Information Systems Security Engineer (ISSE) - Journeyman

Goldbelt
Mechanicsburg, United States of America
30 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English
Experience level
Intermediate

Job location

Mechanicsburg, United States of America

Tech stack

Systems Engineering
Computer Security
Information Technology

Job description

The Information Systems Security Engineer (ISSE) - Journeyman supports the design, implementation, and maintenance of cybersecurity architecture for systems and enclaves. This role focuses on executing RMF activities, supporting security control implementation, and assisting with system authorization efforts., * Support the development and maintenance of system cybersecurity architecture and solutions

  • Assist in identifying Authorizing Official (AO) and Security Control Assessor (SCA) cognizance and applicable authorization requirements (e.g., reciprocity, cross domain, overlays)
  • Help identify and tailor security control baselines in accordance with system categorization
  • Support development, maintenance, and tracking of the System Security Plan (SSP)
  • Assist in implementing and testing security controls
  • Perform vulnerability-level risk assessments and support POA&M/CAP tracking
  • Support execution of required security testing for Authorization & Accreditation (A&A) and annual reviews
  • Assist in preparing Security Assessment Plans (SAPs) with program support
  • Support mitigation and closure of vulnerabilities through change control processes
  • Execute cybersecurity testing to assess security controls and document compliance status
  • Ensure accurate data entry into eMASS and alignment with implementation results
  • Maintain traceability of vulnerabilities from assessment results to POA&M entries
  • Support development of the Security Assessment Report (SAR) and associated documentation
  • Utilize the eMASS Collaboration Board for RMF coordination and document findings in the Artifacts repository
  • Participate in system engineering activities to ensure cybersecurity requirements are integrated throughout the lifecycle

Qualifications

Necessary Skills and Knowledge:

  • Familiarity with RMF, NIST 800-53 controls, and DoD cybersecurity policies

Requirements

  • Minimum 2 years of experience of the following:
  • Experience in documenting RMF Assessment and Authorization requirements.
  • Experience in RMF testing of all CS requirements and analysis required to complete an RMF package document for submittal and approval.
  • Experience performing vulnerability risk analysis on the deficiencies found during RMF testing.
  • Must be able to supply total number of RMF authorizations performed.
  • Experience with IA tools and scanners used to evaluate the security posture of the system/enclave.
  • Experience with DoD-specific, DoN-specific, and NAVSUP-specific RMF services (including RMF package services) and using and complying with the Navy RMF Process Guide version 4.1 (or 4.0 or the latest version) and the NAVSUP FAO RMF Business Rules version 1.0 (or latest version).
  • Experience with concurrently supporting over 10 RMF packages.
  • Must have a Tier III Level Clearance

Preferred Qualifications:

  • Bachelor's degree in Cybersecurity, Information Technology, Engineering, or related field

Benefits & conditions

At Goldbelt, we value and reward our team's dedication and hard work. We provide a competitive base salary commensurate with your qualifications and experience. As an employee, you'll enjoy a comprehensive benefits package, including medical, dental, and vision insurance, a 401(k) plan with company matching, tax-deferred savings options, supplementary benefits, paid time off, and professional development opportunities.

Apply for this position