ACAS Cybersecurity Analyst
Listed on 2026-07-06
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Description
Job Title:
ACAS Cybersecurity Analyst
Location:
Oakton, VA
Department:
Cyber Security Services
Reports To:
Management
FLSA Status:
Full Time/Non-exempt
The ACAS Cybersecurity Analyst supports the Defense Advanced Research Projects Agency (DARPA) mission by executing advanced vulnerability management, compliance, and Continuous Monitoring (Con Mon) within complex, multi-enclave Risk Management Framework (RMF) environments. This role ensures that standard enterprise systems and unique Research & Development (R&D) systems remain secure and compliant under both Department of Defense (DoD) and Intelligence Community (IC) directives.
The analyst serves as the Assured Compliance Assessment Solution (ACAS) Subject Matter Expert (SME), ensuring complete network visibility, verifying directive compliance, and mitigating vulnerabilities across DoDI 8510.01, ICD 503, and JSIG governed environments.
ACAS Cybersecurity Analyst responsibilities include, but are not limited to:
- Advanced ACAS Administration:
Deploy, configure, and manage Tenable Security Center (Tenable.sc) and Nessus scanners across connected and air-gapped enclaves (NIPR, SIPR, JWICS, SAP). - Vulnerability, R&D & Directive Scanning:
Execute and analyze credentialed and non-credentialed vulnerability scans. Tailor scan zones, profiles, and asset lists to ensure 100% visibility while preventing disruptions to fragile, experimental DARPA research systems. Perform targeted scanning to determine and verify system compliance with DCDC Communications Tasking Orders (CTOs). - Troubleshooting & Maintenance:
Diagnose and resolve complex scanner connectivity issues, WMI/SSH credentialed scan failures, and perform manual/offline plugin and feed synchronizations for isolated, highly classified networks. - Multi-Framework Compliance Validation:
Validate findings against DISA STIGs, CIS benchmarks, and specific IC/SAP security baselines. Conduct compliance checks using tools such as SCC, STIG Viewer, and Evaluate-STIG. - Risk & Remediation Tracking:
Develop and maintain POA&M documentation. Monitor IAVA/IAVM notices and IC-specific vulnerability alerts. Collaborate with operations and engineering personnel to provide risk-based remediation strategies, tracking mitigation within systems of record (e.g., eMASS, Xacta). - Continuous Monitoring & Upstream Reporting:
Execute Con Mon activities, integrating ACAS outputs with local SIEM tools (e.g., Splunk) to maintain ongoing authorization and coordinate with the external Cybersecurity Service Provider (CSSP). Support upstream enterprise cybersecurity posture reporting, ensuring accurate data synchronization with the Continuous Monitoring and Risk Scoring (CMRS) system. - DoD & IC RMF Support:
Support RMF lifecycle activities across multiple regulatory frameworks—including DoD RMF (DoDI 8510.01), Intelligence Community Directive 503 (ICD 503), and the Joint SAP Implementation Guide (JSIG). Maintain artifacts and map technical scan findings to NIST SP 800-53 and CNSSI 1253 controls.
The ACAS Cybersecurity Analyst is expected to have additional duties as assigned in support of corporate cybersecurity services and DARPA mission requirements. Additional details are reviewed in accordance with company policies.
OtherThis is typical office or administrative work, and there is no exposure to adverse environmental conditions.
This position requires sedentary work. Sedentary work is defined as:
Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
- Education/
Experience:
Bachelor’s degree in Cybersecurity, Information Technology, or related field (or equivalent experience) with 5–7+ years of experience in DoD/IC cybersecurity, heavily focused on vulnerability management and RMF. - Clearance:
Active Top Secret clearance with SCI eligibility. (Willingness to undergo a Counterintelligence…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).