ASRC Federal Holding Company • Alexandria, VA 22303
Job #2818345200
Cyber Security Engineer - ACAS Governance & Compliance Lead
Alexandria, VA, USA Req #665
Tuesday, January 7, 2025
ASRC Federal NetCentric Technology is seeking a Cyber Security Engineer - ACAS Governance & Compliance Lead to support one of our federal government contracts based out of Seaside, California and Alexandria, Virginia. The successful candidate will be responsible for leading mentoring a team of Governance and Compliance professionals to ensure proper maintenance of the Assured Compliance Assessment Solution (ACAS) suite of applications and vulnerability management in support of RMF activities. This position will require travel to Seaside, California and Alexandria, Virginia.
Responsibilities:
ACAS Management : Act as the primary point of contact for the design, development, and implementation strategy for the Assured Compliance Assessment Solution (ACAS) in support of meeting security objectives for cloud infrastructure and enterprise networks environments.
Team Leadership : Provide cross-functional collaboration amongst cybersecurity service support teams for routine and event-oriented activities in the following areas.
Vulnerability Management : Lead configuration and optimization of ACAS policies, writing scripts (Bash, Python), and performing root cause analysis to resolve issues.
Manage vulnerability policies, custom alerts, scan policies, and ticketing workflows.
Cross-reference weekly IAVM (Information Assurance Vulnerability Management) compliance reports with ACAS scan results to identify and remediate vulnerabilities.
Support cybersecurity reviews and audits to ensure systems meet DoD 8140 and 8570 compliance standards.
Governance and Compliance: Lead and support ISSO activity task to ensure proper documentation for Authority to Operate (ATO) and Continuous Monitoring are maintained and updated.
Detection and Response: Lead cross-functional activities to assess operational impact of enterprise systems as identified in U.S. Cyber Command (USCC) and Joint Force Headquarters (JFHQ) directives.
Reporting and Documentation : Lead and manage teams in the generation and maintenance of cybersecurity RMF artifacts such as System Security Plans, POA&M (Plans of Action & Milestones), and security CONOPS (Concept of Operations).
Continuous Process Improvement: Regularly review and update vulnerability management processes and procedures (SOP) based on lessons learned from routine and event-oriented incidents in accordance with DoD regulations, directives, and industry best practices.
Required Qualifications:
Active Secret Clearance and Bachelor's degree in Information Technology, Cybersecurity, or a related field.
Active DoD 8570 IAT Level II certification or greater , including at least one of the following certifications in good standing: CCNA Security, CySA+, GICSP, GSEC, Security+ CE, CND, SSCP, CASP+CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, or CCSP.
6+ years of relevant IT or Cybersecurity experience, including 4+ years of hands-on expertise managing the Assured Compliance Assessment Solution (ACAS) suite throughout its lifecycle-from initial deployment, configuration, and integration into enterprise networks to continuous monitoring, maintenance, and optimization. This includes proficiency in configuring scan policies, customizing dashboards, managing Tenable Nessus scans, Security Center reporting, and ensuring seamless updates to maintain compliance and efficiency.
DISA ACAS certified.
Strong knowledge of Linux and Windows operating systems, with proficiency in scripting languages like Bash and Python for automation, troubleshooting, and ACAS tool customization to meet organizational needs.
Experience in vulnerability management , including interpreting and remediating ACAS scan results, managing IAVM compliance reporting, analyzing system vulnerabilities, and ensuring full lifecycle security solutions using ACAS to maintain enterprise network integrity.
Proven ability to generate security artifacts (e.g., POA&M, CONOPS, security plans), implement end-to-end ACAS solutions, and collaborate effectively in team environments to address evolving cybersecurity threats and challenges.
Travel to Seaside, California and Alexandria, Virginia.
Preferred Skills:
Deep understanding of Information Technology (IT) systems configuration within the Department of Defense (DoD) and extensive hands-on experience with ACAS tools to ensure the security and compliance of cloud infrastructure and enterprise environments.
Familiarity with tools such as ESS, Microsoft Defender, Splunk, Tanium and Burp Suite capabilities and how these tools complement one another in support cybersecurity support services.
Advantages of Working at ASRC Federal:
Learning and Development: After 90 days of employment, regular full-time employees are eligible for our professional development program. This includes annual funding for:
Pursuing Associate's, Bachelor's, or Graduate Degrees.
Obtaining industry-standard professional certifications.
Participating in professional certificate programs.
Covering registration fees for professional conferences.
Employee Resource Groups (ERGs): Engage with colleagues through our ERGs, which foster networking and collaboration among individuals with shared interests, backgrounds, and experiences. Our ERGs include:
Women's Impact Network (WIN).
Multicultural ERG.
Military Community (MILCOM).
Pride ERG for LGBTQ+ employees and allies.
Purpose-Driven Careers: Join a company recognized as a:
Certified Great Place to Work .
Military Times' Best for Vets Employer.
~~~'s Top 25 Veteran Employer .
Comprehensive Benefits:
Insurance Coverage : Comprehensive plans for medical, dental, vision, life insurance, and short-term/long-term disability.
Paid Leave : Inclusive policies for bereavement, military obligations, and parental needs, along with 11 paid holidays annually.
Retirement Savings : A 401(k) plan with a generous company match and immediate vesting to help secure your financial future.
Incentives : Employee referral bonuses to reward you for helping grow the ASRC Federal Family
Embark on a career with ASRC Federal, where your growth, purpose, and well-being are at the forefront of what we do.
We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law.
EEO Statement
ASRC Federal and its Subsidiaries are Equal Opportunity /Affirmative Action employers. All qualified applicants will receive consideration for employment without regard to race, gender, color, age, sexual orientation, gender identification, national origin, religion, marital status, ancestry, citizenship, disability, protected veteran status, or any other factor prohibited by applicable law.
Other details
Job FamilyInformation Technology
Job Sub-FamilyInformation Security
Pay TypeSalary
Required EducationBachelor's Degree
Alexandria, VA, USA
<
ASRC Federal Holding Company • Washington, DC 20080 • Yesterday
ASRC Federal Holding Company • Washington, DC 20022 • 3 Days Ago
ASRC Federal Holding Company • Alexandria, VA 22303 • Yesterday
The MITRE Corporation • Mc Lean, VA 22107 • 3 Days Ago
AHU Technologies Inc • Washington, DC 20022 • 4 Days Ago
TekStream Solutions • Arlington, VA 22201 • Today
Apex Systems • Alexandria, VA 22350 • Today