JCS Solutions logo
JCS SolutionsPosted 1 week ago
EXPIRED

ISSO – Vulnerability Management

$100,000–$114,000 year

On-siteAndrews AFB, Maryland, United States

Full TimeSmallCybersecurity

Job Summary

Manage the Plan of Action and Milestones (POA&M) process for cybersecurity vulnerabilities and DISA STIG findings by analyzing scan results to identify CAT I, II, and III findings, false positives, and configuration issues. Track, document, and validate remediation activities, risk acceptances, and exceptions to ensure adherence to RMF, NIST, DoD, and Air Force cybersecurity requirements. Prepare vulnerability reports, compliance dashboards, and metrics for leadership, inspection readiness, and activities including CCRI and CORA. Collaborate with system administrators, Queue Managers, and engineering teams to prioritize critical vulnerabilities and maintain ACAS asset groupings and scan configurations. Support continuous monitoring, audits, accreditation activities, and security control assessments while developing documentation supporting system security posture.

Required Qualifications

  • Active DoD Secret Security Clearance
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field
  • 3+ years of cybersecurity, information assurance, vulnerability management, or system administration experience
  • At least 1 year of hands-on experience with ACAS, Tenable, or related vulnerability management platforms
  • CompTIA Security+ CE or higher DoD 8570/8140-compliant certification meeting current ISSO qualification requirements
  • Experience managing POA&Ms, vulnerability remediation efforts, and cybersecurity compliance documentation
  • Working knowledge of DISA STIGs, vulnerability severity classifications, risk assessment methodologies, and remediation strategies
  • Familiarity with NIST SP 800-53, the Risk Management Framework (RMF), and Air Force cybersecurity policies, including AFMAN 17-130
  • Experience analyzing vulnerability scan results and identifying CAT I, II, and III findings, false positives, and configuration issues
  • Strong understanding of cybersecurity principles, enterprise systems, networks, and secure configuration management
  • Exceptional attention to detail, documentation skills, and the ability to interpret technical vulnerability data and communicate recommendations effectively
  • Strong interpersonal and collaboration skills with the ability to work across technical and non-technical teams
  • Experience supporting U.S. Air Force, DISA, AFNCR, or other Department of Defense mission environments
  • Experience supporting CCRI, CORA, Command Cyber Readiness Inspections, or similar cybersecurity assessment and inspection activities
  • Proven success coordinating enterprise vulnerability remediation campaigns and driving closure of high-priority findings
  • Ability to communicate risk-based recommendations to technical teams, leadership, and non-technical stakeholders
  • Experience developing executive-level dashboards, cybersecurity metrics, and compliance reporting
  • Knowledge of automation and scripting technologies such as PowerShell, Python, or Nessus APIs to improve operational efficiency and reporting capabilities
  • Advanced cybersecurity certifications such as CISSP, CASP+, CISM, or equivalent credentials
  • A proactive, solutions-oriented mindset with a passion for strengthening cybersecurity posture and supporting mission-critical operations
  • Experience working in fast-paced environments supporting high-visibility customers where operational readiness and security are paramount
  • Must be able to lift 50 lbs

Desired Qualifications

  • Additional years of relevant experience and certifications may be considered in lieu of a degree
  • Experience supporting DISPATCH, EvaluateSTIG, STIG Manager, and related vulnerability management and compliance tools
  • Experience working in fast-paced environments supporting high-visibility customers where operational readiness and security are paramount

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Find similar roles