CybersecurityJobs.io
← Back to all jobs

Job Description

Apavo Corporation is seeking an ACAS Cybersecurity Analyst to join the team onsite in Oakton, VA. This role supports DoD/IC RMF vulnerability management, continuous monitoring, and compliance across multiple enclaves, handling ACAS administration, vulnerability scanning, risk remediation, and upstream reporting. The position emphasizes hands-on administration of security scanning tools within sensitive environments and close collaboration with operations and engineering to maintain a robust cyber posture.

Responsibilities

  • Advanced ACAS administration: Deploy, configure, and manage Tenable Security Center (Tenable.sc) and Nessus scanners across connected and air-gapped enclaves (NIPR, SIPR, JWICS, SAP).
  • Vulnerability, R&D & directive scanning: Conduct credentialed and non-credentialed scans, tailor scan zones, profiles, and asset lists to ensure complete visibility while avoiding disruption to delicate research systems. Perform targeted scans to verify system compliance with DCDC CTOs.
  • Troubleshooting & maintenance: Diagnose and resolve complex scanner connectivity issues, credentialed scan failures (WMI/SSH), and perform manual/offline plugin and feed synchronization for isolated, highly classified networks.
  • Multi-framework compliance validation: Validate findings against DISA STIGs, CIS benchmarks, and IC/SAP baselines. Use tools such as SCC, STIG Viewer, and Evaluate-STIG for compliance checks.
  • Risk & remediation tracking: Develop and maintain POA&M documentation; monitor IAVA/IAVM notices and IC-specific vulnerability alerts. Work with operations and engineering to craft risk-based remediation strategies and track mitigations in systems of record (eMASS, Xacta).
  • Continuous monitoring & upstream reporting: Execute continuous monitoring (ConMon) activities, integrating ACAS outputs with local SIEM (e.g., Splunk) to sustain ongoing authorization and coordinate with the external CSSP. Support upstream enterprise cybersecurity posture reporting with data synchronized to the CMRS system.
  • DoD & IC RMF support: Support RMF lifecycle activities across DoD RMF (DoDI 8510.01), ICD 503, and JSIG. Maintain artifacts and map scan findings to NIST SP 800-53 and CNSSI 1253 controls.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Technology, or a related field (or equivalent experience).
  • 5–7+ years of DoD/IC cybersecurity experience with a strong focus on vulnerability management and RMF.
  • Active Top Secret clearance with SCI eligibility.
  • Willingness to undergo Counterintelligence (CI) or Full-Scope Polygraph for SAP readiness is highly preferred.
  • DoD 8570.01-M / 8140.03 compliant for IAT Level II (e.g., Security+ CE, CySA+) or Level III (e.g., CASP+, CISSP).
  • Current DISA ACAS Operator and/or Administrator training certificate.
  • Extensive, hands-on ACAS experience (Nessus / Tenable.sc), including offline updates, CMRS integration, air-gapped deployments, and credentialed scan troubleshooting.
  • CE certification (Linux+, Windows Server) or equivalent command-line experience is highly preferred for ACAS host management.
  • Deep knowledge of DoD RMF (DoDI 8510.01), IC RMF (ICD 503), JSIG, CNSSI 1253, NIST SP 800-53, STIG implementation, and IAVA/IAVM/CTO remediation processes.
  • Experience with SCC, STIG Viewer, eMASS, Xacta (common in IC/SAP environments), and log aggregation tools (e.g., Splunk).
  • Strong analytical and problem-solving abilities with the capacity to convey cyber risk to non-technical stakeholders.

Technologies

  • Tenable.sc, Nessus, ACAS, WMI, SSH
  • SCC, STIG Viewer, Evaluate-STIG
  • Splunk, eMASS, Xacta, CMRS
  • DISA STIGs, CIS benchmarks, NIST SP 800-53, CNSSI 1253
  • DoD RMF (DoDI 8510.01), ICD 503, JSIG

Other

  • This role is typical office or administrative work with no exposure to adverse environmental conditions and involves sedentary work.
  • Apavo Corporation provides equal employment opportunities and prohibits harassment or discrimination based on protected characteristics. Reasonable accommodations under the ADA are available upon request through HR, and employment is at-will.

Similar Jobs