Information Systems Security Engineer Level 3 (Government)
Job Description
The Information Systems Security Engineer Level 3 role supports government programs by providing expert technical guidance and evaluating security assessments to identify vulnerabilities and non-compliance. This is a full-time, onsite position based in Columbia, Maryland, working five days per week (40 hours per week).
Role Overview
In this position, you will help ensure that system architectures are both functional and secure across program-of-record systems, new and proposed systems, and special purpose environments with platform IT interconnectivity. You will also recommend mitigation strategies for secure networking, computing, and enclave environments, and contribute to prevention and early detection and resolution of risks to high value assets.
Core Responsibilities
- Provide expert guidance and evaluate security engineering work products supporting engineering teams across the design, development, implementation, evaluation, and integration of secure networking, computing, and enclave environments.
- Recommend system-level solutions for the secure development and maintenance of systems.
- Advocate and monitor improvement to IA policy while coordinating with customers, IT staff, and high-level corporate officers to define and achieve required IA objectives.
- Ensure security and architecture requirements are addressed for information systems, including platform IT interconnectivity across relevant environments.
- Support prevention and early detection and resolution of risks to high value assets.
- Architect, design, implement, support, and evaluate security-focused tools and services.
- Provide software vulnerability remediation advice to software developers and software development teams.
- Implement security vulnerability testing tools for continuous monitoring and patch verification.
- Test and evaluate products in a lab environment.
- Review certification and accreditation (C&A) documentation and provide feedback on completeness and compliance.
- Apply knowledge of 800-53 controls by testing information systems for compliance and creating test cases.
- Use knowledge of incident response to create, execute, and report incident response activities.
- Apply knowledge of network security technologies including Firewalls, IDS/IPS, intrusion detection, VLANS, routing, and related capabilities.
- Apply knowledge of virtualization technologies such as virtual firewalls, networking, and segmentation.
- Apply knowledge of SIEM technologies such as Splunk and create security event related dashboards.
- Apply knowledge of malware identification, containment, and eradication.
- Apply knowledge of access control systems including PKI, multi-factor authentication, and entitlements management.
- Demonstrate proficiency with Microsoft Windows and Linux.
- Provide input into development of security policies and procedures.
- Evaluate and recommend new and emerging security products and technologies.
- Participate in projects that develop new intellectual property.
- Demonstrate strong written and verbal communication, along with leadership and teamwork skills.
- Support security advocacy within the organization to support customer trust.
Required Education and Experience
- TS/SCI with polygraph clearance is required.
- 20 years of experience as an ISSE on programs and contracts of similar scope, type, and complexity are required.
- Bachelor’s degree in Computer Science, Information Assurance, Information Security System Engineering, or a related discipline from an accredited college or university is required.
- A Master’s degree in a related field may be substituted for two (2) years of experience, reducing the requirement to 18 years.
- Four (4) years of additional ISSE experience may be substituted for a Bachelor’s degree.
- DoD 8570 compliance with IASAE Level 2 is required.
Security Technologies and Tools
- 800-53
- Firewalls
- IDS/IPS
- VLANS
- SIEM technologies such as Splunk
- Virtual firewalls
- Virtualization technologies
- Microsoft Windows and Linux
- PKI, multi-factor authentication
- Access control and entitlements management
Compensation and Employment Details
- Pay range: USD 118,700 - 243,300 per year
- Employment type: Full-time (Regular)
- Schedule: 40 hours per week
- Location: Columbia, Maryland (onsite)
Individual starting salary within the range may depend on geography, experience, expertise, and education/training.
Benefits
- Medical/Dental/Vision coverage
- 401(k) plan
- Tuition reimbursement program
- Paid Time Off and Holidays: based on date of hire, at least 23 days of vacation each year and 9 company-designated holidays (pro-rated when working less than 40 hrs/wk)
- Paid Parental Leave
- Paid Caregiver Leave
- Disability Benefits (short term and long term)
- Life and Accidental Death Insurance
- Supplemental benefit programs: critical illness/accident hospital indemnity/group legal
- Employee Assistance Programs (EAP)
- Extensive employee wellness programs
- Employee discounts up to 50% off on eligible AT&T mobility plans and accessories, AT&T internet (and fiber where available), and AT&T wireline phone