ECS

ACAS Vulnerability Assessment Lead SME

ECS$120K — $150K *
Aerospace & Defense
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Current Secret security clearance with ability to obtain Top Secret (TS) and Sensitive Compartmented Information (SCI) clearance.
  • IAM I certification (e.g., CompTIA Security+ CE, ISC² CAP, ISC² SSCP, GIAC GSLC).
  • 12+ years of experience in enterprise vulnerability assessment and compliance scanning.
  • Proficient in ACAS, Tenable Security Center, and Nessus.
  • Strong problem-solving and decision-making skills.
  • Excellent interpersonal and communication abilities.

Responsibilities

  • Direct enterprise vulnerability assessment operations for DoW mission systems.
  • Operate and sustain Tenable Security Center and Nessus for continuous monitoring.
  • Design and configure credentialed vulnerability and compliance scans across various environments.
  • Develop and maintain custom scan policies and compliance profiles.
  • Analyze vulnerability findings and validate results with risk categorization.
  • Coordinate remediation activities with cybersecurity and IT teams.
  • Produce vulnerability assessment reports and compliance dashboards.

Benefits

  • Supports audit readiness and continuous monitoring reviews.
  • Ensures accurate documentation and defensible reporting for stakeholders.
  • Contributes to measurable improvements in cybersecurity visibility and resilience.
Full Job Description
• This role directs enterprise vulnerability assessment operations using the Assured Compliance Assessment Solution (ACAS), Tenable Security Center, and Nessus scanning infrastructure to protect DoW mission systems across both unclassified and classified networks.
• Directs enterprise vulnerability assessment operations using ACAS to support DoW mission systems across unclassified and classified networks.
• Operates and sustains Tenable Security Center and Nessus scanning infrastructure to deliver continuous monitoring aligned with Risk Management Framework objectives and DoW guidance.
• Designs and configures credentialed vulnerability and compliance scans across virtualized, cloud, and on premise environments including VMware, Windows Server, Red Hat Enterprise Linux, container platforms, and network appliances.
• Develops and maintains custom scan policies, STIG and SRG compliance profiles, authenticated scanning credentials, and asset tagging structures aligned to mission criticality and operational risk.
• Analyzes vulnerability findings, validates results, performs risk categorization, and correlates findings with IAVA notifications, patch cycles, and configuration baselines.
• Coordinates remediation activities with system administrators, network engineers, and cybersecurity teams using ServiceNow, Jira, and SharePoint to track corrective actions and evidence closure.
• Produces authoritative vulnerability assessment reports, compliance dashboards, and executive summaries supporting Authorizing Officials, Senior Information Security Officers, and Combatant Command stakeholders.
• Maintains scanning infrastructure availability through lifecycle management, scanner updates, plugin maintenance, and performance tuning.
• Supports audit readiness, continuous monitoring reviews, and authorization decisions through traceable documentation and defensible reporting.
• Delivers measurable improvements in security visibility, vulnerability remediation velocity, and cyber resilience while advancing program values of mission assurance, operational readiness, accountability, and information advantage.
• Performs other duties as assigned.
• Current Secret security clearance with the ability to obtain and maintain a Top Secret (TS) security clearance with Sensitive Compartmented Information (SCI).
• IAM I - CompTIA Security+ CE, ISC² CAP, ISC² SSCP, or GIAC GSLC.
• 12 + years of experience in enterprise vulnerability assessment and compliance scanning using ACAS, Tenable, and Nessus across multi-domain environments.
• Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
• Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).

About ECS

ECS is a leading provider of digital solutions and services to the federal government. The company was founded in 2001 by Roy Kapani and has since grown to become a trusted partner to a wide range of government agencies. ECS offers a broad range of services, including cloud computing, cybersecurity, and artificial intelligence. The company has been recognized for its innovative solutions and has won numerous awards, including the AWS Public Sector Partner of the Year award.
Learn more about ECS
Size
2,000 employees
Industry

Similar Jobs

More Jobs at ECS

  • ECS
    Analytic Engineer
    $90K — $130K *
    Fairfax, VA 22031 (Fairfax County)
    Aerospace & Defense
    In-Person
  • ECS
    Analytic Engineer
    $90K — $130K *
    Falls Church, VA 22042 (Fairfax County)
    Aerospace & Defense
    In-Person
  • ECS
    Senior Governance Training Specialist
    $100K — $130K *
    Fairfax, VA 22031 (Fairfax County)
    Education, Government & Non-Profit
    In-Person
  • ECS
    Analytic Engineer
    $90K — $130K *
    Washington, DC 20310 (District Of Columbia County)
    Aerospace & Defense
    In-Person
  • ECS
    Senior Governance Training Specialist
    $100K — $130K *
    Falls Church, VA 22042 (Fairfax County)
    Education, Government & Non-Profit
    In-Person

More Aerospace & Defense Jobs

Find similar ACAS Vulnerability Assessment Lead SME jobs: