> Markdown version of [/jobs/ext/1205960-senior-information-systems-security-engineer-isse](https://www.wearedevelopers.com/jobs/ext/1205960-senior-information-systems-security-engineer-isse). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Systems Security Engineer (ISSE) - **Company:** Applied Research Solutions - **Location:** Arlington, DC, United States - **Experience:** Expert - **Salary:** $178,000.0 - $198,000.0 - **Contract:** Permanent contract - **Skills:** Ubuntu (Operating System), Cloud Engineering, Code Review, Cyber Security, Information Systems, Linux, Document Management Systems, Disaster Recovery, Network Architecture, Systems Development Life Cycle, Security Content Automation Protocol, Software Requirements Analysis, Information Technology, Tenable Nessus, Nessus, Devsecops - **Published:** July 8, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9017916/senior-information-systems-security-engineer-isse ## About the Role * Must be a US citizen * BA/BS Degree, and 15 years of Cyber-Security experience and 5 years DoD experience or; MA/MS Degree and 12-year experience, 5 years in DoD or; 20 years of directly related experience with proper certifications of which 8 years are in DoD * DoD 8570.01 MMGT512 compliant certification. * Experience with the Risk Management Framework (RMF). * Active Top Secret Security Clearance The expected annual salary range: $178k - $198k. Salary is dependent upon the role and associated responsibilities, candidate's experience, and qualifications to include education/training, and key skills. All positions at Applied Research Solutions are subject to background investigations. Employment is contingent upon successful completion of a background investigation including criminal history and identity check. ## Description * Support the system/application authorization and accreditation (A&A) effort for weapon systems and PIT Systems, to include assessing and guiding the quality and completeness of A&A activities, tasks, and resulting artifacts mandated by governing DoD and Air Force policies (i.e., Risk Management Framework (RMF). Understanding of how RMF intersects with the acquisition process and how it's used to generate requirements; how RMF and Cybersecurity should be covered in contracts - requirements, deliverables, PWS/SOW language. Understanding how to work through RMF and controls with a program to establish appropriate levels of risk based on program lifecycle and mission requirements. * Recommend policies and procedures to ensure the reliability of and accessibility to information systems and to prevent and defend against unauthorized access to systems, networks, and data. * Develop, execute, and track the performance of security measures to protect information and network infrastructure and computer systems. * Review and assess architectures and recommend cybersecurity strategies to developmental and legacy system designs. * Assess threats to determine impact and recommend corrective actions to program managers to reduce risk. * Translate program/system requirements into technical requirements and architectures needed to meet program objectives. * Life cycle development Promote awareness of security issues among management and ensuring sound security principles are reflected in program's' visions and goals. Participate in systems design. * Understanding of DevSecOps environments to check for security flaws and vulnerabilities during code review. * Understanding of operating systems including Linux, Ubuntu, IoT systems, ZTA environments and Cloud development. * Identify, define, and document system security requirements and recommend solutions to management. * Plan, develop, implement, and update Cyber Security Strategy Information within the Program Protection Plan (PPP) and assess CPI (Critical Program Information) and CC (Critical Components) analysis. * Recommend and review Tempest requirements, systems security contingency plans and disaster recovery procedures. * Experience with compliance and vulnerability and software scanning tools (STIGs, Nessus, ACAS, SCC/ SCAP, etc.) to include the review and creation of mitigation reports. * Review the Vendor submitted Contract Data Requirement List (CDRL) items for Cybersecurity related areas, to ensure technical requirements have been met, and provided substantial comments and recommendations to the Program Management (PM) team as to adequacy of the CDRL. * Other duties as assigned. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [SRE Methods In an Agency Environment](https://www.wearedevelopers.com/videos/348-sre-methods-in-an-agency-environment) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [How Much Does a Software Engineer Make? Realistic Software Engineering Salaries](https://www.wearedevelopers.com/magazine/425-how-much-does-a-software-engineer-make-realistic-software-engineering-salaries) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk)