Information Security Engineer
Job Description
Design and operate security architectures for classified environments, with ownership of RMF and ATO activities and direct reporting to the Government Security Council.
Responsibilities
- Plan, design, and build security architectures; oversee implementation of network and computer security and ensure alignment with corporate cybersecurity policies and procedures
- Monitor cybersecurity requirements for LANs, WANs, VPNs, routers, firewalls, and related network devices
- Conduct security assessments for applications and systems using penetration testing, vulnerability testing, and risk analysis
- Configure and install firewalls and intrusion detection systems
- Apply software patches to remediate vulnerabilities
- Respond immediately to cybersecurity-related incidents and perform thorough post-event analysis
- Investigate intrusion incidents and conduct forensic investigations
- Serve as the direct security reporting line to the Government Security Council for security posture, risk status, and program effectiveness
- Deliver executive-quality briefings to the OCLI President to support escalation to the Government Security Council
- Lead cybersecurity operations across multiple classified systems, providing technical direction, work breakdown, cost estimates, and resource allocation
- Act as COMSEC Account Manager, managing communications security materials, accounts, and procedures per government sponsor requirements
- Own the full RMF lifecycle and Authority to Operate (ATO) process for accredited systems
- Provide strategic direction for classified cybersecurity environments and collaborate with government agencies and internal stakeholders to prioritize and deliver mission-aligned security solutions
- Architect and engineer cybersecurity solutions compliant with NISPOM, DISA STIGs, CNSSI 1253, and NIST 800-53 / 800-171
- Author and maintain Body of Evidence (BOE) artifacts, including SSPs, SARs, POA&Ms, and supporting RMF documentation for ATO packages
- Prepare authorization packages, enter evidence into eMASS, and execute annual government security audits and assessments
- Administer enterprise access control and CCTV systems
Requirements
- Must possess an active DoD clearance (SECRET or above)
- 2+ years of professional experience in administrative, regulatory, or compliance roles
- Experience conducting trainings and briefings
- Strong verbal and written communication skills, with excellent interpersonal and relationship-building skills
- Strong organizational skills
- Proficient in MS Office Suite
- Self-motivated and able to work with minimal supervision
- Able to work where cell phones are prohibited (20% of the time)
- Eligibility to obtain a U.S. DoD Security Clearance; current, active U.S. DoD Security Clearance preferred
Technologies
- LANs, WANs, VPNs, routers, firewalls, intrusion detection systems
- Risk Management Framework (RMF), Authority to Operate (ATO)
- NISPOM, DISA STIGs, CNSSI 1253, NIST 800-53, NIST 800-171
- Body of Evidence (BOE), System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms)
- eMASS, CCTV
- MS Office Suite
Benefits
- Paid time off
- Health, life and disability insurance
- 401(k)
- Bonus program
Location: Santa Rosa, CA (onsite)
Experience: 2+ years
Salary: USD 80,500 - 149,500 per year