Quick Summary
Overview
Vulnerability Assessor Location: Alexandria,
Technical Tools
Other
Vulnerability Assessor
Location: Alexandria, VA (Hybrid – Telework with periodic on-site support as required)Clearance: Active Secret
Position Overview
ASRC Federal is seeking a Vulnerability Assessor to support the Department of War Education Activity (DoWEA) Enterprise Cyber Program. The Vulnerability Assessor will identify, analyze, and track system vulnerabilities to strengthen the organization’s cybersecurity posture and ensure compliance with DoD Risk Management Framework (RMF) requirements. This role supports Continuous Monitoring (ConMon) activities and works closely with cybersecurity and system teams to enhance DoWEA’s enterprise-wide security operations.
Responsibilities
Conduct vulnerability scans using ACAS (Tenable/Nessus), STIG Viewer, and related DoD-approved assessment tools.
Categorize and analyze vulnerabilities in accordance with NIST SP 800-53, DISA STIGs, and DoDI 8510.01 (RMF).
Collaborate with Information System Security Managers (ISSMs), Information System Security Officers (ISSOs), and system administrators to track remediation and update Plans of Action and Milestones (POA&Ms).
Prepare and maintain vulnerability assessment reports and risk summaries for leadership.
Support RMF Steps 3–6 and Continuous Monitoring documentation within eMASS.
Research and evaluate emerging technologies to identify new or evolving risks and recommend mitigation strategies.
Basic Qualifications
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related discipline (four additional years of equivalent experience may substitute).
Minimum 5+ years of cybersecurity or vulnerability management experience.
Active DoD Secret clearance
DoD 8570.01-M IAT Level II certification (e.g., Security+ CE, CySA+, CCNA-Security).
Hands-on experience with ACAS (Tenable/Nessus) and STIG compliance tools.
Strong analytical, documentation, and communication skills.
Working knowledge of vulnerability scanning, risk assessment methodologies, and remediation tracking.
Preferred Qualifications
Familiarity with DoW (DoD) RMF, eMASS, and DISA STIG/SRG compliance.
Understanding of NIST SP 800-53, CNSSI 1253, and DoDI 8510.01 frameworks.
Knowledge of common cybersecurity threats, exploits, and attack vectors.
Experience supporting federal or DoD IT environments.
Positive, proactive approach and ability to collaborate effectively across remote and on-site teams.
Location & Eligibility
Where is the job
—
Location terms not specified
Listing Details
- Posted
- June 11, 2026
- First seen
- June 11, 2026
- Last seen
- June 11, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 49%
- Scored at
- June 11, 2026
Signal breakdown
freshnesssource trustcontent trustemployer trust
External application · ~5 min on asrcfh's site
Please let asrcfh know you found this job on Jobera.
3 other jobs at asrcfh
View all →Explore open roles at asrcfh.
Similar Other jobs
View all →Short-form Video & Social, Community Comms
Senior Integration Reliability Engineer, Technical Operations
Risk Strategist, Onboarding and Compliance
Remote
Risk Operations Associate (CDMX) - User Policy Operations
Product Support Specialist
Product Support Specialist
Newsletter
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
A
B
C
D
No spam. Unsubscribe at any time.