2

Remote Disa Acas Jobs in Virginia (NOW HIRING)

Conduct self-assessments using ACAS (Nessus) and SCAP Compliance Checker (SCC) to identify ... Work is typically based in a remote working environment and subject to frequent interruptions.

New

Conduct self-assessments using ACAS (Nessus) and SCAP Compliance Checker (SCC) to identify ... Work is typically based in a remote working environment and subject to frequent interruptions.

New

Remote Disa Acas information

What are some common challenges faced by Remote DISA ACAS professionals, and how can they be addressed?

Remote DISA ACAS professionals often face challenges such as managing secure network access, ensuring compliance across dispersed environments, and coordinating with on-site teams to address vulnerabilities. Communication can be more complex when troubleshooting security findings or deploying patches remotely. To address these challenges, it's important to establish clear communication channels, schedule regular check-ins with stakeholders, and utilize secure remote access tools authorized by DISA policies. Building strong documentation habits and staying updated on ACAS best practices will also help maintain smooth operations and compliance.

What is the difference between Remote Disa Acas vs Remote HR Advisor?

AspectRemote Disa AcasRemote HR Advisor
CertificationsACAS, Disa-specific trainingHR certifications (e.g., CIPD, SHRM)
Work EnvironmentPrimarily remote, focused on dispute resolutionRemote or office-based, broader HR functions
Employer & Industry UsageUsed in UK public sector and dispute resolutionUsed across various industries for HR support

Remote Disa Acas specialists focus on dispute resolution and employment law advice, often within the UK public sector, requiring specific ACAS and Disa training. Remote HR Advisors handle broader HR functions like recruitment, employee relations, and policy development, with certifications like CIPD or SHRM. While both roles can be remote, their core responsibilities and industry usage differ, making them distinct career paths within HR and employment support.

What are the key skills and qualifications needed to thrive as a Remote DISA ACAS Analyst, and why are they important?

To thrive as a Remote DISA ACAS Analyst, you need in-depth knowledge of network security, vulnerability assessment, and compliance frameworks, often backed by a bachelor’s degree in IT or cybersecurity and relevant certifications like CompTIA Security+ or CISSP. Expertise in using the Assured Compliance Assessment Solution (ACAS), including Tenable.sc/Nessus and related DISA tools, is critical. Strong analytical thinking, attention to detail, and effective remote communication skills set top performers apart. These skills ensure robust security posture, maintain compliance with Department of Defense standards, and facilitate seamless collaboration in distributed environments.

What is a Remote DISA ACAS?

A Remote DISA ACAS refers to a professional who operates the Department of Defense Information System Agency’s (DISA) Assured Compliance Assessment Solution (ACAS) remotely. ACAS is a suite of security tools used to scan, identify, and manage vulnerabilities within DoD networks to ensure compliance with cybersecurity standards. Remote DISA ACAS personnel are responsible for running network vulnerability scans, generating reports, and helping organizations maintain the required security posture, all while working offsite. This role is vital for protecting sensitive government information and supporting compliance with DoD cybersecurity regulations.
What are the most commonly searched types of Disa Acas jobs in Virginia? The most popular types of Disa Acas jobs in Virginia are:
What are popular job titles related to Remote Disa Acas jobs in Virginia? For Remote Disa Acas jobs in Virginia, the most frequently searched job titles are:
What job categories do people searching Remote Disa Acas jobs in Virginia look for? The top searched job categories for Remote Disa Acas jobs in Virginia are:
What cities in Virginia are hiring for Remote Disa Acas jobs? Cities in Virginia with the most Remote Disa Acas job openings:
Infographic showing various Remote Disa Acas job openings in Virginia as of July 2026, with employment types broken down into 7% Locum Tenens, 86% Full Time, 4% Part Time, and 3% Contract. Highlights an 84% Physical, 6% Hybrid, and 10% Remote job distribution.

Sr Cyber Security Engineer

Constellis

VA • Remote

Full-time

Posted yesterday

New


Constellis rating

7.2

Company rating: 7.2 out of 10

Based on 45 frontline employees who took The Breakroom Quiz

37th of 116 rated security


Job description

Position Overview

The Senior Cyber Security Engineer will bridge the gap between "Compliance" and "Engineering." You will not just audit the system, you will help build it securely and own the cybersecurity workstream end-to-end. This role is responsible for achieving Authority to Operate (ATO) under DoD Risk Management Framework (RMF) standards among other federal certifications while embedding security automation directly into our CI/CD pipelines, and reporting program status and risk directly to LEXSO leadership. You will work side-by-side with backend and frontend engineers to harden the microservices architecture against evolving threats, and you will independently identify security gaps, drive architectural design decisions and shepherd remediation to completion..

Responsibilities

  • Own the LEXSO cybersecurity program end-to-end - from gap identification through architectural design to implementation tracking
  • Report cyber risk posture and remediation progress; translate technical findings into terms leadership can act on
  • Define and maintain the cybersecurity requirements backlog and progress-tracking cadence
  • Lead the technical execution of the RMF process to achieve and maintain Authority to Operate (ATO) for the LEXSO platform
  • Implement security controls in accordance with NIST SP 800-53 and DoD SRG/STIGs
  • Generate and maintain artifacts required for eMASS, including SSPs, POAMs, and SARs
  • Conduct self-assessments using ACAS (Nessus) and SCAP Compliance Checker (SCC) to identify vulnerabilities
  • Integrate automated security testing (SAST/DAST) tools (e.g., SonarQube, OWASP ZAP) into the GitLab/GitHub CI/CD pipeline
  • Develop scripts (Python, Bash, Ansible) to automate patching and configuration management for Linux (RHEL/Ubuntu) servers
  • Implement Container Security scanning for Docker/Kubernetes environments to detect vulnerabilities before deployment
  • Enforce "Security as Code" principles using Terraform or Helm charts
  • Analyze vulnerability scan results and write the code/scripts to remediate findings (e.g., fixing SSH configurations, patching libraries, hardening NGINX)
  • Harden APIs and microservices by implementing secure authentication (OAuth2/JWT/mTLS) and encryption standards (FIPS 140-2)
  • Respond to zero-day threats and CVEs by rapidly deploying hotfixes to the production environment
  • Conduct threat modeling sessions with the engineering team to identify attack vectors in the multi-sensor architecture
  • Design and implement secure logging and auditing pipelines (ELK Stack/Splunk) to meet audit requirements
  • Advise on the secure architecture for integrating third-party sensors (LiDAR, Radar) and IoT devices
  • Work is typically based in a remote working environment and subject to frequent interruptions. Business work hours are Monday-Friday from 8:00 am to 5:00 pm, however some extended or weekend hours may be required.
  • Other duties as assigned

Qualifications

  • 8+ years of experience in Cyber Security Engineering or DevSecOps.
  • Proven track record of achieving ATO (Authority to Operate) for a software system in a DoD/Federal environment
  • Hands-on experience with RMF, NIST 800-53, and DISA STIGs
  • Proficiency in scripting languages (Python, Bash) for automation
  • Experience with vulnerability scanning tools (ACAS/Nessus, SonarQube, Burp Suite)
  • Strong knowledge of Linux Security (SELinux, iptables, hardening)
  • Experience with CI/CD tools (GitLab CI, Jenkins) and Container Security (Docker/K8s)
  • Demonstrated ability to work autonomously - identify security gaps, drive architectural design decisions, and track implementation through to completion
  • Experience communicating technical findings and program status to executive leadership; able to translate risk and remediation into terms leadership can act on
  • Track record of ownership over requirements definition and progress reporting for cybersecurity workstreams
  • CISSP, CASP+, or Security+ CE (Required)
  • Active Secret Security Clearance
  • Bachelor's degree in Computer Science, Cyber Security, or related technical discipline.
  • Preferred Experience:
    • Experience securing cloud environments (AWS GovCloud / Azure Government)
    • Experience with FedRAMP authorization processes
    • Familiarity with "Zero Trust" architecture principles
    • Previous experience as a Software Developer before moving into Security
    • Prior experience as a technical lead or senior individual contributor with direct exposure to stakeholders

BENEFITS

Constellis offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflect its commitment to creating a diverse and supportive workplace.


What Constellis employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom