Information Systems Security Engineer (ISSE)
Job Description
Aspetto, Inc. is seeking an Information Systems Security Engineer (ISSE) to support NAVFAC Marianas in Guam and deliver security engineering across the full RMF lifecycle for Facility-Related Control Systems (FRCS).
Responsibilities
- Execute RMF Steps 1–6 in line with Department of the Navy and NAVFAC Echelon II guidance
- Develop, obtain, maintain, and track Authorities to Operate (ATOs) for Facility-Related Control Systems
- Create and maintain cybersecurity policies, Standard Operating Procedures (SOPs), implementation plans, and related RMF documentation
- Implement and evaluate security controls according to NIST SP 800-53 and applicable DoD requirements
- Perform vulnerability assessments using tools including ACAS, SCAP, Evaluate-STIG, and other approved assessment tools
- Conduct manual Security Technical Implementation Guide (STIG) and Security Requirements Guide (SRG) validations
- Develop, update, and maintain Plans of Action and Milestones (POA&Ms) in eMASS
- Support System-Level Continuous Monitoring (SLCM) and ongoing cybersecurity compliance activities
- Serve as Configuration Management Officer and participate in Configuration Control Board (CCB) activities
- Support cybersecurity incident response and participate in the MAR CERT on-call rotation
- Prepare and deliver bi-weekly RMF status reports to the Information Systems Security Manager (ISSM)
- Coordinate cybersecurity efforts across installations including Naval Base Guam, Marine Corps Base Camp Blaz, and Andersen Air Force Base
- Travel locally between supported installations as required
Requirements
- U.S. Citizenship required
- Active Top Secret eligibility based on a Tier 5 investigation, or ability to meet clearance requirements prior to start
- Minimum 5 years of professional Risk Management Framework (RMF) experience
- Minimum 1 year specialized experience supporting Facility-Related Control Systems (FRCS), Industrial Control Systems (ICS), or Operational Technology (OT) environments
- Experience with eMASS, ACAS, VRAM, Security Center, STIGs, SRGs, and cybersecurity vulnerability assessment tools
- Working knowledge of NIST SP 800-53, DoD cybersecurity requirements, and RMF processes
- Strong technical writing skills for cybersecurity policies, procedures, assessment documentation, and compliance reporting
- Ability to work independently and manage cybersecurity responsibilities with minimal supervision
- Ability to maintain required professional certifications throughout employment
- Must meet applicable DoD Manual 8140.03 Work Role 461 qualification requirements at the Intermediate or Advanced level
- Maintain certification status and complete continuing professional development requirements, including minimum 20 CPD hours annually when required
- Willing to relocate to or currently reside in Guam
- Reliable transportation for travel between supported installations
- Available for emergency response and on-call requirements
- On-site role: not eligible for remote work
Technologies
- Risk Management Framework (RMF)
- NIST SP 800-53
- ACAS
- SCAP
- Evaluate-STIG
- Security Technical Implementation Guide (STIG)
- Security Requirements Guide (SRG)
- eMASS
- Security Center
- VRAM
- Plans of Action and Milestones (POA&Ms)
- System-Level Continuous Monitoring (SLCM)
- Authorities to Operate (ATOs)
- DoD Manual 8140.03 Work Role 461
- CompTIA Security+
- CCSP
- CompTIA Cloud+
- GICSP
- GISF
- GSEC
- CISSP-ISSEP
- CompTIA CySA+
- GSNA
- GCSA
- GCLD
- CISSO
- FITSP-O
- RCCE Level 1
DoD 8140 Certification Requirements
- Candidates must meet applicable DoD Manual 8140.03 Work Role 461 qualification requirements at the Intermediate or Advanced level
- Examples of qualifying certifications may include:
- Intermediate: CompTIA Security+, CCSP, CompTIA Cloud+, GICSP, GISF, GSEC
- Advanced: CISSP-ISSEP, CompTIA CySA+, GSNA, GCSA, GCLD, CISSO, FITSP-O, RCCE Level 1
- Maintain required certification status and complete continuing professional development requirements, including minimum of 20 CPD hours annually, when required
Physical Requirements
- Ability to stand and walk for extended periods
- Ability to work on rough or uneven surfaces
- Ability to climb ladders and access equipment within industrial or facility environments
- Ability to lift and move IT or related equipment weighing up to 25 pounds
Benefits
- 401(k) matching
- Dental insurance
- Employee assistance program
- Health insurance
- Health savings account
- Paid time off
- Professional development assistance
- Relocation assistance
- Tuition reimbursement
- Vision insurance
Application
- Answer required: What is your desired salary?
Work Location: In person. Location: Guam, GU (onsite).