Information Systems Security Engineer (ISSE)
Job Description
Grow your security engineering impact supporting RMF compliance through Assessment and Authorization (A&A) and Continuous Monitoring (ConMon) activities across multi-level classification environments. This onsite role at Fort Belvoir, VA pairs critical security engineering work with access to cutting-edge technologies and a team that coordinates across cybersecurity, technical services, and customer stakeholders.
Compensation for this position is USD 107,950 - 146,050 per year. The role is Secret clearance required and requires U.S. citizenship, with less than 10% travel.
What you’ll do
- Coordinate with other DSMS program teams to plan and create cybersecurity architecture and design documents, ensuring compliance with DoD and other organizational IA policies and guidance.
- Apply best practices for implementing security controls within an IS using software engineering methodologies, system/security engineering principles, secure design and architecture, and secure coding techniques.
- Develop cybersecurity architecture and design plans for communication and collaboration products, operating system platforms (servers, devices, and management products), applications, and security considerations for product implementation.
- Provide security engineering support for DSMS Network accreditation.
- Integrate cybersecurity expertise into lifecycle management, including planning architecture and design management, migration and deployment, and system testing and implementation.
- Research, develop, test, and document architectures and solutions for implementing new cybersecurity technologies to improve information collaboration and cybersecurity capabilities for the program and its user base.
- Develop and deliver criticality analysis for logic-bearing system components (hardware, firmware, and software) and the functions they implement, protect, or that may introduce vulnerabilities.
- Develop and maintain mission criticality analyses, vulnerability assessments, and risk assessments, including identification and countermeasure implementation for mission-critical functions, ensuring updated assumptions, rationale, results, supply chain risk information, and mitigations are available for Government review.
- Prepare and submit Interim Authorization to Test (IATT) and Authority to Operate (ATO) requests with Plans of Action and Milestones (PoAMs).
- Develop, maintain, and coordinate Body of Evidence (BoE) documentation for system assets.
- Collaborate with Technical Services and Security Services teams, plus customer agency stakeholders, to support compliance.
- Track lien remediation/resolution workflow and enter tracking tool updates; evaluate system change requests and assess both system and organizational risks tied to modifications.
- Execute ConMon activities on established timelines, including BoE collection and tracking tool updates.
- Conduct recurring reviews of system state and security posture to ensure secure operation and that information systems security policies and procedures are followed.
- Recommend security control implementation and identify countermeasures or mitigating controls; respond to security information queries and report requests.
- Support security incident investigations and report findings as needed.
- Assist with communication, implementation, and enforcement of security policies and plans for data, applications, hardware, and telecommunications systems.
- Advise stakeholders on information assurance standards, dependencies, and emerging security technologies; use Enterprise Security Services tools such as Trellix and ACAS to track and remediate vulnerabilities and compliance deficiencies.
What you’ll need
- Bachelor of Arts / Bachelor of Science
- 2+ years of related experience
- Secret security clearance level
- U.S. citizenship required
- Travel: less than 10%
Tools and technologies
- Trellix
- ACAS
- Plans of Action and Milestones (PoAMs)
- Body of Evidence (BoE)
Benefits and growth
- 401K with company match
- Comprehensive health and wellness packages
- Internal mobility team dedicated to helping you own your career
- Professional growth opportunities, including paid education and certifications
- Cutting-edge technology you can learn from and apply to solve real world problems
Additional details
- Location: Fort Belvoir, Virginia (onsite / on customer site)
- REQ#: RQ229469
- Requisition type: Regular
- Category: Cyber and IT Risk Management
- Public trust: None
- Work requirements: U.S. Citizenship Required; Travel Required: less than 10%
Identity verification process
- You are expected to be on camera during virtual interviews.
- We reserve the right to take your picture to verify your identity and prevent fraud.
- You authorize the collection, processing, and use of your biometric data for identity verification and security purposes.