Security Engineer, Vulnerability Management (ACAS/Tenable.sc) - Secret clearance
PGTEK Ogden, Utah, United States · $130K–$160K/yr
Information Technology & Services · 51-200 employees
About the role
The Security Engineer will administer and optimize the Tenable.sc/ACAS environment to drive vulnerability remediation and ensure compliance with DoD STIG and RMF requirements. They will also conduct vulnerability scans, perform false-positive analysis, and collaborate with cross-functional teams to harden enterprise systems.
What they look for
Requirements
Candidates must have 5+ years of experience in vulnerability management and hold an active DoD Secret clearance. A DoD 8570/8140 IAT Level II baseline certification is also required for this role.
Benefits
Full description
Security Engineer, Vulnerability Management (ACAS/Tenable.sc)About the RolePGTEK is seeking a Security Engineer, Vulnerability Management with a Secret clearance (or higher) to administer and optimize our Tenable.sc/ACAS environment, drive vulnerability remediation across enterprise systems, and support compliance with DoD STIG and RMF requirements.
This is a hands-on role that combines deep Tenable platform expertise with Windows/Linux administration, vulnerability analysis, system hardening, and cross-team collaboration. The ideal candidate will have experience working in a DoD or federal environment and be comfortable managing vulnerability scanning and remediation across complex enterprise environments.
Key ResponsibilitiesTenable Security Center / ACAS• Administer and optimize Tenable.sc and Nessus, including scan policies, scan zones, repositories, credentials, and audit files.
- Perform credentialed vulnerability scans, STIG compliance scans, discovery scans, and port scans.
- Analyze and interpret STIGs, CKLs, ACAS/Tenable findings, and vulnerability results to support compliance and risk reduction.
- Leverage Windows and Linux administration skills to support and troubleshoot authenticated vulnerability scanning.
- Conduct false-positive analysis and validation to ensure accurate vulnerability reporting.
- Collaborate with Cloud, Network, Platform, Security, and Engineering teams to drive vulnerability remediation and system hardening.
Vulnerability Coverage & Asset Discovery• Identify and close gaps in vulnerability scan coverage to ensure comprehensive visibility across the environment.
- Perform asset discovery and maintain accurate inventories to ensure all in-scope systems are included in scanning cycles.
- Analyze scan results to identify coverage gaps, unscanned assets, and compliance blind spots.
- Recommend corrective actions to improve vulnerability visibility, scanning effectiveness, and overall security posture
- 5+ years of experience in vulnerability management, information assurance, or systems security, preferably within a DoD or federal environment.
- Hands-on experience administering Tenable.sc, Nessus, and ACAS in a DoD or federal environment.
- Working knowledge of DoD STIGs, CKLs, and RMF processes.
- Strong Windows and Linux administration experience.
- Active DoD Secret clearance required; clearance must be current and verifiable.
- DoD 8570/8140 IAT Level II baseline certification required, such as:
- CompTIA Security+ CE
- CySA+
- GSEC
- SSCP
- CCNA-Security
- Strong written and verbal communication skills with the ability to collaborate effectively across technical teams.
Work Location & TravelThis is a hybrid position. Candidates must live within approximately 90 minutes of one of the following locations:
- Mechanicsburg, PA
- Ogden, UT
- Oklahoma City, OK
- Montgomery, AL
- Fort Meade, MD
Approximately 25% travel may be required to DISA locations.
Compensation & BenefitsSalary Range: $130,000–$160,000
PGTEK offers the opportunity to work on long-term federal technology programs while supporting mission-critical cybersecurity and infrastructure initiatives.
Contract Length: 10 years
Start Date: ASAP
Our comprehensive benefits package for full-time salaried employees is effective immediately upon the start date. Benefits include comprehensive PPO medical coverage with access to a Health Savings Account (HSA) option, a vision plan, and dental insurance with the base dental plan option paid for by PGTEK. Life Insurance, Short and Long-Term disability, and Critical Illness insurance have premiums covered. Additionally, PGTEK offers a matching 401(k) plan and a discount on pet insurance through ASPCA Pet Insurance. An Employee Assistance Program is available at no cost to all employees. PGTEK offers a generous amount of PTO and Holidays, and an Education Assistance Program is available after 12 months of employment.
ABOUT PGTEK
PGTEK is a true consulting organization dedicated to helping clients achieve their business and technology objectives utilizing our decades of experience and business relationships. PGTEK invests in the educational advancements of our staff by providing the necessary resources to complete Professional and Business Certifications. Our company is our people, and we treat them like family.
EOE, including disability/veterans
Similar roles
-
Senior Security Engineer
Commonwealth Bank Bengaluru, Karnataka, India
-
Security Engineer, GKE
Google Seattle, Washington, United States · $174K–$252K/yr
-
Cybersecurity Incident Response Triage Analyst
Accenture Federal Services Careers Marketplace Arlington, Virginia, United States · $57K–$109K/yr
-
Cybersecurity Incident Response Triage Analyst
Accenture Federal Services Arlington, Virginia, United States · $57K–$109K/yr
-
Information Security Engineer
EverBank Jacksonville, Florida, United States
-
Cybersecurity Acquisition Analyst
Hepburn and Sons, LLC District of Columbia, United States · $80K–$100K/yr