ASRC

Vulnerability Assessor

ASRC$90K — $120K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, or related field (or equivalent experience).
  • 5+ years of experience in cybersecurity or vulnerability management.
  • Active DoD Secret clearance required.
  • DoD 8570.01-M IAT Level II certification (such as Security+ CE, CySA+, or CCNA-Security).
  • Hands-on experience with ACAS (Tenable/Nessus) and STIG compliance tools.
  • Strong analytical, documentation, and communication skills.

Responsibilities

  • Conduct vulnerability scans using ACAS and other DoD-approved tools.
  • Analyze and categorize vulnerabilities per NIST SP 800-53 and DoDI 8510.01 guidelines.
  • Collaborate with cybersecurity personnel to track remediation efforts.
  • Prepare and maintain vulnerability reports for leadership review.
  • Support RMF Steps 3-6 and maintain documentation in eMASS.
  • Research emerging technologies to identify evolving risks.

Benefits

  • Competitive health care plans including dental and vision.
  • 401(k) retirement plan options.
  • Education assistance programs available.
  • Paid time off including holidays and required paid leave.
  • Life insurance coverage.
Full Job Description
Vulnerability Assessor

Location: Alexandria, VA (Hybrid - Telework with periodic on-site support as required)
Clearance: Active Secret

Position Overview

ASRC Federal is seeking a Vulnerability Assessor to support the Department of War Education Activity (DoWEA) Enterprise Cyber Program. The Vulnerability Assessor will identify, analyze, and track system vulnerabilities to strengthen the organization's cybersecurity posture and ensure compliance with DoD Risk Management Framework (RMF) requirements. This role supports Continuous Monitoring (ConMon) activities and works closely with cybersecurity and system teams to enhance DoWEA's enterprise-wide security operations.

Responsibilities
  • Conduct vulnerability scans using ACAS (Tenable/Nessus), STIG Viewer, and related DoD-approved assessment tools.
  • Categorize and analyze vulnerabilities in accordance with NIST SP 800-53, DISA STIGs, and DoDI 8510.01 (RMF).
  • Collaborate with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), and system administrators to track remediation and update Plans of Action and Milestones (POA&Ms).
  • Prepare and maintain vulnerability assessment reports and risk summaries for leadership.
  • Support RMF Steps 3-6 and Continuous Monitoring documentation within eMASS.
  • Research and evaluate emerging technologies to identify new or evolving risks and recommend mitigation strategies.

Basic Qualifications
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or related discipline (four additional years of equivalent experience may substitute).
  • Minimum 5+ years of cybersecurity or vulnerability management experience.
  • Active DoD Secret clearance
  • DoD 8570.01-M IAT Level II certification (e.g., Security+ CE, CySA+, CCNA-Security).
  • Hands-on experience with ACAS (Tenable/Nessus) and STIG compliance tools.
  • Strong analytical, documentation, and communication skills.
  • Working knowledge of vulnerability scanning, risk assessment methodologies, and remediation tracking.

Preferred Qualifications
  • Familiarity with DoW (DoD) RMF, eMASS, and DISA STIG/SRG compliance.
  • Understanding of NIST SP 800-53, CNSSI 1253, and DoDI 8510.01 frameworks.
  • Knowledge of common cybersecurity threats, exploits, and attack vectors.
  • Experience supporting federal or DoD IT environments.
  • Positive, proactive approach and ability to collaborate effectively across remote and on-site teams.

We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. The salary offered will depend on several factors including, but not limited to, relevant experience, skills, education, geographic location, internal equity, business needs, and other factors permitted by law. Posted pay ranges are a general guideline only and are not a guarantee of compensation or salary.

About ASRC

Arctic Slope Regional Corporation (ASRC) is an Alaska Native corporation that was established in 1972 under the Alaska Native Claims Settlement Act (ANCSA). The company is owned by approximately 13,000 Iñupiat shareholders who live primarily in eight villages on Alaska's North Slope. ASRC is a diversified company with subsidiaries involved in oil and gas exploration and production, government services, construction, and resource development. The company has a strong commitment to sustainability and environmental stewardship, and has implemented a number of initiatives to reduce its environmental impact.
Learn more about ASRC
Size
3,500 employees
Industry
Founded
2003

Similar Jobs

More Jobs at ASRC

More Information Technology Jobs

Find similar Vulnerability Assessor jobs: