2

Remote Disa Acas Jobs in Virginia (NOW HIRING)

Conduct self-assessments using ACAS (Nessus) and SCAP Compliance Checker (SCC) to identify ... Work is typically based in a remote working environment and subject to frequent interruptions.

Conduct self-assessments using ACAS (Nessus) and SCAP Compliance Checker (SCC) to identify ... Work is typically based in a remote working environment and subject to frequent interruptions.

Remote Disa Acas information

What are some common challenges faced by Remote DISA ACAS professionals, and how can they be addressed?

Remote DISA ACAS professionals often face challenges such as managing secure network access, ensuring compliance across dispersed environments, and coordinating with on-site teams to address vulnerabilities. Communication can be more complex when troubleshooting security findings or deploying patches remotely. To address these challenges, it's important to establish clear communication channels, schedule regular check-ins with stakeholders, and utilize secure remote access tools authorized by DISA policies. Building strong documentation habits and staying updated on ACAS best practices will also help maintain smooth operations and compliance.

What is the difference between Remote Disa Acas vs Remote HR Advisor?

AspectRemote Disa AcasRemote HR Advisor
CertificationsACAS, Disa-specific trainingHR certifications (e.g., CIPD, SHRM)
Work EnvironmentPrimarily remote, focused on dispute resolutionRemote or office-based, broader HR functions
Employer & Industry UsageUsed in UK public sector and dispute resolutionUsed across various industries for HR support

Remote Disa Acas specialists focus on dispute resolution and employment law advice, often within the UK public sector, requiring specific ACAS and Disa training. Remote HR Advisors handle broader HR functions like recruitment, employee relations, and policy development, with certifications like CIPD or SHRM. While both roles can be remote, their core responsibilities and industry usage differ, making them distinct career paths within HR and employment support.

What are the key skills and qualifications needed to thrive as a Remote DISA ACAS?

To thrive as a Remote DISA ACAS Analyst, you need in-depth knowledge of network security, vulnerability assessment, and compliance frameworks, often backed by a bachelor’s degree in IT or cybersecurity and relevant certifications like CompTIA Security+ or CISSP. Expertise in using the Assured Compliance Assessment Solution (ACAS), including Tenable.sc/Nessus and related DISA tools, is critical. Strong analytical thinking, attention to detail, and effective remote communication skills set top performers apart. These skills ensure robust security posture, maintain compliance with Department of Defense standards, and facilitate seamless collaboration in distributed environments.

What is a Remote DISA ACAS?

A Remote DISA ACAS refers to a professional who operates the Department of Defense Information System Agency’s (DISA) Assured Compliance Assessment Solution (ACAS) remotely. ACAS is a suite of security tools used to scan, identify, and manage vulnerabilities within DoD networks to ensure compliance with cybersecurity standards. Remote DISA ACAS personnel are responsible for running network vulnerability scans, generating reports, and helping organizations maintain the required security posture, all while working offsite. This role is vital for protecting sensitive government information and supporting compliance with DoD cybersecurity regulations.
What are the most commonly searched types of Disa Acas jobs in Virginia? The most popular types of Disa Acas jobs in Virginia are:
What job categories do people searching Remote Disa Acas jobs in Virginia look for? The top searched job categories for Remote Disa Acas jobs in Virginia are:
What cities in Virginia are hiring for Remote Disa Acas jobs? Cities in Virginia with the most Remote Disa Acas job openings:
Infographic showing various Remote Disa Acas job openings in Virginia as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% Remote job distribution.

Vulnerability Manager Lead

Dark Wolf Solutions

Arlington, VA • On-site, Remote

Full-time

Posted yesterday

New


Job description

Dark Wolf is seeking a Vulnerability Management Lead to oversee technical vulnerability operations, modern AI workload security, and compliance baselines across a large-scale, multi-tenant cloud government system. Working closely with cross-functional engineering teams, system administrators, and program leadership, the Lead will drive the end-to-end vulnerability lifecycle from initial detection through final remediation.

We are seeking a collaborative cybersecurity professional with a solid foundation in federal or DoD vulnerability management, cloud environments, and technical risk assessment. This position offers the opportunity to lead operational workflows, leverage data analysis (SQL) and tool integrations (REST APIs) to automate reporting, and help shape security strategies for modern platforms—including emerging AI/LLM workloads.

Whether you are an experienced Lead or a Senior Vulnerability/Systems Analyst ready to take the next step in leadership, this role provides an impactful platform to guide technical risk decisions across a mission-critical system. This position is based out of Arlington, VA with hybrid/remote opportunities. Additional responsibilities include:

Key Responsibilities

  • Oversee daily vulnerability identification, triage, and reporting across AWS cloud assets, traditional hybrid infrastructure, and AI/LLM application stacks.
  • Evaluate raw vulnerability data generated by ACAS (Tenable.sc) and AWS security tools to determine its actual threat vector; identify true contextual risk based on compensating controls, network exposure, and the system's specific cloud architecture.
  • Leverage ACAS to execute and analyze SCAP-compliant configuration audits, verifying system alignment with established DISA STIG security benchmarks and identifying configuration drift across cloud assets.
  • Monitor, document, and track the end-to-end lifecycle of technical remediation efforts.
  • Establish and manage cybersecurity vulnerability tickets within Jira to maintain a clear audit trail from identification to closure.
  • Serve as a primary point of contact for hands-on IT support, system administrators, and engineers; clearly communicate the technical details of vulnerabilities, outline required remediation steps, and assist in prioritizing patches.
  • Translate un-remediated, high-true-risk vulnerabilities into actionable Plan of Action and Milestones (POA&Ms), clearly detailing the technical milestones and business impacts.
  • Translate complex technical findings and AI-specific security risks into concrete, step-by-step remediation guidance for platform, data science, and DevOps engineering teams.
  • Collaborate with the team to cross-reference active exploit intelligence against known system vulnerabilities, refining true risk prioritizations based on active real-world threats.
  • Compile and deliver vulnerability posture reports, metrics dashboards, and executive briefings for government stakeholders.
  • Mentor mid-level analysts on triage methodologies, emerging AI threat vectors, technical writing, and workflow automation.
Required Qualifications
  • 6+ years of experience in Cybersecurity, Vulnerability Management, or Systems Administration supporting federal or DoD information systems.
  • Direct, hands-on experience utilizing ACAS (Tenable.sc) to filter, analyze, and report on enterprise vulnerabilities.
  • Operational understanding of the Security Content Automation Protocol (SCAP) ecosystem, including how automated configuration audit files translate into compliance metrics within vulnerability scanners.
  • Comprehensive understanding of how Splunk Enterprise Security and Trellix (ESS) correlate with vulnerability monitoring activities
  • Practical experience writing SQL queries for reporting and/or analytics
  • Proven proficiency utilizing Jira (or equivalent enterprise ticketing infrastructure) to track, update, and manage technical workflows through completion.
  • Excellent interpersonal and written communication skills, with a demonstrated ability to translate complex security vulnerabilities into actionable guidance for IT personnel.
  • Solid understanding of core AWS services (EC2, VPC, Security Groups, IAM) and how vulnerabilities manifest within a cloud-native environment.
  • Must hold an active DoD 8570/8140 IAT Level II certification (e.g., Security+, CySA+).
  • U.S. Citizenship with an active Top Secret security clearance
Desired Qualifications
  • Possess a valid DISA certification for ACAS, Trellix, or Splunk issued or renewed within the last three years, or demonstrate the capability to successfully obtain the required DISA certification upon hire.
  • Familiarity with tracking vulnerabilities across containerized microservices (Docker/Kubernetes) or modern data platforms like Databricks.
  • Ability to identify and evaluate vulnerabilities unique to AI/LLM environments, including model training/inference pipelines, API endpoints, microservices, and AI framework dependencies (e.g., PyTorch, LangChain, Hugging Face) using frameworks like the OWASP Top 10 for LLM Applications.

The salary range for this position is estimated to be between $155,000.00 - $160,000.00, commensurate on experience and technical skillset.

We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories.

In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.