2

Full Time Cis Cyber Security Jobs (NOW HIRING)

Senior Manager, Cybersecurity

Dallas, TX · On-site

$109K - $148K/yr

Lead cyber risk assessments and controls audits using frameworks such as NIST and CIS Controls, and ... Working Conditions This is a full-time position based at Groundworks' Field Support Office in ...

Cyber Security Program Manager

Miami, FL · On-site

$150K - $165K/yr

Miami, Florida, United States (3x week in Office) Hire Type: Full-time Department: Technology ... and CIS Controls. * Awareness of the evolving threat landscape, including malware, phishing ...

New York, NY or Miami, FL (3x week in Office) Hire Type: Full-time Department: Technology Summary ... and CIS Controls. * Awareness of the evolving threat landscape, including malware, phishing ...

next page

Showing results 1-20

Full Time Cis Cyber Security information

See salary details

$40.5K

$122.9K

$180K

How much do full time cis cyber security jobs pay per year?

As of Jul 20, 2026, the average yearly pay for full time cis cyber security in the United States is $122,890.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,000.00 and $142,000.00 per year, depending on experience, location, and employer.

What are some common challenges faced by CIS Cyber Security professionals in a full-time role, and how can they be addressed?

Full-time CIS Cyber Security professionals often encounter challenges such as staying updated with rapidly evolving threats, managing heavy workloads during security incidents, and ensuring compliance with industry standards. To address these issues, professionals should engage in continuous learning through certifications and training, prioritize tasks effectively, and foster strong communication with other IT and business teams. Collaboration and leveraging automation tools can also help streamline repetitive tasks and enhance overall security posture.

What is the difference between Full Time Cis Cyber Security vs Cyber Security Analyst?

AspectFull Time Cis Cyber SecurityCyber Security Analyst
CertificationsCISSP, CompTIA Security+CompTIA Security+, CEH
Work EnvironmentCorporate, government, or large organizationsIT departments, security firms, or consulting
Job FocusImplementing security policies, compliance, risk managementMonitoring security systems, incident response, vulnerability assessment

Full Time Cis Cyber Security roles typically focus on implementing security frameworks and ensuring compliance within organizations, often requiring certifications like CISSP. Cyber Security Analysts mainly monitor security systems, respond to incidents, and perform vulnerability assessments. While both roles require security certifications and work in similar environments, their core responsibilities differ, with Cis Cyber Security emphasizing policy and risk management, and Analysts focusing on operational security tasks.

What are the key skills and qualifications needed to thrive as a CIS Cyber Security professional, and why are they important?

To thrive as a CIS Cyber Security professional, you need a strong understanding of network security, risk assessment, and information security principles, often backed by a degree in computer science or cybersecurity and relevant certifications such as CISSP or CompTIA Security+. Familiarity with security tools like SIEM systems, firewalls, and vulnerability scanners, as well as frameworks like NIST or CIS Controls, is typically required. Analytical thinking, attention to detail, and effective communication are essential soft skills for identifying threats and collaborating with teams. These skills are crucial for protecting organizational assets, ensuring regulatory compliance, and mitigating cyber risks.

What is a Full Time CIS Cyber Security professional?

A Full Time CIS Cyber Security professional is someone who works to protect an organization's computer systems, networks, and data from cyber threats, following the standards and best practices set by the Center for Internet Security (CIS). Their responsibilities include monitoring for security breaches, implementing security measures, responding to incidents, and ensuring compliance with CIS benchmarks. These professionals work full-time to continuously improve the organization's security posture and reduce vulnerabilities.
More about Full Time Cis Cyber Security jobs
What cities are hiring for Full Time Cis Cyber Security jobs? Cities with the most Full Time Cis Cyber Security job openings:
What are the most commonly searched types of Cis Cyber Security jobs? The most popular types of Cis Cyber Security jobs are:
What states have the most Full Time Cis Cyber Security jobs? States with the most job openings for Full Time Cis Cyber Security jobs include:
Infographic showing various Full Time Cis Cyber Security job openings in the United States as of July 2026, with employment types broken down into 23% Locum Tenens, 68% Full Time, 6% Part Time, and 3% Contract. Highlights an 84% Physical, 5% Hybrid, and 11% Remote job distribution, with an average salary of $122,890 per year, or $59.1 per hour.

ACAS Cybersecurity Analyst

Apavo Corporation

Oakton, VA • On-site

Full-time

Posted 27 days ago


Job description

Job Title: ACAS Cybersecurity Analyst
Location: Oakton, VA
Department: Cyber Security Services
Reports To: Management
FLSA Status: Full Time/Non-exempt
Description:
Apavo delivers cybersecurity services to military, defense, and critical infrastructure organizations, and we're growing our Cyber Security Services team. We're built on quality, clear communication, and the belief that every team member's input matters - paired with a genuine commitment to work-life balance and professional growth. If you want cybersecurity work that has real mission impact, backed by a team that invests in your development, we'd love to talk.
Job Purpose:
In this role, the ACAS Cybersecurity Analyst plays a key part in supporting a high-priority federal research mission, driving vulnerability management, compliance validation, and Continuous Monitoring (ConMon) efforts across complex, multi-enclave Risk Management Framework (RMF) environments.
Duties & Responsibilities:
ACAS Cybersecurity Analyst responsibilities include, but are not limited to:
Advanced ACAS Administration: Deploy, configure, and manage Tenable Security Center (Tenable.sc) and Nessus scanners across connected and air-gapped enclaves (NIPR, SIPR, JWICS, SAP).
Vulnerability, R&D & Directive Scanning: Execute and analyze credentialed and non-credentialed vulnerability scans. Tailor scan zones, profiles, and asset lists to ensure 100% visibility while preventing disruptions to fragile, experimental research systems. Perform targeted scanning to determine and verify system compliance with DCDC Communications Tasking Orders (CTOs).
Troubleshooting & Maintenance: Diagnose and resolve complex scanner connectivity issues, WMI/SSH credentialed scan failures, and perform manual/offline plugin and feed synchronizations for isolated, highly classified networks.
Multi-Framework Compliance Validation: Validate findings against DISA STIGs, CIS benchmarks, and specific IC/SAP security baselines. Conduct compliance checks using tools such as SCC, STIG Viewer, and Evaluate-STIG.
Risk & Remediation Tracking: Develop and maintain POA&M documentation. Monitor IAVA/IAVM notices and IC-specific vulnerability alerts. Collaborate with operations and engineering personnel to provide risk-based remediation strategies, tracking mitigation within systems of record (e.g., eMASS, Xacta).
Continuous Monitoring & Upstream Reporting: Execute ConMon activities, integrating ACAS outputs with local SIEM tools (e.g., Splunk) to maintain ongoing authorization and coordinate with the external Cybersecurity Service Provider (CSSP). Support upstream enterprise cybersecurity posture reporting, ensuring accurate data synchronization with the Continuous Monitoring and Risk Scoring (CMRS) system.
DoD & IC RMF Support: Support RMF lifecycle activities across multiple regulatory frameworks-including DoD RMF (DoDI 8510.01), Intelligence Community Directive 503 (ICD 503), and the Joint SAP Implementation Guide (JSIG). Maintain artifacts and map technical scan findings to NIST SP 800-53 and CNSSI 1253 controls.
The ACAS Cybersecurity Analyst is expected to have additional duties as assigned in support of corporate cybersecurity services and mission requirements. Additional details are reviewed in accordance with company policies.
Other:
This is typical office or administrative work, and there is no exposure to adverse environmental conditions.
This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
Apavo Corporation provides equal employment opportunities to all applicants and employees and strictly prohibits any type of harassment or discrimination in regards to race, religion, age, color, sex, disability status, national origin, genetics, sexual orientation, protected veteran status, gender expression, gender identity, or any other characteristic protected under federal, state, and/or local laws.
Consistent with the Americans with Disabilities Act (ADA), it is the policy of Apavo Corporation to provide reasonable accommodation when requested by a qualified applicant or employee with a disability, unless such accommodation would cause an undue hardship. The policy regarding requests for reasonable accommodation applies to all aspects of employment, including the application process. If reasonable accommodation is needed, please contact Apavo Human Resources at hr@apavo.com or 571-407-0069
Employment with Apavo Corporation is on an at-will basis, meaning either you or the Company can terminate the employment relationship, at any time, for any or no reason, and with or without cause or notice. As an at-will employee, your employment with Apavo Corporation is not guaranteed for any length of time.
Requirements
Qualifications:
  • Education/Experience: Bachelor's degree in Cybersecurity, Information Technology, or related field (or equivalent experience) with 5-7+ years of experience in DoD/IC cybersecurity, heavily focused on vulnerability management and RMF.
  • Clearance: Active Top Secret clearance with SCI eligibility. (Willingness to undergo a Counterintelligence (CI) or Full-Scope Polygraph for SAP readiness is highly preferred).
  • DoD Directive: DoD 8570.01-M / 8140.03 compliant for IAT Level II (e.g., Security+ CE, CySA+) or Level III (e.g., CASP+, CISSP).
  • ACAS Certification: Current DISA ACAS Operator and/or Administrator training certificate is required.
  • Technical Proficiency: Deep, hands-on administrative experience with ACAS (Nessus / Tenable.sc) infrastructure, including offline updates, CMRS integration, air-gapped deployments, and credentialed scan troubleshooting.
  • OS/Environment: Computing Environment (CE) certification (e.g., Linux+, Windows Server) or equivalent command-line experience is highly preferred for ACAS host management.
  • Framework Knowledge: Strong understanding of DoD RMF (DoDI 8510.01), IC RMF (ICD 503), JSIG, CNSSI 1253, NIST SP 800-53 controls, STIG implementation, and IAVA/IAVM/CTO remediation processes.
  • Tooling: Experience with SCC, STIG Viewer, eMASS, Xacta (heavily used in IC/SAP environments), and log aggregation tools (e.g., Splunk).
  • Communication: Strong analytical and problem-solving skills, with the ability to communicate technical cyber risks to non-technical program managers and research scientists.