Senior Cybersecurity Engineer - RMF/ISSE Lead
Job Description
The Senior Cybersecurity Engineer - RMF/ISSE Lead will support and strengthen the security posture for a division’s family of Electronic Warfare systems. This onsite role in Sterling, VA focuses on leading RMF execution, guiding systems through Authorization to Operate (ATO), and managing a small team of Security Engineers across the system lifecycle.
Role Overview
Lead the security engineering effort for Electronic Warfare systems by executing Risk Management Framework (RMF) activities across Steps 1 through 6. Serve in ISSO/ISSE capacity to guide systems from initial categorization to ATO, while ensuring Assessment & Authorization (A&A) documentation and continuous monitoring support ongoing compliance.
Key Responsibilities
- Lead, mentor, and manage a team of 3-5 Security Engineers.
- Oversee project timelines and ensure delivery of high-quality security solutions; conduct performance evaluations and support ongoing professional development.
- Direct the design and documentation of secure system architectures spanning web applications, application stacks, Web Application Firewalls (WAFs), and Intrusion Detection/Prevention Sensors (IDS/IPS).
- Manage secure architecture activities that include antimalware technologies and Advanced Persistent Threat (APT) prevention.
- Define security requirements and integrate security capabilities across all SDLC phases (initiation, acquisition/development, implementation, operations/maintenance, disposition) following NIST 800-64 Rev. 2 guidance.
- Execute RMF activities (Steps 1-6) and perform ISSO/ISSE functions to support progress through ATO.
- Direct team efforts supporting DoD or IC acquisition programs resulting in IATT and/or ATO.
- Develop, maintain, and review A&A documentation using Xacta, eMASS, or equivalent tools, including SSP, SCTM, and BoE.
- Ensure hardware and software meet Government Security Certification Officer (SCO) requirements and align with NIST SP 800-53, ICD 503, and CNSSI 1253 standards.
- Implement continuous monitoring (ConMon) and lead security audits using IC and DoD approved scanning tools, including Nessus/ACAS, SCAP/SCC, STIG Viewer, Nmap, and additional vulnerability assessment platforms.
- Direct incident response activities and participate in an on-call rotation for security incidents.
Required Qualifications
- Bachelor’s degree in computer science, Cybersecurity, Engineering, Information Technology, or related field (or equivalent experience).
- 10+ years with demonstrated ISSE/ISSO responsibilities, preferably within the Intelligence Community or DoD.
- Experience achieving IATT and/or ATO on DoD or IC acquisition programs.
- People management or team leadership experience.
- Current active TS/SCI eligibility.
- DoD 8570/8140 IASAE Level III (e.g., CISSP).
- Familiarity with RMF processes and NIST SP 800-53 and NIST 800-64 Rev. 2.
- Experience integrating security across the full SDLC: initiation, acquisition/development, implementation, operations/maintenance, and disposition.
- Working knowledge of network protocols (TCP/IP, DNS, HTTP/HTTPS), VPNs, IDS/IPS, firewalls, and DMZ configurations.
- Hands-on Linux/Unix experience.
- Experience with web applications, application stacks, WAFs, and application-layer security controls.
- A&A tracking tools experience including Xacta or eMASS, and SCAP/SCC, plus vulnerability assessment tools such as Nessus, ACAS, and additional platforms.
Technologies and Tools
- Risk Management Framework (RMF), NIST 800-64 Rev. 2, NIST SP 800-53, ICD 503, CNSSI 1253
- ISSO, ISSE, IATT, Authorization to Operate (ATO)
- Xacta, eMASS, SSP, SCTM, BoE
- Nessus/ACAS, SCAP/SCC, STIG Viewer, Nmap, Linux/Unix
- TCP/IP, DNS, HTTP/HTTPS, VPNs, IDS/IPS, firewalls, DMZ configurations
- Web Application Firewalls (WAFs), web applications, antimalware technologies, Advanced Persistent Threat (APT) prevention
Benefits
- Flexible time off benefit
- Robust learning resources
- Healthcare
- Wellness
- Financial benefits
- Retirement
- Family support
- Continuing education
- Time off benefits
Incident Response
- Direct incident response activities and participate in an on-call rotation for security incidents.
Clearance and Certifications
- Current active TS/SCI eligibility
- DoD 8570/8140 IASAE Level III (e.g., CISSP)
Travel Requirements
- Percentage of Travel Required: Up to 10%
- Type of Travel: Local
Compensation
Salary range: USD 103,800 - 218,100 per year.