> Markdown version of [/jobs/ext/1952129-security-engineer-isse](https://www.wearedevelopers.com/jobs/ext/1952129-security-engineer-isse). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer/ISSE - **Company:** TOTAL FORCE ALLIANCE LLC - **Location:** Fort Meade, MD, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Audit Trail, Microsoft Azure, Cloud Computing, Cloud Computing Security, Databases, Data Control, Federal Information Processing Standards (FIPS), Information Systems Security Engineering Professional, Key Management, Log Analysis, Package Management Systems, Public Key Infrastructure, Zero Trust Network Access, Security Information and Event Management, Systems Integration, Information Security Management System, Large Language Models, Containerization, Microsoft Sentinel, Key Vault, Plan of Action and Milestones - **Published:** August 6, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9064728/security-engineerisse ## About the Role * 7+ years in information system security engineering/cybersecurity for federal or DoD systems, with direct, hands-on RMF experience. * Demonstrated ownership of at least two systems through a full RMF authorization to an ATO/cATO - SSP, control implementation, POA&M, and package management. * Hands-on experience with eMASS (or equivalent) and NIST 800-53 control implementation and assessment. * Experience hardening systems to DISA STIGs and validating compliance. * Working knowledge of cloud security architecture - identity, network isolation (private endpoints), key management, and SIEM/continuous monitoring. * Understanding of CUI handling (DoDI 5200.48) and the DoD Cloud Computing SRG impact levels. * DoD 8140/8570-compliant certification for the ISSE role (e.g., CISSP, CASP+, or equivalent). * Strong technical writing and the ability to produce assessor-ready evidence. * Ability to carry security engineering and authorization across multiple environments on a lean, senior team. * Candidates must have and maintain an active TS/SCI clearance with the Department of Defense. Preferred Qualifications: * Direct experience accrediting workloads in Azure Government or classified Azure environments. * Experience with cross-domain solutions (CDS) and the SABI/TSABI process, or supporting a data-transfer accreditation. * Experience standing up continuous monitoring with Microsoft Sentinel and integrating with a designated CSSP. * Familiarity with securing containerized workloads (AKS, hardened images, image signing/scanning). * Experience with AI/LLM security controls (data-residency, scope-bound retrieval, prompt-injection defense) in a governed environment. * ISSM or RMF assessor experience; CISSP-ISSEP. ## Description This is a critical-path role. Systems are configured, assessed, and separately authorized per environment, so you will carry the control implementation, the System Security Plan and POA&M, the hardening, and the continuous-monitoring posture - coordinating closely with cloud engineers, developers, and the Government. When accreditation is on the critical path, your work is what keeps delivery on schedule. Location: Candidate must be located in the Washington, DC, metro region and must be available onsite in Maryland as needed. This role supports secure Government environments; Candidates must have and maintain an active TS/SCI clearance with the Department of Defense. All personnel shall meet DoD 8140/8570 (DoDM 8140 / DCWF) baseline requirements. Responsibilities: * Own RMF execution - categorize, select, implement, assess, and support authorization under NIST 800-37 / 800-53 and DoDI 8510.01. * Author and maintain the System Security Plan (SSP), POA&M, and full control-implementation evidence; manage the authorization package in eMASS (or the Government's system of record). * Serve as the security engineering interface to the Government ISSM/AO and assessors; prepare for and support all assessment-and-authorization activities. * Implement and validate hardening against applicable DISA STIGs (application/ASD, container, database, OS) and track remediation to closure. * Design and operate the continuous-monitoring posture - audit logging, SIEM integration (Microsoft Sentinel / Log Analytics), and control-assessment cadence - and maintain POA&M currency. * Engineer and verify the data-protection posture: encryption in transit and at rest, key management (Key Vault / managed identity, customer-managed keys, FIPS-validated cryptography), and no secrets in source or image. * Own the CAC/PIV / DoD PKI validation design (OCSP/CRL) with the cloud and application engineers. * Enforce CUI handling and, where applicable, cross-domain and classified-data controls and spillage prevention. * Implement least-privilege access, zero-trust controls, and privileged-access administration (Bastion / JIT / MFA / privileged access workstations). * Produce and maintain the security documentation and as-built records required for accreditation and customer handoff. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Resilient by Design: Building Robust Architectures in High-Stakes Financial Systems](https://www.wearedevelopers.com/videos/2106-resilient-by-design-building-robust-architectures-in-high-stakes-financial-systems) - [Best Practices for Using GitHub Secrets](https://www.wearedevelopers.com/videos/1214-best-practices-for-using-github-secrets) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) - [No Keys for the Robot: GitOps as the Control Plane for Autonomous Agents](https://www.wearedevelopers.com/videos/100095-no-keys-for-the-robot-gitops-as-the-control-plane-for-autonomous-agents) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)