> Markdown version of [/jobs/ext/1794139-senior-information-systems-security-engineer](https://www.wearedevelopers.com/jobs/ext/1794139-senior-information-systems-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Systems Security Engineer - **Company:** Parsons Corporation - **Location:** Boulder, CO, United States - **Experience:** Expert - **Salary:** $112,200.0 - $196,400.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Agile Methodology, Systems Engineering, Cyber Security, Information Systems, Scrum Methodology, Systems Development Life Cycle, Red Hat Enterprise Linux, Ansible, Symantec, Kubernetes, Infrastructure Automation Frameworks, Nessus, CIS Benchmarks, National Industrial Security Program Operating Manual (NISPOM), Puppet, Docker, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 15, 2026 - **Apply:** https://parsons.wd5.myworkdayjobs.com/Search/job/US---CO-Boulder/Senior-Information-Systems-Security-Engineer_R183330 ## About the Role * Active DoD Top Secret security clearance, with the ability and willingness to obtain SCI access. * 5+ years of relevant experience with additional education able to count towards years of experience * Bachelors degree, but additional years of experience can count in lieu of a degree. * Security+ Certification Required What Desired Skills You Might Bring: * Familiarity with NISPOM and Risk Management Framework * Ability to identify system design and operational vulnerabilities, and make recommendations to address security deficient areas * Active TS/SCI Security Clearance * Demonstrated knowledge of infrastructure automation and provisioning (e.g. Chef, Puppet, Ansible, etc.) * Demonstrated knowledge of containerized virtualization deployment and orchestration (e.g. Docker, Kubernetes, etc.) * Demonstrated experience with agile software/system development * Demonstrated experience delivering operational mission systems * Experience with security trade studies and use case development * Experience deriving security controls/requirements to provide technical criteria to system developers for successful implementation within the software/system development lifecycle * Hands-on experience with and ability to direct system administrators to securely configure systems assets per customer security standards, community best practices and/or benchmarks * Draft Security Test and Evaluation (ST&E) plans with the ability to trace security controls to security test cases and to demonstrate functional security compliance * Experience leading and conducting security testing activities using automated vulnerability assessment tools (i.e. Nessus, OpenVAS, SCC, etc.) and ST&E plan to verify security requirement compliance * Experience drafting and updating security artifacts such as: CTP/ST&E, SSP, Security CONOP, security architecture views, user guides, POA&M, PPS, PTI/PTT, SCTM, ISA, RAR/RMM etc. * Experience securing virtualization technologies to include virtual software, machines and appliances * Demonstrated leadership and project execution skills with ability to work under pressure and meet deadlines * Excellent written and oral communication skills, to include leading security presentations and briefings to executive, management, and/or program personnel ## Description Parsons is looking for a sharp Information Security Systems Engineer (ISSE) to join our growing team! In this fully onsite role you will assist with cyber and information security tasking as directed by the Lead ISSO. Program tasking will be in support of system security engineering matters, RMF requirements, system design guidance, and sustainment of secure systems infrastructure toolsets and applications . What You'll Be Doing: * Serve as a POC/Liason between contract personnel and the ISSOs across multiple enclaves * Provide guidance and assistance to system engineers in support of the Risk Management Framework (RMF) Assessment and Authorization (A&A) process to ensure systems successfully achieve an Authority to Operate (ATO) * Ensure that security related efforts/tasks are understood * Assisted with IA Training, Awareness and Incident Response * Provide primary systems administration on security toolsets and applications on both Windows and Red Hat Enterprise Linux based systems * Conducted scap scans, stig checks and analyzes results * Utilized Symantec and Logrhythm * Track patches, new security risks, and vendor errata updates for applicability to the sites * Work with PO and Scrum Master to ensure help create and execute required tickets for security related task execution * Create/Drive PTI/PTT packages * Lead POAM efforts with ISSOs * Coordinate/drive POAM efforts with TLOSS personnel * Lead RMF/ATO efforts * Ensure security baselines are kept in sync to include patching and scanning efforts * Support information system Self Inspection, Auditing, and Continuous Monitoring * Provide support as needed to other HW/SW teams on security requirements ## Related Videos - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Automate everything via NodeJS and Puppeteer](https://www.wearedevelopers.com/videos/322-automate-everything-via-nodejs-and-puppeteer) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From clicks to cribs - How to find your dream home with web scraping](https://www.wearedevelopers.com/videos/767-from-clicks-to-cribs-how-to-find-your-dream-home-with-web-scraping) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Docker build without Docker](https://www.wearedevelopers.com/videos/100114-docker-build-without-docker) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)