openqareer

USAF - ACAS Engineer

cFocus Software Incorporated · Linthicum Heights, MD

# USAF - ACAS Engineer **cFocus Software Incorporated** · Linthicum Heights, MD · `On-site` 🕒 **Статус:** *Опубликовано: вчера* · *Источник: Indeed* --- ### About the Role cFocus Software seeks a ACAS Engineer to join our program supporting the United States Air Force (USAF). This position is on-site in Linthicum Heights, MD. This position requires an Active TS/SCI clearance. Qualifications: - Active TS/SCI clearance - B.S. Computer Science, Information Technology, or a related field - Experience administering ACAS or comparable enterprise vulnerability assessment tools, including scan configuration, scheduling, credentialed scanning, and reporting. - Ability to diagnose scan failures and authentication issues, assess coverage, validate findings, and verify remediation through follow-up scanning. - Working knowledge of enterprise networks, server operating systems, applications, virtual infrastructure, and cloud or hybrid environments. - Experience interpreting vulnerability findings and coordinating patching, secure configuration changes, and STIG remediation with technical teams. - Ability to prepare accurate vulnerability reports, maintain assessment records, and provide technical evidence for cybersecurity compliance and authorization activities. - Clear communication skills for explaining findings, coordinating remediation, and working with system owners and operations personnel. Duties: - Configure, operate, and maintain assigned ACAS and Government-approved enterprise vulnerability scanning capabilities, following approved designs, security baselines, and change procedures. - Perform weekly vulnerability scans of DC3 networks and applications. Coordinate credentialed scanning across scoped IT and operational technology assets, including approved scan windows and access arrangements. - Maintain scan scope and asset coverage records; identify missed assets, failed scans, and authentication problems, and coordinate corrective action to improve coverage. - Analyze scan results, validate findings, investigate suspected false positives, and prioritize vulnerabilities for remediation in coordination with system owners and cybersecurity personnel. - Prepare and submit the Vulnerability Report using the CORA scoring model to the Government no later than 5 p.m. Eastern Time every Friday. Check report accuracy, completeness, and technical quality before submission. - Track identified vulnerabilities through remediation and verification. Recommend corrective actions, coordinate patching and secure configuration changes, and perform follow-up scans to validate closure. - Support continuous vulnerability monitoring and secure configuration management. Provide findings and technical evidence for compliance reviews and security posture reporting. - Coordinate with systems administrators and engineers to support timely remediation of critical infrastructure vulnerabilities and implementation of Government-directed security requirements. - Support the automated Vulnerability Management Program through approved CI/CD workflows, scan analysis, remediation recommendations, and patch verification. - Support Infrastructure as Code and Configuration as Code processes by evaluating security findings and proposed changes before authorized deployment to production. - Assist with enterprise scanning engine deployment for Initial Operational Capability (IOC), due 180 calendar days after the transition-in period, and support continued scanning during NOC/SOC sustainment. - Provide vulnerability data, scan records, and technical evidence supporting Risk Management Framework assessments and Authorization to Operate or continuous ATO activities. - Maintain scanning procedures and troubleshooting documentation. - Coordinate with NOC, SOC, and incident response personnel when findings indicate potential compromise or urgent security exposure. xKrzqqtsJf

Наблюдалась 2026-10-07, впервые 2026-10-05, источник — Indeed.

Открыть у работодателя