> Markdown version of [/jobs/ext/1426920-information-systems-security-engineer](https://www.wearedevelopers.com/jobs/ext/1426920-information-systems-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Engineer - **Company:** B.R.S. Inc. - **Location:** Bethesda, MD, United States - **Experience:** Starter - **Contract:** Permanent contract - **Skills:** Systems Engineering, Collaborative Software, Cyber Security, Information Security Management, Microsoft Office, SARS Software Products, Information Technology - **Published:** July 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=90c8a3e792621579 ## About the Role * Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Engineering, Information Technology, or a related discipline. * Two (2) years of experience supporting cybersecurity, RMF, information assurance, compliance, or systems engineering activities. * Familiarity with NIST Risk Management Framework concepts and federal cybersecurity requirements. * Working knowledge of: NIST SP 800-53 security controls; Security documentation practices; Basic RMF principles under NIST SP 800-37; and Microsoft Office applications and collaboration tools. * Familiarity with eMASS or the demonstrated ability to learn governance, risk, and compliance platforms quickly. * Active DoD 8570/8140 certification, such as Security+ or equivalent. * Ability to obtain and maintain required government access. Desired Qualifications * Experience supporting higher education, healthcare, or research environments. * Exposure to Authority to Operate (ATO) or accreditation activities. * Experience collecting and organizing technical evidence for compliance initiatives. * Familiarity with eMASS. * Knowledge of continuous monitoring concepts and documentation requirements. * Strong organizational and analytical skills. * Effective written and verbal communication skills. ## Description VGS is seeking a Junior Information System Security Engineer (ISSE) to support our ongoing mission in San Antonio, TX. The Junior Information System Security Engineer (ISSE) provides cybersecurity engineering and Risk Management Framework (RMF) support to accelerate the University's security compliance and modernization initiatives. During the initial three-month performance period, the ISSE shall provide dedicated surge support to transition security controls from NIST SP 800-53 Revision 4 to Revision 5 and prepare associated evidence for review within eMASS. Upon completion of the surge effort, the ISSE shall transition to supporting Assessment and Authorization (A&A) activities for academic systems, assisting in the development of accreditation packages and modernization efforts. The position works under the guidance of senior cybersecurity personnel while collaborating with system owners, administrators, developers, and government stakeholders to support timely and compliant authorization activities., * Review assigned security controls and supporting documentation to facilitate transition from NIST SP 800-53 Revision 4 to Revision 5 requirements. * Update control implementation statements and associated documentation to align with Revision 5 requirements. * Develop, collect, organize, and validate supporting Body of Evidence (BoE) artifacts. * Upload and maintain required evidence and documentation within the Enterprise Mission Assurance Support Service (eMASS). * Coordinate with ISSOs, system administrators, system owners, and government personnel to resolve documentation gaps and obtain required evidence. * Track assigned controls and provide status updates regarding completion progress, outstanding issues, and dependencies. * Identify deficiencies requiring escalation and recommend corrective actions. * Ensure assigned controls are prepared and submitted in a complete and audit-ready condition. * Support government reviews and respond to requests for clarification or additional evidence. * Assist in conducting RMF Assessment and Authorization (A&A) analyses for academic applications, products, and supporting technologies. * Support development and maintenance of accreditation artifacts, including: System Security Plans (SSPs); Security Assessment Plans (SAPs); Security Assessment Reports (SARs); Plans of Action and Milestones (POA&Ms); Security Categorization documentation; Continuous Monitoring documentation; Control implementation narratives; Authorization recommendation packages; and Supporting Body of Evidence (BoE). * Coordinate with technical teams and stakeholders to gather information necessary to support authorization activities. * Assist in assessing security control implementation and documenting findings. * Track assigned systems and support completion of authorization milestones. * Participate in meetings and working sessions supporting accreditation efforts. * Support audits and responses to requests for evidence or documentation. * Assist senior ISSE personnel in identifying opportunities to improve authorization workflows and streamline documentation processes. * Contribute to development of recommendations intended to accelerate future modernization and authorization activities. ## Related Videos - [Model Based Systems Engineering in an Agile Product Development Process](https://www.wearedevelopers.com/videos/68-model-based-systems-engineering-in-an-agile-product-development-process) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Automated Driving - Why is it so hard to introduce](https://www.wearedevelopers.com/videos/628-automated-driving-why-is-it-so-hard-to-introduce) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What is Software Engineering?](https://www.wearedevelopers.com/magazine/289-what-is-software-engineering) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Software Engineer Career: Things You Should Know](https://www.wearedevelopers.com/magazine/143-software-engineer-career-things-you-should-know) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)