Jobs and Careers
AS

Cyber Security Engineer - ACAS (Hybrid)

ASRC Federal
Alexandria, United Statesfull_timeVerifiedPosted 16 May 2025
💰 $145,000/yr($125,000/yr$145,000/yr)

About the role

ASRC Federal is a leading government contractor furthering missions in space, public health and defense. As an Alaska Native owned corporation, our work helps secure an enduring future for our shareholders. Join our team and discover why we are a top veteran employer and Certified Great Place to Work™


ASRC Federal NetCentric Technology is seeking a Cyber Security Engineer – ACAS (HYBRID) to support one of our federal government clients. The successful candidate MUST possess an active Secret Security Clearance and will be part of a Governance and Compliance team of professionals ensuring proper maintenance of the Assured Compliance Assessment Solution (ACAS) suite of applications and vulnerability management in support of RMF activities. The position is hybrid therefore requiring onsite presence 3-days a week at our customer location in Seaside, California or Alexandria, Virginia.

Responsibilities:
• ACAS Management: Will assist in the design, development, and implementation strategy for the Assured Compliance Assessment Solution (ACAS) in support of meeting security objectives for cloud infrastructure and enterprise networks environments.
• Vulnerability Management: Lead configuration and optimization of ACAS policies, writing scripts (Bash, Python), and performing root cause analysis to resolve issues.
◦ Develop vulnerability policies, custom alerts, scan policies, and ticketing workflows.
◦ Cross-reference weekly IAVM (Information Assurance Vulnerability Management) compliance reports with ACAS scan results to identify and remediate vulnerabilities.
◦ Support cybersecurity reviews and audits to ensure systems meet DoD 8140 and 8570 compliance standards.
• Governance and Compliance: Support ISSO/ISSM/SO activity task to ensure proper documentation for Authority to Operate (ATO) and Continuous Monitoring are maintained and updated.
• Detection and Response: Participate in cross-functional activities to assess operational impact of enterprise systems as identified in U.S. Cyber Command (USCC) and Joint Force Headquarters (JFHQ) directives.
• Reporting and Documentation: Assist in the generation and maintenance of cybersecurity RMF artifacts such as System Security Plans, POA&M (Plans of Action & Milestones), and security CONOPS (Concept of Operations).
• Continuous Process Improvement: Regularly review and update vulnerability management processes and procedures (SOP) based on lessons learned from routine and event-oriented incidents in accordance with DoD regulations, directives, and industry best practices.

Required Qualifications:
• Active Secret Clearance and Bachelor’s degree in Information Technology, Cybersecurity, or a related field.
• Active DoD 8570 IAT Level II certification or greater, including at least one of the following certifications in good standing: CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP, CASP+CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, or CCSP.
• 6+ years of relevant IT or Cybersecurity experience, including 4+ years of hands-on expertise managing the Assured Compliance Assessment Solution (ACAS) suite throughout its lifecycle—from initial deployment, configuration, and integration into enterprise networks to continuous monitoring, maintenance, and optimization. This includes proficiency in configuring scan policies, customizing dashboards, managing Tenable Nessus scans, Security Center reporting, and ensuring seamless updates to maintain compliance and efficiency.
• DISA ACAS certified.
• Strong knowledge of Linux and Windows operating systems, with proficiency in scripting languages like Bash and Python for automation, troubleshooting, and ACAS tool customization to meet organizational needs.
• Experience in vulnerability management, including interpreting and remediating ACAS scan results, managing IAVM compliance reporting, analyzing system vulnerabilities, and ensuring full lifecycle security solutions using ACAS to maintain enterprise network integrity.
• Proven ability to generate security artifacts (e.g., POA&M, CONOPS, security plans), implement end-to-end ACAS solutions, and collaborate effectively in team environments to address evolving cybersecurity threats and challenges.
• Deep understanding of Information Technology (IT) systems configuration within the Department of Defense (DoD) and extensive hands-on experience with ACAS tools to ensure the security and compliance of cloud infrastructure and enterprise environments.
• Familiarity with tools such as ESS, Microsoft Defender, Splunk, Tanium and Burp Suite capabilities and how these tools complement one another in support cybersecurity support services.

California Residents: This position is offering a pay range of $125,000.00 - $145,000.00 depending on experience, seniority, geographic location

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

ASRC Federal

View company profile →