Information Assurance Specialist (Vulnerability Assessment/ACAS)

Abacus Technology
Montgomery, AL, United States
26 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Data Analysis Computer-Aided Audit Tools Cyber Security Computer Networks Issue Tracking Systems Intrusion Detection Systems Forescout Nessus Plan of Action and Milestones Vulnerability Analysis

Job description

Abacus Technology is seeking an Information Assurance Specialist to provide vulnerability assessment and ACAS support for the Air Force Intranet Control (AFINC) III Support program at Maxwell AFB/Gunter Annex. This is a full-time position.

  • Perform assessments of system and network and identifies where the system/network deviate from acceptable configurations, DoD policy, or local policy/guidelines.
  • Measure effectiveness of defense-in-depth architecture against known vulnerabilities using available tools within organization to find them.
  • Analyze, prioritize, and mitigate vulnerabilities to lower or eliminate risk.
  • Create reports to effectively communicate to government problems and proposed solutions.
  • Actively manage (inventory, track, and request corrective action) all hardware devices on network that only authorized devices are given access and ensure unauthorized and unmanaged devices are found and prevented from gaining access.
  • Manage (inventory, track, and correct) all software on the network so that only authorized software is installed and can execute, and ensure unauthorized and unmanaged software is found and prevented from installation or execution.
  • Submit tickets to appropriate teams for corrective actions.
  • Conduct/review/validate vulnerability scans.
  • Perform vulnerability scans to include analysis of results, identification of false positives, exceptions, and subsequent POA&Ms and/or MFRs creation, monitoring and reporting to include POA&M status and contributions to Monthly and Quarterly reports.
  • Collect and review data gathered from a variety of tools (including intrusion detection system alerts, firewall, network traffic logs, and host system logs) to analyze events for possible attacks that occur within the environment.
  • Validates, investigates, and analyzes all response activities related to cyber incidents.
  • Support creating and maintaining incident tracking information; planning, coordinating, and directing recovery activities; and incident tracking information; and incidents analysis tasks, including examining all available information and supporting evidence of artifacts related to an incident or event.
  • Perform assessments of systems and networks within the network environment or enclave and identify where those systems and/or networks deviate from acceptable configurations, enclave policy, or local policy.

Requirements

3+ years experience in a cyber security or information assurance role. HS diploma or GED. Must be Security+ certified. Must hold a Forescout certification. Experience utilizing security relevant tools to include: NESSUS, ACAS, DISA STIGs, Audit Tools, Forescout, and ESS. Outstanding communication skills across all levels of the organization. Must be a US citizen and hold a current Secret clearance.

Applicants selected will be subject to a U.S. government security investigation and must meet eligibility requirements for access to classified information.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:48 min

Automating exploratory data analysis within training pipelines

Dora Petrella · WWC 2023

1:29 min

Assisting security analysis using AI code review tools

Matteo Meucci Matteo Meucci · Europe 2026 Virtual

1:36 min

Performing exploratory data analysis to uncover underlying patterns

Julian Joseph · LIVE

5:51 min

Transitioning to continuous security operations and automated system hardening

Thomas Fuchs +3 · LIVE

1:44 min

Coordinating security mitigations with the CISA clearinghouse

Adrian Mouat Adrian Mouat · WWC Europe 2026

1:31 min

Overcoming technochauvinism and evaluating algorithmic training dataset integrity

Prathyusha Charagondla · LIVE

Videos

See all

Related articles

See all