite 3 days/week
Cybersecurity Engineer 5 - Vulnerability Management / ACAS Engineer
Cybersecurity Engineer 5 - Vulnerability Management / ACAS Engineer

Kinsley Power Systems • Columbus (OH)

On-site
USD 100,000 - 130,000
USAF - Cloud Engineer
USAF - Cloud Engineer

cFocus Software Incorporated • Linthicum (MD)

On-site
USD 140,000 - 180,000
System Administrator (ACAS/Vulnerability Management)
System Administrator (ACAS/Vulnerability Management)

Abacus Technology • Montgomery (AL)

On-site
USD 70,000 - 100,000
Senior ACAS Engineer - Vulnerability & Compliance (Remote)
Senior ACAS Engineer - Vulnerability & Compliance (Remote)

ICS Nett, Inc. (ICS) • Quantico (VA)

Hybrid
USD 110,000 - 140,000
Telework
Onsite 3 days/week
USAF - Systems Administrator
USAF - Systems Administrator

cFocus Software Incorporated • Linthicum (MD)

On-site
USD 90,000 - 130,000
ACAS & Vulnerability Management Systems Administrator
ACAS & Vulnerability Management Systems Administrator

Abacus Technology • Montgomery (AL)

On-site
USD 70,000 - 100,000
Cyber Security Engineer - ACAS (Hybrid) at ASRC Federal Holding Company Seaside, CA
Cyber Security Engineer - ACAS (Hybrid) at ASRC Federal Holding Company Seaside, CA

ASRC Federal Holding Company • Seaside (CA)

On-site
USD 125,000 - 145,000
Medical, dental, and vision insurance
Paid leave and holidays
401(k) with company match
+2
System Administrator II Assured Compliance Assessment Solution (ACAS) Administrator/Vulnerability Assessment (VA) Analyst)
System Administrator II Assured Compliance Assessment Solution (ACAS) Administrator/Vulnerability Assessment (VA) Analyst)

DLS Engineering • Montgomery (AL)

On-site
USD 64,000 - 67,000
401k with company match
Health, Vision, Dental, Life Insurance
Paid Time Off
ACAS Administrator
ACAS Administrator

Colonial Group • Alexandria (VA), Northern (KY)

Hybrid
USD 90,000 - 120,000