Information Systems Security Engineer

B.R.S. Inc.
Bethesda, MD, United States
19 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Starter
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Systems Engineering Collaborative Software Cyber Security Information Security Management Microsoft Office SARS Software Products Information Technology

Job description

VGS is seeking a Junior Information System Security Engineer (ISSE) to support our ongoing mission in San Antonio, TX. The Junior Information System Security Engineer (ISSE) provides cybersecurity engineering and Risk Management Framework (RMF) support to accelerate the University’s security compliance and modernization initiatives. During the initial three-month performance period, the ISSE shall provide dedicated surge support to transition security controls from NIST SP 800-53 Revision 4 to Revision 5 and prepare associated evidence for review within eMASS. Upon completion of the surge effort, the ISSE shall transition to supporting Assessment and Authorization (A&A) activities for academic systems, assisting in the development of accreditation packages and modernization efforts. The position works under the guidance of senior cybersecurity personnel while collaborating with system owners, administrators, developers, and government stakeholders to support timely and compliant authorization activities., * Review assigned security controls and supporting documentation to facilitate transition from NIST SP 800-53 Revision 4 to Revision 5 requirements.

  • Update control implementation statements and associated documentation to align with Revision 5 requirements.
  • Develop, collect, organize, and validate supporting Body of Evidence (BoE) artifacts.
  • Upload and maintain required evidence and documentation within the Enterprise Mission Assurance Support Service (eMASS).
  • Coordinate with ISSOs, system administrators, system owners, and government personnel to resolve documentation gaps and obtain required evidence.
  • Track assigned controls and provide status updates regarding completion progress, outstanding issues, and dependencies.
  • Identify deficiencies requiring escalation and recommend corrective actions.
  • Ensure assigned controls are prepared and submitted in a complete and audit-ready condition.
  • Support government reviews and respond to requests for clarification or additional evidence.
  • Assist in conducting RMF Assessment and Authorization (A&A) analyses for academic applications, products, and supporting technologies.
  • Support development and maintenance of accreditation artifacts, including:

System Security Plans (SSPs); Security Assessment Plans (SAPs); Security Assessment Reports (SARs); Plans of Action and Milestones (POA&Ms); Security Categorization documentation; Continuous Monitoring documentation; Control implementation narratives; Authorization recommendation packages; and Supporting Body of Evidence (BoE).

  • Coordinate with technical teams and stakeholders to gather information necessary to support authorization activities.
  • Assist in assessing security control implementation and documenting findings.
  • Track assigned systems and support completion of authorization milestones.
  • Participate in meetings and working sessions supporting accreditation efforts.
  • Support audits and responses to requests for evidence or documentation.
  • Assist senior ISSE personnel in identifying opportunities to improve authorization workflows and streamline documentation processes.
  • Contribute to development of recommendations intended to accelerate future modernization and authorization activities.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Assurance, Computer Science, Engineering, Information Technology, or a related discipline.
  • Two (2) years of experience supporting cybersecurity, RMF, information assurance, compliance, or systems engineering activities.
  • Familiarity with NIST Risk Management Framework concepts and federal cybersecurity requirements.
  • Working knowledge of:

NIST SP 800-53 security controls; Security documentation practices; Basic RMF principles under NIST SP 800-37; and Microsoft Office applications and collaboration tools.

  • Familiarity with eMASS or the demonstrated ability to learn governance, risk, and compliance platforms quickly.
  • Active DoD 8570/8140 certification, such as Security+ or equivalent.
  • Ability to obtain and maintain required government access.

Desired Qualifications

  • Experience supporting higher education, healthcare, or research environments.
  • Exposure to Authority to Operate (ATO) or accreditation activities.
  • Experience collecting and organizing technical evidence for compliance initiatives.
  • Familiarity with eMASS.
  • Knowledge of continuous monitoring concepts and documentation requirements.
  • Strong organizational and analytical skills.
  • Effective written and verbal communication skills.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:08 min

Introduction to speakers and model-based systems engineering goals

Daniel Siegl +1 · LIVE

2:12 min

Empowering enterprise engineering through open source program offices

Cédric Gégout Cédric Gégout +4 · WWC Europe 2026

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:09 min

Balancing data science skillings alongside systems engineering rigor

Nico Schmidt · LIVE

5:05 min

Bridging the gap to production systems engineering

Luca Palmieri · LIVE

Videos

See all

Related articles

See all