1

Disa Acas Jobs (NOW HIRING)

Senior ACAS Engineer

Quantico, VA · Hybrid

$114.80K - $155.70K/yr

... NIST, DISA STIGs, CIS Benchmarks). The ACAS Engineer will collaborate with other cybersecurity professionals, system administrators, and IT staff to identify vulnerabilities, track remediation ...

Client Solution Architects (CSA) is currently seeking an ACAS/AESS Administrator to support our ... AESS specific training and/or certification (e.g., DISA AESS 201 Admin ePO5.1 and DISA AESS 301 ...

Implement and maintain STIG hardening, ACAS/Nessus vulnerability scanning, and ensure compliance with DISA and Marine Corps cybersecurity policies (RMF/ATO) * Conduct vulnerability scans, analyze ...

SOC Vulnerability Management ACAS Lead - Senior

Fairfax, VA · On-site

$105.70K - $143.40K/yr

... DISA DCDC. Please Note: This position is contingent upon contract award. Responsibilities * Lead ACAS scanning operations across ARNG enterprise environments, including scan planning, execution ...

New

Current DoD/DISA ACAS Training Certification * Experience with DoD/NSS and Only-Locally - Trusted PKI Operations, Maintenance, Cybersecurity, DoD/NSS PKI Compliance, and DoD/USMC Risk Management ...

Client Solution Architects (CSA) is currently seeking an ACAS/AESS Administrator to support our ... AESS specific training and/or certification (e.g., DISA AESS 201 Admin ePO5.1 and DISA AESS 301 ...

Description Client Solution Architects (CSA) is currently seeking an ACAS/AESS Administrator to ... AESS specific training and/or certification (e.g., DISA AESS 201 Admin ePO5.1 and DISA AESS 301 ...

next page

Showing results 1-20

Disa Acas information

See salary details

$38K

$357.5K

$400K

How much do disa acas jobs pay per year?

As of May 31, 2026, the average yearly pay for disa acas in the United States is $357,482.00, according to ZipRecruiter salary data. Most workers in this role earn between $354,000.00 and $400,000.00 per year, depending on experience, location, and employer.

What is a DISA ACAS job?

A DISA ACAS (Assured Compliance Assessment Solution) job involves managing and maintaining ACAS, a vulnerability scanning and compliance tool used within the Department of Defense (DoD). Professionals in this role are responsible for configuring and running scans, analyzing security data, and ensuring network compliance with DoD cybersecurity policies. They often work with tools like Tenable Nessus and Security Center to identify and mitigate vulnerabilities. This role requires knowledge of risk management frameworks, DoD security protocols, and network security principles.

What are the key skills and qualifications needed to thrive as a DISA ACAS (Assured Compliance Assessment Solution) Administrator, and why are they important?

To thrive as a DISA ACAS Administrator, you need strong knowledge of network security principles, vulnerability assessment, and experience with Department of Defense (DoD) compliance standards, often supported by relevant IT certifications like CompTIA Security+ or CISSP. Proficiency in using ACAS tools (such as Tenable Nessus and SecurityCenter), as well as familiarity with RMF (Risk Management Framework) processes, is essential. Attention to detail, analytical thinking, and effective communication are vital soft skills for interpreting scan results and collaborating with both technical and non-technical stakeholders. These skills ensure that systems remain secure, compliant with DoD requirements, and resilient against cybersecurity threats.

What are some typical challenges faced by individuals working in DISA ACAS roles, and how can they prepare for them?

Professionals working with DISA ACAS (Assured Compliance Assessment Solution) often encounter challenges such as keeping up with frequent policy updates, managing large-scale network scans, and ensuring compliance across a variety of systems. To prepare, candidates should become familiar with STIGs (Security Technical Implementation Guides), regularly update their knowledge of DISA requirements, and develop strong troubleshooting skills. Collaboration with system administrators and security teams is also key to effectively address vulnerabilities and maintain compliance in a dynamic environment.

What is DISA ACAS?

DISA ACAS stands for Defense Information Systems Agency’s Assured Compliance Assessment Solution. It is a suite of cybersecurity tools used by the U.S. Department of Defense to automate the process of vulnerability scanning, compliance reporting, and risk management of IT systems. ACAS helps identify security weaknesses, ensures compliance with federal standards, and provides actionable insights to improve network security. It plays a crucial role in maintaining the cybersecurity posture of DoD networks.

What is the difference between Disa Acas vs Disa Acas?

AspectDisa Acas

Since the comparison is between the same job title, Disa Acas, there is no difference in roles, responsibilities, or qualifications. Both refer to the same position, typically involving advisory and support roles within organizations, often in HR or compliance sectors. They usually require similar certifications and work in similar environments, such as corporate offices or consultancy firms. The primary distinction may be in specific employer terminology or regional usage, but generally, Disa Acas is a singular role without variation.

What are the most commonly searched types of Disa Acas jobs? The most popular types of Disa Acas jobs are:
What states have the most Disa Acas jobs? States with the most job openings for Disa Acas jobs include:
Infographic showing various Disa Acas job openings in the United States as of May 2026, with employment types broken down into 92% Full Time, 2% Part Time, and 6% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $357,482 per year, or $171.9 per hour.

Senior ACAS Engineer

asrcfh

Quantico, VA • Hybrid

$114.80K - $155.70K/yr

Other

Posted 5 days ago


Job description

ASRC Federal is seeking a highly skilled and experienced Senior ACAS (Assured Compliance Assessment Solution) Engineer to join our dynamic team. The successful candidate will be responsible for the implementation, maintenance, and optimization of our ACAS infrastructure. This role is critical for ensuring the security and compliance of our information systems with DoD and other federal regulations. The ideal candidate will have a strong background in cybersecurity, vulnerability management, and network security. This position will support our Defense Counterintelligence Security Agency (DCSA) program based out of Quantico VA.

Remote flexibility available! Telework offered with a requirement to be onsite up to three (3) days a week at Quantico Marine Corps Base VA.

Position Description:

The Assured Compliance Assessment Solution (ACAS) Engineer is a critical role responsible for the implementation, maintenance, and operational support of the ACAS suite of tools within the organization. This position focuses on ensuring continuous vulnerability scanning, configuration compliance assessments, and reporting capabilities to maintain a strong security posture and adherence to relevant security policies and regulations (e.g., NIST, DISA STIGs, CIS Benchmarks). The ACAS Engineer will collaborate with other cybersecurity professionals, system administrators, and IT staff to identify vulnerabilities, track remediation efforts, and improve overall security.

Minimum Requirements: 

  • Minimum of 8+ years of experience in vulnerability management, security scanning, or cybersecurity operations.
  • Hands-on experience with the Tenable ACAS suite (Nessus, SecurityCenter/Tenable.sc, NNM/Tenable.asm) is required.
  • Active Secret Clearance REQUIRED, eligible to be upgraded to TS/SCI
  • Must meet 8570 certification requirements at the time of hire.  IAM or IAT Level I (e.g., A+, CCNA Security, Network+ CE, SSCP, CAP, GSLC, Security+ or higher tiered 8570 certification
  • Highly desired: Bachelor’s Degree, in Cybersecurity, and/or Information Systems Management or equivalent.

 

Responsibilities:

  • ACAS Implementation and Configuration:
    • Install, configure, and maintain ACAS components, including Nessus scanners, SecurityCenter/Tenable.sc, and Nessus Network Monitor (NNM)/Tenable.asm.
    • Deploy and manage distributed scanning infrastructure across diverse network environments.
    • Customize ACAS settings, policies, and scan templates to meet specific organizational requirements.
  • Vulnerability Scanning and Analysis:
    • Schedule and execute vulnerability scans using Nessus scanners.
    • Analyze scan results to identify vulnerabilities, misconfigurations, and security gaps.
    • Prioritize vulnerabilities based on severity, exploitability, and potential impact.
    • Validate scan findings to minimize false positives.
  • Compliance Assessment and Reporting:
    • Configure ACAS to perform compliance assessments against industry standards and internal security policies.
    • Generate comprehensive reports on vulnerability status, compliance posture, and remediation progress.
    • Provide analysis and interpretation of assessment results to stakeholders.
    • Develop custom reports and dashboards to visualize security metrics and trends.
  • Remediation Support and Tracking:
    • Collaborate with system administrators and IT staff to facilitate vulnerability remediation efforts.
    • Provide guidance and technical assistance on vulnerability mitigation strategies.
    • Track remediation progress and ensure timely resolution of identified issues.
    • Re-scan systems to verify remediation effectiveness.
  • System Administration and Maintenance:
    • Perform system administration tasks for ACAS servers and databases.
    • Monitor system performance and troubleshoot any issues.
    • Apply security patches and software updates to ACAS components.
    • Maintain accurate documentation of ACAS configuration and procedures.
  • Threat Intelligence Integration:
    • Integrate ACAS with threat intelligence feeds to enhance vulnerability detection capabilities.
    • Correlate scan results with threat intelligence data to identify potential exploitation attempts.
    • Customize ACAS policies to prioritize vulnerabilities based on threat landscape.
  • Training and Documentation:
    • Develop and maintain training materials for ACAS users.
    • Provide training and support to IT staff on vulnerability management processes.
    • Document ACAS procedures, policies, and best practices.
  • Continuous Improvement:
    • Stay up-to-date on the latest vulnerability trends and security threats.
    • Research and evaluate new ACAS features and capabilities.
    • Identify opportunities to improve ACAS effectiveness and efficiency.
    • Contribute to the development of security policies and procedures.

 

Work Environment and Physical Demands: 

  • This is primarily a Telework position with a requirement to be onsite up to three (3) days a week
  • If alternate worksite is other than DCSA facilities or corporate office space, must have the reliable ability to communicate over voice (cell phone preferred) and stable, capable internet connection
  • Must be able to communicate complex technical ideas to a diverse customer base both verbally and in written form