> Markdown version of [/jobs/ext/1955194-information-system-security-engineer-isse](https://www.wearedevelopers.com/jobs/ext/1955194-information-system-security-engineer-isse). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Engineer (ISSE) - **Company:** S O S I Inc - **Location:** Honolulu County, HI, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Systems Engineering, Confluence, JIRA, Cloud Computing Security, Configuration Management, Cyber Security, Information Systems, Linux, Information Security Management, Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Zero Trust Network Access, Security Content Automation Protocol, Software Engineering, Data Streaming, Systems Architecture, Virtualization Technology, Software Vulnerability Management, SARS Software Products, HybridCloud, SC Clearance, Information Technology, Nessus, Servicenow, Plan of Action and Milestones - **Published:** August 6, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9080504/information-system-security-engineer-isse ## About the Role * Active Secret clearance with the ability to obtain and maintain a Top-Secret clearance. * Must meet DoD 8140 qualification requirements for DCWF 652 Security Architect Intermediate (Primary) + Bachelors Degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering // OR // GMON, SecurityX, CCSP, CISSO, Cloud+, CSSLP, FITSP-D, GCSA, or GSEC. * DCWF 461 Systems Security Analyst Intermediate (Secondary) + Bachelors Degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering // OR // CCSP, Cloud+, GICSP, GISF, GSEC, or Security+. * Six (6) years of experience supporting cybersecurity, information assurance, systems engineering, or RMF-related activities. * Experience supporting DoD Assessment and Authorization (A&A) or RMF processes. * Experience with eMASS and maintenance of RMF authorization packages. * Experience implementing and assessing NIST SP 800-53 security controls. * Experience with ACAS, Tenable Security Center, Nessus, SCAP, and vulnerability management processes. * Working knowledge of Windows, Linux, networking, virtualization, and enterprise information systems. * Strong communication skills with the ability to engage both technical and non-technical stakeholders., * Active Top Secret clearance with SCI eligibility. * CISSP certification. * CISSP-ISSEP, CCSP, CGRC, SecurityX (formerly CASP+), or CSSLP certification. * Experience supporting Combatant Command, Navy, or Joint operational environments. * Experience with Zero Trust Architecture implementation. * Knowledge of Cross Domain Solutions (CDS) and Commercial Solutions for Classified (CSfC). * Experience with cloud security technologies and hybrid cloud environments. * Experience conducting cybersecurity architecture reviews and secure design assessments. * Experience using JIRA, Confluence, ServiceNow, or similar collaboration and workflow platforms. * Experience supporting Security Control Assessor reviews and ATO renewals. ## Description * Design, review, and implement cybersecurity architecture and engineering solutions supporting enterprise and mission systems. * Integrate security requirements into system design, development, testing, implementation, and sustainment activities. * Support and lead RMF activities throughout the authorization lifecycle, including categorization, control selection, implementation, assessment, authorization, and continuous monitoring. * Develop, review, and maintain RMF documentation including System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms). * Evaluate system changes, upgrades, and new capabilities to determine cybersecurity impacts and authorization requirements. * Validate implementation of NIST SP 800-53 security controls and DISA Security Technical Implementation Guides (STIGs). * Conduct cybersecurity architecture reviews, security engineering analyses, and technical risk assessments. * Analyze ACAS, Tenable, Nessus, and SCAP assessment results and coordinate remediation efforts with system administrators and engineering teams. * Develop and implement continuous monitoring strategies to maintain cybersecurity compliance and authorization status. * Participate in Configuration Control Boards (CCBs), Technical Review Boards (TRBs), and engineering working groups. * Provide technical guidance and cybersecurity recommendations to system owners, ISSOs, ISSMs, and senior leadership. * Support cybersecurity inspections, Security Control Assessor (SCA) assessments, and Command Cyber Readiness Inspections. * Evaluate interconnections, data flows, and system architectures to identify security risks and recommend mitigations. * Track vulnerability remediation efforts and maintain POA&M activities to meet organizational and regulatory requirements. * Support implementation and adoption of Zero Trust principles and cybersecurity modernization initiatives. * Prepare technical reports, executive summaries, and briefing materials for leadership decision-making. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)