> Markdown version of [/jobs/ext/1824166-information-systems-security-engineer](https://www.wearedevelopers.com/jobs/ext/1824166-information-systems-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Engineer - **Company:** Sg2 Recruiting LLC - **Location:** Arlington, VA, United States - **Contract:** Permanent contract - **Skills:** Xacta, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Cyber Security, Identity and Access Management, Windows PowerShell, Smartsuite, Security Information and Event Management, SQL Databases, Tisax, Webinspect, Software Security, SC Clearance, Tanium Platform Expertise, Nessus, Nutanix, Splunk, Vmware - **Published:** July 7, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9016306/information-systems-security-engineer ## About the Role U.S. Citizenship and ability to obtain / maintain a Secret Clearance Seven (7) or more years of cybersecurity, information assurance, GRC, compliance, or audit experience Experience supporting DoD contractors, federal agencies, FOCI-mitigated organizations, or other highly regulated environments Experience developing enterprise cybersecurity governance programs Experience developing and maintaining SSPs, ECPs, and POA&Ms Working knowledge of: ISO 2700, NIST 800-171, CMMC, RMF, SOX, GDPR, TISAX Experience with cybersecurity compliance platforms and GRC tools Strong technical writing, documentation, and communication skills Ability to communicate effectively with executives, auditors, customers, and technical teams Ability to meet with team members in Washington, DC Metro office monthly or as needed. It's a Plus If You Have This: Active Secret Clearance Experience supporting FOCI-mitigated organizations Experience establishing cybersecurity programs for newly formed organizations Secure enterprise architecture experience Enterprise networking expertise SOC, SIEM, and SOAR strategy experience Vendor Risk Management experience Supply chain cybersecurity experience Business continuity and disaster recovery leadership Technical Operations Center experience Experience with: Splunk, Nessus Security Center, WebInspect, Xacta, Tanium, Microsoft Azure, AWS/C2S, VMware, Nutanix, PowerShell, SQL Security, STIG compliance, SecDevOps Professional certifications such as: CISSP, CISM, CISA, CEH, ITIL, CCNP, JNCIA, ISO Lead Auditor What's In It For You ## Description SG2 Recruiting is partnering with Wind RiverX to identify an experienced Information Systems Security Engineer / Manager who thrives at the intersection of cybersecurity, compliance, secure systems engineering, and enterprise governance. You'll be joining a rapidly growing defense technology organization supporting some of the nation's most critical missions. Reporting directly to the Senior Director of Compliance, you'll play an active role in building an enterprise cybersecurity program that enable secure innovation while ensuring compliance with Department of Defense, federal, and international security standards. The ideal candidate has hands-on experience supporting highly regulated organizations-particularly FOCI-mitigated environments-and enjoys working alongside engineering, IT, security, and executive leadership to build scalable cybersecurity programs from the ground up. What You Will Be Doing: Lead Governance, Risk & Compliance (GRC) Developing and maintaining enterprise cybersecurity governance programs Driving compliance with ISO 27001, NIST 800-171, CMMC, RMF, SOX, GDPR, NIS2, TISAX, and related regulatory frameworksCreating and maintaining cybersecurity policies, standards, procedures, and governance documentation Developing System Security Plans (SSPs), Electronic Communications Plans (ECPs), and Plans of Action & Milestones (POA&Ms) Partnering with control owners to manage risks, exceptions, and continuous compliance improvements Drive Enterprise Security Programs Conducting cybersecurity risk assessments Monitoring security controls and regulatory compliance Supporting secure systems architecture and enterprise network security initiatives Collaborating with engineering teams on secure identity management, authentication, authorization, and access control Supporting secure cloud and hybrid infrastructure environments Lead Audit Readiness Preparing the organization for internal audits, customer assessments, and regulatory reviews Coordinating audit evidence collection across cross-functional teams Supporting CMMC assessments and RMF accreditation activities Maintaining audit-ready documentation and cybersecurity artifacts Strengthen Enterprise Resilience Leading Business Impact Assessments (BIAs) Maintaining business continuity and disaster recovery programs Conducting tabletop exercises Developing cyber incident response and continuity playbooks Manage Third-Party Cybersecurity Risk Performing vendor cybersecurity assessments Evaluating supplier security documentation Tracking remediation activities Supporting cybersecurity contract reviews and right-to-audit requirements Strengthening supply chain security posture Partner Across the Business Collaborating with Architecture, Engineering, Product Security, IT, and executive leadership Supporting Government Security Committee initiatives Delivering executive briefings on cybersecurity posture and organizational risk Promoting cybersecurity awareness and role-based training programs What You Need ## Related Videos - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WebAssembly: The Next Frontier of Cloud Computing](https://www.wearedevelopers.com/videos/972-webassembly-the-next-frontier-of-cloud-computing) - [Generating code with Angular schematics](https://www.wearedevelopers.com/videos/129-generating-code-with-angular-schematics) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)