SonicJobs Logo
Left arrow iconBack to search

Information Assurance Specialist

SUMARIA SYSTEMS LLC
Posted a day ago, valid for 20 days
Location

Montgomery, AL, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Sonic Summary

info
  • The Information Assurance Specialist II position focuses on vulnerability assessment and ACAS security management for the Air Force enterprise networks.
  • Candidates must have a minimum of three years of experience in cybersecurity, Information Assurance, or a related technical discipline.
  • The role requires hands-on experience with technologies such as ACAS, Nessus, and Forescout, along with a current Security+ certification and an active Secret Security Clearance.
  • Responsibilities include conducting security assessments, analyzing vulnerability scan results, and developing compliance documentation to enhance network security.
  • This full-time position is located at Maxwell AFB / Gunter Annex in Montgomery, AL, with a competitive salary based on experience.

Job Title: Information Assurance Specialist II – Vulnerability Assessment / ACAS Security Manager

Cybersecurity is critical to protecting the Air Force enterprise networks that enable mission operations around the world. This position supports the Air Force Intranet Control (AFINC) III program by providing vulnerability assessment, Information Assurance, and Assured Compliance Assessment Solution (ACAS) support for Air Force network environments.

Working alongside Government personnel and enterprise network teams, you will help identify, assess, prioritize, and remediate cybersecurity vulnerabilities while ensuring systems remain aligned with Department of Defense and Air Force security requirements. This role requires hands-on experience with enterprise vulnerability management technologies, including ACAS/Nessus and Forescout, and provides direct support to the security and resilience of Air Force networks.

In this role, you will perform vulnerability assessment, continuous monitoring, security analysis, and Information Assurance activities across complex network environments. Responsibilities include, but are not limited to:

  • Perform security assessments of systems and networks to identify deviations from approved configurations, Department of Defense requirements, Security Technical Implementation Guides (STIGs), and local security policies.
  • Conduct, review, and validate vulnerability scans using Assured Compliance Assessment Solution (ACAS) and Nessus.
  • Analyze vulnerability scan results, identify false positives and approved exceptions, prioritize findings based on risk, and coordinate corrective actions.
  • Develop and maintain Plans of Action and Milestones (POA&Ms), Memorandums for Record (MFRs), and associated vulnerability management documentation.
  • Monitor remediation activities and provide vulnerability and POA&M status for monthly, quarterly, and other Government reporting requirements.
  • Evaluate the effectiveness of defense-in-depth security architectures against known vulnerabilities using approved cybersecurity assessment tools.
  • Analyze, prioritize, and recommend mitigation strategies that reduce or eliminate cybersecurity risk.
  • Develop reports and technical documentation that clearly communicate cybersecurity findings, risks, and recommended solutions to Government stakeholders.
  • Utilize Forescout to support visibility, control, and management of devices connecting to the enterprise network.
  • Inventory and track network-connected hardware to help ensure only authorized and appropriately managed devices receive network access.
  • Identify unauthorized or unmanaged devices and coordinate actions to prevent or restrict network access.
  • Monitor and manage authorized software across network environments to identify and prevent unauthorized or unmanaged software installation and execution.
  • Submit and track tickets with appropriate technical teams to facilitate vulnerability remediation and corrective actions.
  • Collect and analyze cybersecurity information from intrusion detection systems, firewalls, network traffic logs, host logs, and other security tools to identify potentially malicious activity.
  • Validate, investigate, and analyze cybersecurity events and support response activities associated with suspected or confirmed incidents.
  • Assist with cybersecurity incident documentation, tracking, coordination, recovery activities, and analysis of supporting evidence and artifacts.
  • Collaborate with system administrators, network engineers, cybersecurity personnel, and Government stakeholders to improve the overall security posture of the AFINC enterprise.

Required Skills/Education

Education: High School Diploma or GED required.

Years of Experience: Three (3) or more years of experience supporting cybersecurity, Information Assurance, vulnerability management, network security, or a related technical discipline.

Required Qualifications:

  • United States Citizenship.
  • Active Secret Security Clearance.
  • Current Security+ certification.
  • Current Forescout certification.
  • Hands-on experience with vulnerability assessment and cybersecurity tools including ACAS and Nessus.
  • Experience implementing or assessing DISA Security Technical Implementation Guides (STIGs).
  • Experience with Forescout and enterprise device visibility or network access control technologies.
  • Familiarity with cybersecurity audit and assessment tools.
  • Experience analyzing vulnerability scan results and coordinating remediation activities.
  • Experience developing or maintaining POA&Ms and other cybersecurity compliance documentation.
  • Understanding of network security concepts, defense-in-depth architectures, and vulnerability management processes.
  • Strong analytical and technical problem-solving skills.
  • Excellent written and verbal communication skills with the ability to communicate technical cybersecurity issues across multiple levels of an organization.

Preferred Qualifications:

  • Experience supporting ACAS within a Department of Defense enterprise environment.
  • Experience administering or supporting Tenable SecurityCenter/Tenable.sc and Nessus infrastructure.
  • Experience with Enterprise Security System (ESS) capabilities.
  • Experience supporting Forescout within large enterprise network environments.
  • Familiarity with DoD cybersecurity policies, Risk Management Framework (RMF), and continuous monitoring requirements.
  • Experience analyzing intrusion detection alerts, firewall logs, network traffic, and host-based security data.
  • Previous experience supporting Air Force enterprise network operations or cybersecurity missions.

Travel: Limited travel may be required in support of program objectives.

Security Clearance Required: Active Secret Security Clearance.

Position Type: Full Time

Work Location: Maxwell AFB / Gunter Annex, Montgomery, AL (Onsite)

Why Join Sumaria Systems

  • Supporting critical Air Force enterprise network and cybersecurity missions
  • Directly contributing to the security and resilience of Air Force network operations
  • Hands-on work with enterprise cybersecurity, vulnerability management, and network security technologies
  • Over 40 years supporting the Department of Defense
  • Expertise across:
    • Cybersecurity
    • Enterprise Network Operations
    • C5ISR
    • Digital Engineering
    • Mission Support

Additional Information

  • No agency submissions accepted
  • Learn more: www.sumaria.com
  • Equal Opportunity Employer



Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.