Information System Security Engineer

Cyber Defense Technologies
Lexington, KY, United States
12 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Android Software Development Apple IOS Signals Intelligence Cyber Security Information Systems Linux Graphics Software Information Security Management Networking Hardware Intrusion Detection and Prevention Log Analysis
+13 more
Microsoft Software Security Content Automation Protocol Software Vulnerability Management SC Clearance Information Technology Patch Management Nessus Nexpose Cyber Warfare Multiplatform Cisco Vulnerability Analysis Vmware

Job description

Overview: Cyber Defense Technologies (CDT) is seeking a proactive Information Systems Security Engineer (ISSE) to support Risk Management Framework (RMF) compliance, system hardening, and security engineering across a diverse portfolio of systems. This role requires independent ownership of complex security challenges- from vulnerability assessment and remediation through continuous monitoring-while ensuring alignment with DoW and USSOCOM security policies. You will bridge high-level security architecture with hands-on implementation across physical and virtual operating systems, networking devices, enterprise, embedded, and air-gapped environments., * Perform security design, configuration, hardening, testing, and monitoring of advanced information systems independently or as part of a team.

  • Conduct vulnerability testing and apply current compliance standards and technical controls across Windows, Linux, Android, iOS, and related platforms.
  • Support security architecture development; enforce trusted relationships with external systems; assess and mitigate security threats/risks throughout the program lifecycle.
  • Assist vendors and system developers in implementing DoW/USSOCOM security functionality and enterprise solutions.
  • Contribute to security planning, assessment, risk analysis, risk management, certification, and awareness activities.
  • Review Assessment & Authorization (A&A;) documentation for completeness and compliance.
  • Support rapid Fielding and Deployment Release processes by ensuring RMF and Authorization to Operate (ATO) requirements are met.
  • Create and maintain IA policy documentation and RMF artifacts, including System Security Plans (SSP), Security Assessment Reports, Risk Assessments, POA&Ms, Control Implementation/Validation documents, Ports/Protocols/Services matrices, network/architecture diagrams, and accreditation boundaries.
  • Execute cross-platform patch management and system imaging.
  • Map NIST 800-53 controls and DISA CCIs to system capabilities in support of ATO maintenance and renewals.
  • Engage customer technical points of contact as needed during architecture and implementation activities.

Requirements

Clearance Requirements: An active Secret clearance is required, TS/SCI preferred. All candidates must be U.S. Citizens. Applicants who do not meet these requirements will not be considered., * Experience with RMF process and requirements (NIST 800-53)

  • Experience with virtualized and standalone environments (VMware)
  • Experience with patch management solutions
  • Experience with standard forensic practices, imaging software, tools, and techniques
  • Experience with Security Technical Implementation Guide (STIG) experience
  • Experience with Vulnerability Management (Nessus, NexPose, OpenVAS, etc)
  • ELINT, Radio Frequency, Electronic Warfare, and/or SIGINT experience a plus
  • Translating technical customer requirements into business process and tasking
  • Technical consulting both buyer and end user customer personnel in a complex environment
  • System Administration experience with Linux and Windows
  • Experience with administration and forensic practices with mobile platforms is a plus, * Bachelor’s degree in Computer Science, Engineering, Information Technology, Cybersecurity, or related technical field; or work relevant work experience equivalent.
  • Minimum 4 years of information security-related experience in areas such as security operations, vulnerability management, security testing, system patching, log analysis, intrusion detection, or security device administration.
  • Knowledge of RMF, Windows/Linux operating systems, STIGs, ACAS, HBSS, and/or related technologies.
  • Demonstrated ability to work independently, analyze root causes, and drive solutions from identification through resolution.
  • U.S. Citizenship and active Secret clearance (or higher), clearable to TS/SCI., * Active DoD 8570 IAT Level II (or higher) certification preferred at time of hire (e.g., Security+ CE, CASP+, CISSP).
  • Hands-on experience with vulnerability assessment tools (ACAS, Nessus, SCAP), VMware, image deployment/orchestration, and multi-platform hardening.
  • Technology-specific certifications (Cisco, VMware, Microsoft, etc.) relevant to the environment.
  • Experience supporting rapid ATO processes and continuous monitoring in DoD/IC environments.

Travel: CONUS Travel of 10 to 15% may be required depending on program needs

Benefits & conditions

  • Competitive salary based. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on work experience, education, certifications, geographic location, contract wage determination that align with the specified role.
  • Comprehensive benefits package, including Health, Dental, Paid Time Off, Holiday Pay, Short-term and Long-term disabilities, Life Insurance, Retirement plans, Learning and Development opportunities, Wellness programs as well as other optional benefits elections. CDT is committed to hiring without regard to race, color, religion, creed, sex, sexual orientation, gender identity, marital status, national origin, age, veteran status, disability, or any other protected class.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

1:40 min

Managing containerized infrastructure with Podman Desktop

Cedric Clyburn Cedric Clyburn +1 · WWC 2025

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:41 min

Parallels between cloud and legacy infrastructure lock-ins

Björn Stahl Björn Stahl · WWC 2024

Videos

See all

Related articles

See all