USAF - ACAS Engineer

cFocus Software Incorporated•Linthicum Heights, MD
•Onsite

About The Position

cFocus Software is seeking an ACAS Engineer to join our program supporting the United States Air Force (USAF). This position is on-site in Linthicum Heights, MD and requires an Active TS/SCI clearance. The role involves configuring, operating, and maintaining assigned ACAS and Government-approved enterprise vulnerability scanning capabilities, performing weekly vulnerability scans, analyzing scan results, and coordinating remediation efforts.

Requirements

  • Active TS/SCI clearance
  • B.S. Computer Science, Information Technology, or a related field
  • Experience administering ACAS or comparable enterprise vulnerability assessment tools, including scan configuration, scheduling, credentialed scanning, and reporting.
  • Ability to diagnose scan failures and authentication issues, assess coverage, validate findings, and verify remediation through follow-up scanning.
  • Working knowledge of enterprise networks, server operating systems, applications, virtual infrastructure, and cloud or hybrid environments.
  • Experience interpreting vulnerability findings and coordinating patching, secure configuration changes, and STIG remediation with technical teams.
  • Ability to prepare accurate vulnerability reports, maintain assessment records, and provide technical evidence for cybersecurity compliance and authorization activities.
  • Clear communication skills for explaining findings, coordinating remediation, and working with system owners and operations personnel.

Responsibilities

  • Configure, operate, and maintain assigned ACAS and Government-approved enterprise vulnerability scanning capabilities, following approved designs, security baselines, and change procedures.
  • Perform weekly vulnerability scans of DC3 networks and applications.
  • Coordinate credentialed scanning across scoped IT and operational technology assets, including approved scan windows and access arrangements.
  • Maintain scan scope and asset coverage records; identify missed assets, failed scans, and authentication problems, and coordinate corrective action to improve coverage.
  • Analyze scan results, validate findings, investigate suspected false positives, and prioritize vulnerabilities for remediation in coordination with system owners and cybersecurity personnel.
  • Prepare and submit the Vulnerability Report using the CORA scoring model to the Government no later than 5 p.m. Eastern Time every Friday.
  • Check report accuracy, completeness, and technical quality before submission.
  • Track identified vulnerabilities through remediation and verification.
  • Recommend corrective actions, coordinate patching and secure configuration changes, and perform follow-up scans to validate closure.
  • Support continuous vulnerability monitoring and secure configuration management.
  • Provide findings and technical evidence for compliance reviews and security posture reporting.
  • Coordinate with systems administrators and engineers to support timely remediation of critical infrastructure vulnerabilities and implementation of Government-directed security requirements.
  • Support the automated Vulnerability Management Program through approved CI/CD workflows, scan analysis, remediation recommendations, and patch verification.
  • Support Infrastructure as Code and Configuration as Code processes by evaluating security findings and proposed changes before authorized deployment to production.
  • Assist with enterprise scanning engine deployment for Initial Operational Capability (IOC), due 180 calendar days after the transition-in period, and support continued scanning during NOC/SOC sustainment.
  • Provide vulnerability data, scan records, and technical evidence supporting Risk Management Framework assessments and Authorization to Operate or continuous ATO activities.
  • Maintain scanning procedures and troubleshooting documentation.
  • Coordinate with NOC, SOC, and incident response personnel when findings indicate potential compromise or urgent security exposure.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service