> Markdown version of [/jobs/ext/2177730-cybersecurity-and-vulnerability-management-systems-administrator](https://www.wearedevelopers.com/jobs/ext/2177730-cybersecurity-and-vulnerability-management-systems-administrator). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity and Vulnerability Management Systems Administrator - **Company:** NexGen Data Systems Inc - **Location:** Columbus, OH, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Azure, Cloud Computing, Cyber Security, System Configuration, Data Systems, Internet Information Services (IIS), Windows Servers, NIPRNet, Security Content Automation Protocol, Software Systems, SQL Databases, Software Vulnerability Management, Data Processing, Enterprise Software Applications, SC Clearance, Servicenow, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 22, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9097514/cybersecurity-and-vulnerability-management-systems-administrator ## About the Role * Clearance Required: Active Department of Defense Secret clearance required. * Investigation / Position Sensitivity: Critical Sensitive / IT-I position requiring a favorable Tier 5 investigation because the duties require privileged systems and security-tool access. * Required Cyber Baseline Certification: Active IAT Level II or higher certification. * Required Computing Environment Certification: Microsoft Certified Solutions Expert Windows Server 2016, Microsoft Certified Azure Solutions Architect Expert, or current DLA-approved equivalent. * Required DoD 8140 Qualification: Must maintain applicable foundational and computing-environment qualifications. * Required Education: BA/BS in a technical discipline with at least 10 years of specialized experience. (Specialized experience is defined as progressive experience in the field of Information Processing, where the majority are specialized in numerous specialized Information Processing disciplines involving a range of hardware/software solutions, at least four years of which are concentrated, hand-on experience in installing, configuring, maintaining, and resolving issues with various software. * Required Experience: Minimum seven years of progressive information processing or systems administration experience. * Specialized Experience: At least six years supporting multiple hardware, software, application, security, or infrastructure disciplines. * Hands-On Experience: At least four years installing, configuring, maintaining, securing, and resolving issues with enterprise software or systems. * Required Vulnerability Experience: ACAS, STIG, SCAP, IAVM, patching, secure configuration, vulnerability validation, and remediation tracking. * Required RMF Experience: Experience maintaining RMF packages, BCSA artifacts, POA&Ms, AORAs, risk assessments, and authorization evidence. * Required Audit Experience: Experience supporting CVA, CCRI, cybersecurity audits, inspections, or control validation exercises. * Desired Skills: ACAS/Tenable, STIG Viewer, SCC, SCAP, Windows Server, IIS, SQL, ServiceNow, eMASS or equivalent RMF repository, and cybersecurity reporting. ## Description NexGen Data Systems is seeking a Cybersecurity and Vulnerability Management Systems Administrator to secure DLA enterprise applications and servers, remediate vulnerabilities, maintain Risk Management Framework documentation, and support audit readiness across NIPRNet, SIPRNet, physical, virtual, and cloud-based environments. The position will perform IAVM compliance, STIG and SCAP validation, ACAS remediation, POA&M and AORA development, BCSA documentation, RMF artifact maintenance, and support for Cybersecurity Vulnerability Assessments and Command Cyber Readiness Inspections. Roles & Responsibilities: * Review and remediate application, operating system, server, and infrastructure vulnerabilities. * Support compliance with the DoD Information Assurance Vulnerability Management program. * Analyze ACAS findings and prioritize remediation based on severity, exploitability, mission impact, and required completion dates. * Apply and validate DISA Security Technical Implementation Guides and Security Content Automation Protocol outputs. * Coordinate patching, secure configuration changes, application updates, and maintenance outages with system owners and technical teams. * Develop vulnerability remediation plans and track corrective actions through closure. * Identify findings requiring a Plan of Action and Milestones or Authorization Official Risk Assessment. * Draft and maintain POA&Ms, AORAs, risk assessments, mitigation statements, milestone dates, and closure evidence. * Develop and maintain RMF artifacts, standard operating procedures, STIG checklist outputs, scan results, and security documentation. * Update Government cybersecurity repositories with current and accurate artifacts. * Support Baseline Cyber Security Assessment approval and ongoing maintenance. * Serve as a technical subject matter resource to DLA cybersecurity personnel and management. * Support Cybersecurity Vulnerability Assessments, Command Cyber Readiness Inspections, audit readiness reviews, evidence requests, and remediation activities. * Ensure no critical vulnerability remains unmitigated without documented Government-approved risk treatment. * Transfer security playbooks, STIG and ACAS history, BCSA records, POA&Ms, AORAs, and audit artifacts during transition-out. Other Duties: Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [From Messy Queries to Scalable Systems - How Data Engineering actually works](https://www.wearedevelopers.com/videos/100203-from-messy-queries-to-scalable-systems-how-data-engineering-actually-works) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [The Data Mesh as the end of the Datalake as we know it](https://www.wearedevelopers.com/videos/156-the-data-mesh-as-the-end-of-the-datalake-as-we-know-it) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)