Information Systems Security Engineer (ISSE), Journeyman
Job Description
The Information Systems Security Engineer (ISSE) designs, implements, and manages security solutions for information systems in a hybrid Arlington, VA environment, ensuring compliance with security standards and conducting risk assessments. Compensation ranges from USD 100,000 to 150,000 per year.
Responsibilities
- Security architecture design and deployment for information systems, covering hardware, software, and network components.
- Identify security risks, assess potential impact, develop mitigation strategies, and apply security controls to address vulnerabilities.
- Ensure systems align with applicable security policies, regulations, and standards such as NIST, RMF, and ICD 503.
- Perform vulnerability scans, interpret findings, and recommend remediation actions.
- Create and maintain security documentation, including system security plans, security assessment reports, and risk management plans.
- Collaborate with system administrators, network engineers, software developers, and other stakeholders to integrate security throughout the system development lifecycle.
- Participate in continuous monitoring activities to maintain security posture and compliance.
- Contribute to incident response efforts, including investigating security incidents, analyzing malware, and supporting forensic analysis.
Requirements
- Bachelor's degree and/or 2 to 5 years of experience.
- Active TS/SCI clearance with polygraph required.
- Strong knowledge of security principles, technologies, and best practices.
- Experience applying the Risk Management Framework (RMF) to information systems.
- Understanding of secure system design principles and experience developing secure architectures.
- Knowledge of various security controls and their implementation.
- Experience with vulnerability scanning tools and techniques.
- Ability to create and maintain security documentation.
- Excellent verbal and written communication skills to collaborate with diverse teams.
- Strong analytical and problem-solving abilities to address complex security challenges.
- Relevant certifications such as CISSP, CISM, CAP, or other equivalent security credentials.
Technologies
- RMF
- NIST
- ICD 503
Benefits
- Competitive compensation
- Comprehensive insurance options
- Matching contributions through the 401(k) plan and the share purchase plan
- Paid time off for vacation, holidays, and sick time
- Paid parental leave
- Learning opportunities and tuition assistance
- Wellness and Well-being programs