USAF - ACAS Engineer
Linthicum Heights, MD
Full Time
USAF - DC3
Experienced
cFocus Software seeks a ACAS Engineer to join our program supporting the United States Air Force (USAF). This position is on-site in Linthicum Heights, MD. This position requires an Active TS/SCI clearance.
Qualifications:
Qualifications:
- Active TS/SCI clearance
- B.S. Computer Science, Information Technology, or a related field
- Experience administering ACAS or comparable enterprise vulnerability assessment tools, including scan configuration, scheduling, credentialed scanning, and reporting.
- Ability to diagnose scan failures and authentication issues, assess coverage, validate findings, and verify remediation through follow-up scanning.
- Working knowledge of enterprise networks, server operating systems, applications, virtual infrastructure, and cloud or hybrid environments.
- Experience interpreting vulnerability findings and coordinating patching, secure configuration changes, and STIG remediation with technical teams.
- Ability to prepare accurate vulnerability reports, maintain assessment records, and provide technical evidence for cybersecurity compliance and authorization activities.
- Clear communication skills for explaining findings, coordinating remediation, and working with system owners and operations personnel.
- Configure, operate, and maintain assigned ACAS and Government-approved enterprise vulnerability scanning capabilities, following approved designs, security baselines, and change procedures.
- Perform weekly vulnerability scans of DC3 networks and applications. Coordinate credentialed scanning across scoped IT and operational technology assets, including approved scan windows and access arrangements.
- Maintain scan scope and asset coverage records; identify missed assets, failed scans, and authentication problems, and coordinate corrective action to improve coverage.
- Analyze scan results, validate findings, investigate suspected false positives, and prioritize vulnerabilities for remediation in coordination with system owners and cybersecurity personnel.
- Prepare and submit the Vulnerability Report using the CORA scoring model to the Government no later than 5 p.m. Eastern Time every Friday. Check report accuracy, completeness, and technical quality before submission.
- Track identified vulnerabilities through remediation and verification. Recommend corrective actions, coordinate patching and secure configuration changes, and perform follow-up scans to validate closure.
- Support continuous vulnerability monitoring and secure configuration management. Provide findings and technical evidence for compliance reviews and security posture reporting.
- Coordinate with systems administrators and engineers to support timely remediation of critical infrastructure vulnerabilities and implementation of Government-directed security requirements.
- Support the automated Vulnerability Management Program through approved CI/CD workflows, scan analysis, remediation recommendations, and patch verification.
- Support Infrastructure as Code and Configuration as Code processes by evaluating security findings and proposed changes before authorized deployment to production.
- Assist with enterprise scanning engine deployment for Initial Operational Capability (IOC), due 180 calendar days after the transition-in period, and support continued scanning during NOC/SOC sustainment.
- Provide vulnerability data, scan records, and technical evidence supporting Risk Management Framework assessments and Authorization to Operate or continuous ATO activities.
- Maintain scanning procedures and troubleshooting documentation.
- Coordinate with NOC, SOC, and incident response personnel when findings indicate potential compromise or urgent security exposure.
Apply for this position
Required*