Hiring.Camp

USAF - ACAS Engineer

cFocus Software Incorporated

·

Today

Location
Linthicum Heights, MD
Workplace
Remote, Hybrid, Onsite
Type
Full-time
Department
Engineering
Education
Master
Clearance
Required
Closing date
Today
Source
ApplyToJob

Description

cFocus Software seeks a ACAS Engineer to join our program supporting the United States Air Force (USAF). This position is on-site in Linthicum Heights, MD. This position requires an Active TS/SCI clearance.
Qualifications:
  • Active TS/SCI clearance
  • B.S. Computer Science, Information Technology, or a related field
  • Experience administering ACAS or comparable enterprise vulnerability assessment tools, including scan configuration, scheduling, credentialed scanning, and reporting.
  • Ability to diagnose scan failures and authentication issues, assess coverage, validate findings, and verify remediation through follow-up scanning.
  • Working knowledge of enterprise networks, server operating systems, applications, virtual infrastructure, and cloud or hybrid environments.
  • Experience interpreting vulnerability findings and coordinating patching, secure configuration changes, and STIG remediation with technical teams.
  • Ability to prepare accurate vulnerability reports, maintain assessment records, and provide technical evidence for cybersecurity compliance and authorization activities.
  • Clear communication skills for explaining findings, coordinating remediation, and working with system owners and operations personnel.
Duties:
  • Configure, operate, and maintain assigned ACAS and Government-approved enterprise vulnerability scanning capabilities, following approved designs, security baselines, and change procedures.
  • Perform weekly vulnerability scans of DC3 networks and applications. Coordinate credentialed scanning across scoped IT and operational technology assets, including approved scan windows and access arrangements.
  • Maintain scan scope and asset coverage records; identify missed assets, failed scans, and authentication problems, and coordinate corrective action to improve coverage.
  • Analyze scan results, validate findings, investigate suspected false positives, and prioritize vulnerabilities for remediation in coordination with system owners and cybersecurity personnel.
  • Prepare and submit the Vulnerability Report using the CORA scoring model to the Government no later than 5 p.m. Eastern Time every Friday. Check report accuracy, completeness, and technical quality before submission.
  • Track identified vulnerabilities through remediation and verification. Recommend corrective actions, coordinate patching and secure configuration changes, and perform follow-up scans to validate closure.
  • Support continuous vulnerability monitoring and secure configuration management. Provide findings and technical evidence for compliance reviews and security posture reporting.
  • Coordinate with systems administrators and engineers to support timely remediation of critical infrastructure vulnerabilities and implementation of Government-directed security requirements.
  • Support the automated Vulnerability Management Program through approved CI/CD workflows, scan analysis, remediation recommendations, and patch verification.
  • Support Infrastructure as Code and Configuration as Code processes by evaluating security findings and proposed changes before authorized deployment to production.
  • Assist with enterprise scanning engine deployment for Initial Operational Capability (IOC), due 180 calendar days after the transition-in period, and support continued scanning during NOC/SOC sustainment.
  • Provide vulnerability data, scan records, and technical evidence supporting Risk Management Framework assessments and Authorization to Operate or continuous ATO activities.
  • Maintain scanning procedures and troubleshooting documentation.
  • Coordinate with NOC, SOC, and incident response personnel when findings indicate potential compromise or urgent security exposure.

Skills

CI/CDCybersecuritySOCRisk ManagementCompliance