The role requires experience supporting secure DoD environments and working with cybersecurity tools and processes such as eMASS, ACAS, Nessus, SCAP, STIGs, RMF artifacts, Cyber Tasking Orders, and ...
The role requires experience supporting secure DoD environments and working with cybersecurity tools and processes such as eMASS, ACAS, Nessus, SCAP, STIGs, RMF artifacts, Cyber Tasking Orders, and ...
● Knowledge of Arista, Aruba, Plexxi, F5 load balancers, and Dell networking devices. ● Familiar with STE/STN requirements to meet STIG/Security mandates and the utilization of Nessus Security ...
● Knowledge of Arista, Aruba, Plexxi, F5 load balancers, and Dell networking devices. ● Familiar with STE/STN requirements to meet STIG/Security mandates and the utilization of Nessus Security ...
Senior Cybersecurity Engineer (ACAS/Trellix SME)
Fort George G Meade, MD · On-site
$150K - $190K/yr
ZTI Solutions is seeking a Senior Cybersecurity Engineer to serve as the primary ACAS (Tenable.sc/Nessus) and Trellix engineer supporting a multinational IL5/IL6 collaboration effort in an ...
Quick apply
Senior Cybersecurity Engineer (ACAS/Trellix SME)
Fort George G Meade, MD · On-site
$150K - $190K/yr
ZTI Solutions is seeking a Senior Cybersecurity Engineer to serve as the primary ACAS (Tenable.sc/Nessus) and Trellix engineer supporting a multinational IL5/IL6 collaboration effort in an ...
The role requires experience supporting secure DoD environments and working with cybersecurity tools and processes such as eMASS , ACAS, Nessus, SCAP, STIGs, RMF artifacts, Cyber Tasking Orders, and ...
The role requires experience supporting secure DoD environments and working with cybersecurity tools and processes such as eMASS , ACAS, Nessus, SCAP, STIGs, RMF artifacts, Cyber Tasking Orders, and ...
The role requires experience supporting secure DoD environments and working with cybersecurity tools and processes such as eMASS, ACAS, Nessus, SCAP, STIGs, RMF artifacts, Cyber Tasking Orders, and ...
The role requires experience supporting secure DoD environments and working with cybersecurity tools and processes such as eMASS, ACAS, Nessus, SCAP, STIGs, RMF artifacts, Cyber Tasking Orders, and ...
● Knowledge of Arista, Aruba, Plexxi, F5 load balancers, and Dell networking devices. ● Familiar with STE/STN requirements to meet STIG/Security mandates and the utilization of Nessus Security ...
Quick apply
● Knowledge of Arista, Aruba, Plexxi, F5 load balancers, and Dell networking devices. ● Familiar with STE/STN requirements to meet STIG/Security mandates and the utilization of Nessus Security ...
Site Reliability Engineer
Aurora, CO · On-site
$57.75 - $77/hr
... Nessus, Jira, or Confluence • Knowledge of patching and hardening systems • TS/SCI clearance with a polygraph • HS diploma or GED • Ability to obtain a Security+ CE, SSCP, CCNA-Security, or ...
Site Reliability Engineer
Aurora, CO · On-site
$57.75 - $77/hr
... Nessus, Jira, or Confluence • Knowledge of patching and hardening systems • TS/SCI clearance with a polygraph • HS diploma or GED • Ability to obtain a Security+ CE, SSCP, CCNA-Security, or ...
• Knowledge of Arista, Aruba, Plexxi, F5 load balancers, and Dell networking devices. • Familiar with STE/STN requirements to meet STIG/Security mandates and the utilization of Nessus Security ...
• Knowledge of Arista, Aruba, Plexxi, F5 load balancers, and Dell networking devices. • Familiar with STE/STN requirements to meet STIG/Security mandates and the utilization of Nessus Security ...
... Nessus. • Handle STE/STN scoring and documentation. • Maintain POA&Ms and patch systems based on security and functional parameters. • Collaborate with hardware vendors on system specs and ...
... Nessus. • Handle STE/STN scoring and documentation. • Maintain POA&Ms and patch systems based on security and functional parameters. • Collaborate with hardware vendors on system specs and ...
ACAS Vulnerability Admin
Quantico, VA · On-site
Maintain the Nessus scanners and PVS's connectivity with the associated Security Center (SC). QUALIFICATIONS EDUCATION AND CERTIFICATIONS: * 2+ years ACAS and/or Nessus experience * 3+ years ...
ACAS Vulnerability Admin
Quantico, VA · On-site
Maintain the Nessus scanners and PVS's connectivity with the associated Security Center (SC). QUALIFICATIONS EDUCATION AND CERTIFICATIONS: * 2+ years ACAS and/or Nessus experience * 3+ years ...
Nessus / Rapid7 * Security Development and Operations (SecDevOps) * Various security tools and processes such as Splunk, Nessus Security Center, WebInspect, Xacta * Cloud security controls and ...
Quick apply
Nessus / Rapid7 * Security Development and Operations (SecDevOps) * Various security tools and processes such as Splunk, Nessus Security Center, WebInspect, Xacta * Cloud security controls and ...
ACAS Vulnerability Admin
Quantico, VA · On-site
Maintain the Nessus scanners and PVS's connectivity with the associated Security Center (SC). QUALIFICATIONS EDUCATION AND CERTIFICATIONS: * 2+ years ACAS and/or Nessus experience * 3+ years ...
ACAS Vulnerability Admin
Quantico, VA · On-site
Maintain the Nessus scanners and PVS's connectivity with the associated Security Center (SC). QUALIFICATIONS EDUCATION AND CERTIFICATIONS: * 2+ years ACAS and/or Nessus experience * 3+ years ...
Experience using: • Tenable Nessus Manager • Linux • Trellix E-Policy Orchestrator • Windows 10/11, Server 2016/2019/ • Windows Active Directory
Experience using: • Tenable Nessus Manager • Linux • Trellix E-Policy Orchestrator • Windows 10/11, Server 2016/2019/ • Windows Active Directory
System Engineer 2-BP-445
Hanover, MD · On-site
... Nessus agents and BigFix. • Must be familiar with tracking and remediating security vulnerabilities across various environments. Qualifications : Required : • An active TS/SCI W/ FULL SCOPE ...
System Engineer 2-BP-445
Hanover, MD · On-site
... Nessus agents and BigFix. • Must be familiar with tracking and remediating security vulnerabilities across various environments. Qualifications : Required : • An active TS/SCI W/ FULL SCOPE ...
Information Security Analyst IV / Security Engineer Vulnerability Management
Washington, DC · On-site
Responsibilities * Perform enterprise vulnerability assessments using Tenable Nessus . * Analyze vulnerability scan results and prioritize remediation based on risk. * Partner with system ...
Information Security Analyst IV / Security Engineer Vulnerability Management
Washington, DC · On-site
Responsibilities * Perform enterprise vulnerability assessments using Tenable Nessus . * Analyze vulnerability scan results and prioritize remediation based on risk. * Partner with system ...
Sr. Information Systems Security Engineer - Splunk/ACAS/Trellix with Security Clearance
Warrenton, VA · On-site
$114K - $157K/yr
The successful candidate will lead the engineering efforts for the Trellix (ePO) ecosystem and the ACAS (Nessus) suite, ensuring mission-critical assets remain secure, compliant, and resilient. This ...
Sr. Information Systems Security Engineer - Splunk/ACAS/Trellix with Security Clearance
Warrenton, VA · On-site
$114K - $157K/yr
The successful candidate will lead the engineering efforts for the Trellix (ePO) ecosystem and the ACAS (Nessus) suite, ensuring mission-critical assets remain secure, compliant, and resilient. This ...
Senior Software Engineer
Springfield, VA · On-site
$140K - $160K/yr
Design and develop robust Spring Boot applications using Angular Typescript and Java, facilitating the import, editing, and export of Tenable audit files used for Nessus vulnerability scans.
Senior Software Engineer
Springfield, VA · On-site
$140K - $160K/yr
Design and develop robust Spring Boot applications using Angular Typescript and Java, facilitating the import, editing, and export of Tenable audit files used for Nessus vulnerability scans.
... Nessus scanners and Passive Vulnerability Scanner's (PVS) connectivity with the associated Security Center (SC). • Develop and/or update the Standard Operating Procedures (SOP) to support each of ...
... Nessus scanners and Passive Vulnerability Scanner's (PVS) connectivity with the associated Security Center (SC). • Develop and/or update the Standard Operating Procedures (SOP) to support each of ...
... Nessus, or Splunk Enterprise Security. • Implementing vulnerability remediation strategies. Required Skills and Competencies • Expertise in security risk assessment and compliance reporting. • ...
... Nessus, or Splunk Enterprise Security. • Implementing vulnerability remediation strategies. Required Skills and Competencies • Expertise in security risk assessment and compliance reporting. • ...
Lead or support vulnerability management, including analysis of ACAS, Nessus, SCAP, Fortify, STIG, IAVM, and other security findings. * Develop, maintain, and track POA&Ms for vulnerabilities, RMF ...
Lead or support vulnerability management, including analysis of ACAS, Nessus, SCAP, Fortify, STIG, IAVM, and other security findings. * Develop, maintain, and track POA&Ms for vulnerabilities, RMF ...
Nessus information
See salary details
$33.5K - $46.3K
1% of jobs
$46.3K - $59K
0% of jobs
$59K - $71.8K
0% of jobs
$71.8K - $84.6K
0% of jobs
$84.6K - $97.4K
4% of jobs
$109.3K is the 25th percentile. Wages below this are outliers.
$97.4K - $110.1K
21% of jobs
$110.1K - $122.9K
15% of jobs
The median wage is $132.8K / yr.
$122.9K - $135.7K
12% of jobs
$135.7K - $148.5K
14% of jobs
$148.5K - $161.2K
7% of jobs
$161.9K is the 75th percentile. Wages above this are outliers.
$161.2K - $174K
26% of jobs
$33.5K
$137.7K
$174K
How much do nessus jobs pay per year?
Can I make $200,000 a year in cyber security?
What is a Tenable job?
What is a Nessus job?
A Nessus job typically involves using Tenable's Nessus vulnerability scanner to assess network security by identifying weaknesses, misconfigurations, and vulnerabilities in systems. Security professionals in this role configure and run scans, analyze results, and provide remediation recommendations to improve cybersecurity posture. Nessus jobs are commonly held by penetration testers, security analysts, and IT administrators responsible for maintaining secure environments.
What does Nessus do?
What are the key skills and qualifications needed to thrive in the Nessus position, and why are they important?
To thrive as a Nessus Vulnerability Analyst, you need a strong foundation in cybersecurity principles, vulnerability assessment, and network security protocols, often demonstrated by a degree in computer science or a related field. Experience with the Nessus vulnerability scanner, familiarity with security frameworks (like CIS or NIST), and relevant certifications such as CompTIA Security+ or CEH are highly valued. Attention to detail, analytical thinking, and strong written communication are important soft skills for accurately reporting findings and collaborating with IT teams. These competencies are crucial for effectively identifying, analyzing, and mitigating security risks within an organization.
What company owns Nessus?
What does a typical day look like for someone working as a Nessus Vulnerability Analyst?
As a Nessus Vulnerability Analyst, your day typically involves conducting vulnerability scans across various network assets, interpreting the resulting reports, and prioritizing the remediation of identified risks. You’ll collaborate closely with IT and security teams to follow up on critical findings, document remediation steps, and ensure compliance with organizational policies. Regular communication with stakeholders is essential, as you’ll provide updates and recommendations based on current threat landscapes. This role offers the opportunity to continuously learn about emerging security threats and technologies while directly contributing to your organization’s cyber defense posture.

Full-time
Posted 15 days ago
Job description
DecisionPoint seeks an Intermediate Information Assurance Engineer to support cybersecurity, compliance, and risk management activities for Global Information Technology Support Services supporting the Military Surface Deployment and Distribution Command (SDDC) Deputy Chief of Staff for Information Management (G6). This position supports the protection, monitoring, assessment, and compliance of SDDC information systems and enterprise IT environments.
The Intermediate Information Assurance Engineer will support Risk Management Framework activities, vulnerability management, STIG compliance, POA&M tracking, incident reporting, cybersecurity documentation, and compliance monitoring across SDDC systems. The role requires experience supporting secure DoD environments and working with cybersecurity tools and processes such as eMASS, ACAS, Nessus, SCAP, STIGs, RMF artifacts, Cyber Tasking Orders, and vulnerability reporting.
This position is located at HQ SDDC, Scott Air Force Base, Illinois.
Note: By applying to this position, you acknowledge and consent to having your resume included in an active competitive government contract bid.
Duties & Responsibilities
The Intermediate Information Assurance Engineer will:
- Support cybersecurity and information assurance activities for SDDC information systems, networks, and business systems.
- Assist with RMF documentation, package development, assessment support, and authorization activities for SDDC systems.
- Update and maintain cybersecurity documentation in eMASS to support current system authorization status, control implementation, and compliance tracking.
- Support development and maintenance of RMF artifacts, including security plans, POA&Ms, security design documentation, assessment materials, and supporting technical documentation.
- Assist with vulnerability management activities, including review of ACAS, Nessus, SCAP, and other security scan results.
- Analyze vulnerability findings and support coordination with system administrators, technical teams, ISSOs, ISSMs, and Government stakeholders to identify remediation actions.
- Support preparation of vulnerability reports, compliance reports, and POA&M updates for open vulnerabilities and IAVM-related findings.
- Monitor STIG compliance for assigned systems and assist with review, validation, documentation, and tracking of STIG findings.
- Ingest or associate STIG findings with applicable RMF controls and assist with maintaining audit-ready compliance documentation.
- Support Cyber Tasking Order tracking, compliance discovery, reporting, and coordination with designated points of contact.
- Assist with firewall, whitelist, PPSM, and other cybersecurity compliance reviews, as required.
- Support incident response and reporting by assisting in the review of anomalous or suspicious activity, researching potential incidents, and coordinating response actions with the ISSO or ISSM.
- Assist with response, containment, eradication, and recovery activities for confirmed security incidents in accordance with SDDC, USTRANSCOM, NETCOM, and DoD procedures.
- Support administration, configuration, reporting, and maintenance of cybersecurity tools such as ACAS, HBSS, Nessus/Security Center, SolarWinds SEM, LogRhythm, McAfee Network Security Manager, IDS sensors, or comparable tools.
- Maintain accurate records, reports, trackers, and technical documentation to support audits, inspections, assessments, and Government reporting requirements.
- Ensure assigned cybersecurity activities comply with applicable DoD, Army, USTRANSCOM, SDDC, RMF, STIG, and information assurance requirements.
Qualifications
Clearance Requirement:
- Must hold an active Secret clearance.
- Must be eligible to obtain and maintain required Common Access Card (CAC), facility access, system access, and Government network access.
Education:
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Information Systems, Engineering, or related technical discipline.
Experience:
- Minimum 5 years of experience supporting cybersecurity, information assurance, RMF, vulnerability management, or compliance activities within DoD or federal environments.
- Experience supporting RMF authorization activities, cybersecurity documentation, control assessment, and compliance reporting.
- Experience using or supporting eMASS for RMF package management, control documentation, POA&M tracking, and authorization support.
- Experience reviewing vulnerability scan results and supporting remediation tracking using tools such as ACAS, Nessus, SCAP, or comparable DoD-approved scanning tools.
- Experience supporting DISA STIG review, compliance validation, audit preparation, and finding remediation.
- Experience developing, updating, and tracking POA&Ms for cybersecurity findings, RMF controls, IAVMs, or vulnerability management activities.
- Experience supporting incident response, suspicious activity reporting, compliance reporting, and coordination with ISSO, ISSM, or cybersecurity leadership.
Technical Knowledge:
- Knowledge of DoD cybersecurity policies, RMF, eMASS, DISA STIGs, POA&M management, IAVM compliance, and vulnerability management processes.
- Familiarity with ACAS, Nessus/Security Center, SCAP scanning, HBSS, McAfee security tools, IDS sensors, or similar cybersecurity tools.
- Understanding of cybersecurity compliance reporting, Cyber Tasking Orders, cyber scorecards, vulnerability index reporting, and audit support.
- Knowledge of system security documentation, assessment procedures, control inheritance, ATO support, and continuous monitoring.
- Understanding of secure configuration management, system hardening, patching, incident handling, and DoD information protection requirements.
- Ability to interpret technical scan results, identify risk impacts, and coordinate practical remediation recommendations with technical teams.
Certifications (Preferred):
- Must hold applicable DoD 8140 / 8570 cybersecurity workforce baseline certification as required for the position.
- Must meet applicable PWS IA baseline and computing environment certification requirements, as validated against the DD254 and final RFP.
- Security+ CE, CySA+, CASP+, CISSP, or other DoD-approved cybersecurity certification preferred, depending on final labor category and access requirements.
Skills:
- Strong analytical and problem-solving skills in cybersecurity and compliance-driven environments.
- Ability to document technical findings clearly and maintain accurate RMF, POA&M, and compliance records.
- Strong attention to detail when reviewing vulnerability findings, STIG checklists, RMF controls, and audit artifacts.
- Ability to coordinate effectively with system administrators, cybersecurity staff, Government stakeholders, and technical leads.
- Strong written and verbal communication skills for reporting findings, risks, remediation status, and compliance posture.
- Commitment to protecting DoD information systems, supporting mission assurance, and maintaining continuous cybersecurity compliance.
Our Equal Employment Opportunity Policy
- EEO and Affirmative Action Policy: DecisionPoint Corporation is an Equal Employment Opportunity and Affirmative Action employer. It is the policy of DecisionPoint Corporation to provide equal employment opportunity in accordance with all applicable Equal Employment Opportunity/Affirmative Action laws, directives and regulations to all employees and qualified applicants without regard to race, ethnicity, color, religion, national origin, sex, age, disability status, pregnancy, sexual orientation, gender identity, genetic information, protected veteran status, or any other protected status under Federal, State or Local laws.
- Pay Transparency Policy: In accordance with Presidential Executive Order 13665, DecisionPoint Corporation will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information.
- Authorization to Share Resume and Personal Information: By expressing your interest and submitting your resume for this position, you authorize DecisionPoint Corporation to share your resume, as well as personal information included on the resume, with its subsidiaries, affiliates and teaming partners for the purpose of considering you for this position and other available positions requiring comparable skills, education and experience. Should DecisionPoint Corporation. or its affiliates and teaming partners wish to initiate pre-employment discussions, you will be asked to complete an employment application and related employment documents.