Information Systems Security Engineer (ISSE) - TS/SCI with Polygraph
Job Description
General Dynamics Information Technology is seeking an accomplished Information Systems Security Engineer to join its on-site team in Herndon, Virginia. This role requires a TS/SCI clearance with Polygraph and centers on sustaining and renewing system security accreditations within RMF/A&A, leveraging tools such as Xacta, GreenLight, and Rapid7, while applying cloud-security design and implementation expertise.
Responsibilities
- Take ownership of critical national security outcomes by applying your expertise to protect the nation from threats.
- As an ISSE, contribute to keeping today secure while shaping a smarter tomorrow.
- Collaborate with Xacta, GreenLight, Rapid7 and onsite Information System Security Managers to sustain and renew system security accreditations.
- Balance multiple projects and guide applications smoothly through the accreditation lifecycle.
- Develop and review security concept of operations.
- Develop and review systems security plans.
- Develop and review security control assessments.
- Develop and review contingency plans.
- Develop and review configuration management plans.
- Develop and review incident response plans.
- Develop and review plan of actions and milestones.
- Develop and review risk management plans.
- Develop and review vulnerability scanning and vulnerability management plans.
- Documented experience with Xacta.
- Documented experience with GreenLight.
- Documented experience with RMF processes (Rev4 and Rev5).
- Cloud security design, requirements analysis, control implementation, and mitigation.
- Experience securing applications in cloud environments such as Amazon Web Services.
- A&A policy and guidance including ICD-503, FISMA and RMF/A&A processes.
- NIST SP 800-series controls (800-27, 800-30, 800-37, 800-53, 800-60, 800-137, 800-144, 800-145).
- FIPS 199 and 200.
- CNSSI 1253 technical controls.
- Developing and maintaining associated certification and accreditation documentation for systems.
- Performing security system scans for network, platform, database, and web services.
- Using security tools such as Nessus, Rapid7, Weblnspect, and AppDetective.
- Outstanding interpersonal skills and team player.
- Outstanding written and verbal communication skills; ability to present reports to management and work with developers and engineers to determine mitigations to vulnerabilities.
- Produce quality deliverables and complete assigned projects on time; provide consistent status updates to ensure IT security projects stay focused.
- Attention to detail; complete tasks per standard operating procedures; report anomalies and inconsistencies.
- Persistent and creative problem solver; strong troubleshooting; identify root cause and present solutions to management.
- Outstanding work ethic and a proven professional; respectful, dependable, takes initiative.
Requirements
- Experience with developing and reviewing security concept of operations
- Experience with developing and reviewing systems security plans
- Experience with developing and reviewing security control assessments
- Experience with developing and reviewing contingency plans
- Experience with developing and reviewing configuration management plans
- Experience with developing and reviewing incident response plans
- Experience with developing and reviewing plan of actions and milestones
- Experience with developing and reviewing risk management plans
- Experience with developing and reviewing vulnerability scanning
- Experience with developing and reviewing vulnerability management plans
- Documented experience with Xacta
- Documented experience with GreenLight
- Documented experience with RMF processes (Rev4 and Rev5)
- Cloud security design, requirements analysis, control implementation, and mitigation
- Experience securing applications in a cloud environment such as Amazon Web Services
- A&A policy and guidance including ICD-503, FISMA and RMF/A&A processes
- NIST SP (800-27, 800-30, 800-37, 800-53, 800-60, 800-137, 800-144, 800-145)
- FIPS (199, 200)
- CNSSI 1253 technical controls
- Developing and maintaining associated certification and accreditation documentation for systems
- Performing security system scans for network, platform, database, and web services
- Using security tools such as Nessus
- Using security tools such as Rapid7
- Using security tools such as Weblnspect
- Using security tools such as AppDetective
- Outstanding interpersonal skills and team player
- Outstanding written and verbal communication skills; ability to present reports to management
- Ability to work with developers and engineers to determine appropriate mitigations to vulnerabilities
- Produce quality deliverables and complete assigned projects on time; provide consistent status updates to ensure IT security projects stay focused
- Attention to detail; completes tasks per SOP; reports anomalies and inconsistencies
- Persistent and creative problem solver; strong troubleshooting; identify root cause and present solutions to management
- Outstanding work ethic and a proven professional; respectful, dependable, takes initiative
Technologies
- Xacta
- GreenLight
- Rapid7
- Nessus
- Weblnspect
- AppDetective
- Amazon Web Services (AWS)
- JIRA
Benefits
- 401K with company match
- Comprehensive health and wellness package
- Internal mobility team dedicated to helping you own your career
- Professional growth opportunities including paid education and certifications
- Cutting-edge technology you can learn from
- Rest and recharge with paid vacation and holidays
Work Requirements
- Years of Experience: 10+ years of related experience
- may vary based on technical training, certification(s), or degree
- Travel Required: None
- Citizenship: U.S. Citizenship Required
Salary and Benefit Information
The likely salary range for this position is $178,500 - $241,500. This is not a guarantee of compensation or salary. Salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.
Our Identity Verification Process
Identity verification relies on biometrics and artificial intelligence to prevent identity fraud. Virtual interviews require on-camera participation, and we may capture a photo to verify identity and deter fraud. By proceeding, you consent to the collection, processing, and use of biometric data for identity verification and security.
About Our Work
We are GDIT, a global technology and professional services firm delivering solutions and mission support to government agencies, defense, and intelligence communities. Our team of about 26,000 experts leverages technology to create tangible value and operates in more than 50 countries, offering capabilities in AI, cloud, cyber, and software development. Explore career opportunities and events by joining our Talent Community at gdit.com/tc. Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans.