Remote job
Information Security Systems Engineer (ISSE)
Job details
About this role
Role overview A mid-level Information System Security Engineer role focused on embedding cybersecurity into business operations by partnering with portfolio teams and an internal CISO organization. The position bridges business objectives with security strategy, applying NIST guidance to identify vulnerabilities and implement countermeasures across federal mission environments.
Responsibilities - Develop and maintain bodies of evidence (BOE) for information systems, custom applications, services, and networks, working directly with project teams. - Implement the Client Data Program (CDP) requirements alongside project teams and translate Client Data Program rules into operational practices. - Author, publish, and maintain system security policies, processes, and governing products that keep operational risk low. - Conduct internal vulnerability assessments and coordinate external audits of security controls. - Coordinate security activities across program management, engineering, software development, and supply chain risk functions. - Produce ATO packages and supporting documentation, including SSPs, POA&Ms, SCTMs, Certification Test Reports, briefings, continuous monitoring plans, and training materials. - Perform Security Impact Analyses on system change requests for systems already authorized by the CISO. - Manage multiple complex priorities in a dynamic environment and translate technical concepts for semi-technical audiences.
Requirements - Bachelor's degree in a related field, or equivalent experience of four or more years. - Two to five years configuring and securing systems to meet compliance with controls and STIGs. - Three or more years conducting Assessment and Authorization using the Risk Management Framework across all six steps. - Two to five years administering risk management in an enterprise or tactical environment. - Five or more years working with the Microsoft Office Suite, including Word, Excel, and PowerPoint. - Two or more years working with systems and the Software Development Life Cycle.
Nice to have - An active Secret security clearance. - Experience with non-traditional IT such as small purpose-built computers or networked sensor equipment. - Vendor-agnostic cloud experience and FedRAMP knowledge. - CISSP certification or an equivalent credential.