> Markdown version of [/jobs/ext/1502430-principal-information-systems-security-engineer-isse](https://www.wearedevelopers.com/jobs/ext/1502430-principal-information-systems-security-engineer-isse). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Information Systems Security Engineer (ISSE) - **Company:** KBR Inc - **Location:** Dayton, OH, United States - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Package Development Process, Fortify (Software), Webinspect, Information Technology, Vulnerability Analysis - **Published:** July 30, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3336314464&tx=IT9184THV&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Bachelor's Degree and fifteen (15) years of experience with Cybersecurity / Information Technology, or in lieu of a degree eighteen (18) years of hands-on experience with Cybersecurity / Information Technology * An active TS/SCI clearance is required * Must have experience working with Special Access Programs (SAPs) * DoD 8570-compliant * Demonstrated expert-level experience with Risk Management Framework * RMF policy development, process improvement, and strategy implementation * Demonstrated expert-level experience with DISA STIGs and SRGs * Demonstrated efficiency and expert-level experience in RMF package development, including POA&Ms (mitigation statements), Security Plans, Risk Assessments, architecture diagrams, asset inventories, and system/site policies, procedures, and processes * Experience with Assured Compliance Assessment Solution (ACAS) * Experience in assessing systems using NIST 800-53, DISA STIGs/SRGs, and ACAS * Deep familiarity and experience with the DoW tool eMASS * Experience working within DoW (experience under DHA a plus) * Excellent customer service and organization skills * Excellent oral and written communication skills * Familiarity with NIST publications, * Experience working under DHA * Experience with HBSS * Knowledge in Continuous Monitoring and Risk Scoring (CMRS) * Experience with Fortify, WebInspect, and/or AppDetective Ready to Make a Difference? ## Description The selected candidate will serve in a Senior ISSE role and perform tasks related to Assessment & Authorization (A&A) and cybersecurity under Direct Hire Authority (DHA) to obtain and maintain Authorizations to Operate (ATOs) for assigned DoD medical systems (i.e., applications, networks, devices)., * Support team in a Senior ISSE capacity for multiple information systems * Serve as Subject Matter Expert (SME) on one or more technologies/skills related to A&A activities * Conduct risk and vulnerability assessments of information systems to identify vulnerabilities, risks, and protection needs * Provide solutions to complex problems that require the regular use of expertise and creativity. Problems are broadly defined and solutions require the continuation of specialized theories and knowledge * Actively lead and participate in regular A&A status meetings with senior government and contract personnel to facilitate progress and address potential issues of RMF system efforts * Participate in sessions aimed at identifying, planning, and executing strategies in response to emerging cybersecurity/RMF policies * Maintain awareness and knowledge of evolving security and risk management standards and communicate and apply relevant changes to existing processes * Lead and/or attend meetings with SDD stakeholders to discuss statuses of efforts * Assess system compliance against NIST, DoW, and DHA security requirements to include the NIST 800-53 controls, DISA Security Technical Implementation Guides (STIGs), and DISA Security Requirements Guides (SRGs) * Produce evidence as necessary to support compliance status of NIST, DoW, and DHA security requirements * Analyze vulnerability scans of information systems and assist in remediation tasks * Submit weekly reports to DHA leadership regarding system/program status * Develop, update, and/or review RMF documentation to include Security Plans, Implementation Plans, Plans of Action and Milestones (POA&Ms), and Risk Assessment Reports * Coordinate with other system SMEs to identify and develop authorization boundary diagrams, architecture diagrams, and hardware and software inventories ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Times of (climate) crisis - How and why sustainable software is a must!](https://www.wearedevelopers.com/videos/988-times-of-climate-crisis-how-and-why-sustainable-software-is-a-must) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [Is Software Engineering Hard?](https://www.wearedevelopers.com/magazine/448-is-software-engineering-hard)