Cybersecurity Engineer II

Information Systems Solutions
Charleston, SC, United States
18 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours

Tech stack

Cyber Security Information Systems Microsoft Security Essentials Software Vulnerability Management Information Technology Vulnerability Analysis

Job description

Information Systems Solutions, Inc, has an immediate opening for a Cybersecurity Engineer II to join our rapidly growing team. The Cybersecurity Engineer II will provide cyber services and solutions, technical support, and management support for ATC Division Programs (NPP)., Specific duties include, but are not limited to the following: · Support the Risk Management Framework process across the system lifecycle. · Prepare, update, and maintain authorization documentation, including System Security Plans, Standard Operating Procedures, Policies, and Plans of Action and Milestones. · Conduct Security Impact Analysis by identifying control gaps, security risks, and compliance issues, then recommend remediation actions. · Coordinate with system owners, engineers, ISSOs, assessors, and leadership to collect evidence and resolve findings. · Track remediation activities and validate closure of security weaknesses. · Support continuous monitoring activities, including control reviews, status reporting, and periodic updates. · Review vulnerability scan results and help align remediation efforts with compliance requirements. · Ensure systems meet applicable regulatory, contractual, and organizational security standards. · Assist with audit preparation, responses to assessors, and recurring compliance reviews. · Communicate risk posture, assessment results, and recommendations to stakeholders in clear business and technical terms.

Requirements

Clearance Level Secret

Certifications (IAT Level II) One of the following:

· Security+ CE

· GIAC Security Essentials Certification (GSEC)

· Security Certified Network Professional (SCNP)

· System Security Certified Practitioner (SSCP)

· SecurityX or CISSP (highly preferred)

Education:

· Bachelor’s degree in Cybersecurity, Computer Science, Electrical or Electronics Engineering

Required Skills:

  • Five (5) years or more of experience, to include:

A strong working knowledge of the Risk Management Framework (RMF), including relevant NIST requirements, and demonstrated experience developing and maintaining Assessment and Authorization (A&A) documentation. This includes System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Impact Analyses, and control traceability artifacts.

The role requires solid familiarity with continuous monitoring, security assessment processes, authorization lifecycle activities, Governance Risk and Compliance (GRC) platforms, vulnerability management, security scanning tools (such as ACAS), regulatory requirements, secure configuration baselines, Security Technical Implementation Guides (STIGs), and remediation tracking.

Candidates must also be able to evaluate technical implementations and effectively align security controls with operational, technical, and management requirements.

Desired Skills:

  • ACAS, eMASS or equivalent certification

Benefits & conditions

At ISS we pride ourselves on providing an employee-focused and family first environment. Being a small business, we take the time to get to know our employees and have a vested interest in helping them achieve their career goals. We work to schedule regular social gatherings within the company to foster camaraderie. ISS values their employees by providing a comprehensive benefits package that includes a fully vested 401(k) matching program, coverage of family medical deductibles, spot bonuses, and educational assistance to further your career.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

2:14 min

Establishing legal admissibility through immutable blockchain attestations

Frederik Gregaard Frederik Gregaard +1 · WWC Europe 2026

4:27 min

Aligning enterprise workflows to support continuous software delivery

Katrin Lehmann Katrin Lehmann +1 · WWC 2025

Videos

See all

Related articles

See all