Information Systems Security Engineer

CareerCircle
Annapolis, MD, United States
3 days ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$104,000.0 - $114,400.0
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Software System Penetration Testing Systems Engineering CompTIA Security+ Cyber Security Firmware Fuzz Testing Networking Hardware Information Systems Security Architecture Professional Network Architecture Network Protocols
+15 more
Software Systems SonarQube Software Vulnerability Management Network Routing Software Security Firewalls (Computer Science) Information Technology Tenable Nessus CIS Benchmarks Cloudwatch Splunk Devsecops Plan of Action and Milestones Static Application Security Testing Dynamic Application Security Testing

Job description

We are seeking an experienced Information Systems Security Manager with over 5 years of experience as an Information Systems Security Engineer (ISSE) in US Department of Defense (DoD) software projects. The ideal candidate will have a strong background in generating and submitting System Security Packages (SSPs), Plans of Action and Milestones (POA&Ms), and other artifacts for DoD Risk Management Framework (RMF), Security Technical Implementation Guide (STIG), and related processes. Additionally, obtaining and maintaining at least one DoD Authorization to Operate (ATO) for an Amazon Web Services-deployed container-based workload is required., * Serve as an Information Systems Security Engineer (ISSE) for DoD software projects for over 5 years.

  • Generate and submit System Security Packages (SSPs), Plans of Action and Milestones (POA&Ms), and other artifacts for DoD RMF, STIG, and related processes.
  • Apply DoD tools such as eMASS and STIG Viewer to create security packages and supporting artifacts.
  • Inform software mitigation requirements based on static application security tools results, such as SonarQube, and container scanning tools.
  • Obtain and maintain at least one DoD Authorization to Operate (ATO) for an AWS-deployed container-based workload.
  • Recommend and validate data protections, test security controls, conduct threat modeling, manage vulnerabilities, and monitor security of deployed workloads.
  • Communicate and collaborate effectively throughout the RMF cybersecurity lifecycle with engineering, cybersecurity, business, and customer stakeholders., Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools. Related Jobs Cybersecurity Systems Engineer Leidos

Linthicum Heights, MD*On-Site

Planning Teamwork Equities Market Data Cryptography Cyber Security Ancient History Computer Science Software Systems Security Testing Technical Support Systems Engineering Information Assurance Engineering Management Requirements Elicitation Vulnerability Management Verbal Communication Skills Requirements Specifications Security Requirements Analysis Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) +0 Information Systems Security Engineer Leidos

Linthicum, MD*On-Site

Planning Firewall Firmware Equities Mitigation CNSSI 1253 Market Data Gap Analysis Risk Analysis Risk Management Network Routing Ancient History Computer Science Security Systems Operating Systems Security Policies Network Protocols Information Privacy Networking Hardware Network Engineering Network Architecture Information Assurance Communications Systems Information Systems Security Security Requirements Analysis Certified Information Systems Security Professional Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) +0

Google IT Support Cybersecurity Systems Engineer Leidos

Linthicum Heights, MD*On-Site

Planning Equities Innovation Market Data Cryptography Cyber Security Systems Design Risk Mitigation Ancient History Computer Science Security Testing Influencing Skills Systems Engineering Technical Leadership Information Assurance Engineering Management Cyber Security Systems Requirements Elicitation Vulnerability Management Verbal Communication Skills Influencing Without Authority Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) +0 Login | JoinContact

Requirements

Visionary SonarQube DevSecOps Innovation Mitigation Fuzz Testing Cyber Security Security Tools Threat Modeling Security Controls CompTIA Security+ Penetration Testing Amazon Web Services Application Security Artificial Intelligence Effective Communication Risk Management Framework Authorization (Computing) Engineering Design Process Information Systems Security Plan Of Action And Milestones (POA&M) Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST) CompTIA Advanced Security Practitioner (CASP+) Enterprise Mission Assurance Support Service (eMASS), * 5+ years as an ISSE for US Department of Defense (DoD) software projects.

  • Experience with DoD tools like eMASS and STIG Viewer.
  • Proficient in generating and submitting SSPs, POA&Ms, and related artifacts for RMF and STIG.
  • Experience with static application security tools (SAST) such as SonarQube, and container scanning tools.
  • Obtaining and maintaining DoD Authorization to Operate (ATO) for AWS-deployed container-based workloads.
  • CISSP, CASP, and/or Security+ certifications.

Additional Skills & Qualifications

  • Experience with US Intelligence Community (IC) system cybersecurity processes and tools.
  • Experience with SOC functions and tools, such as Splunk or CloudWatch.
  • Experience with AWS security services like Security Hub and GuardDuty.
  • Experience as an ISSE on a DevSecOps team through multiple software releases.
  • Familiarity with system security tools such as Wiz or eMASSter.
  • Familiarity with CIS benchmarks and industry security standards.
  • Exposure to penetration testing, fuzz testing, and dynamic application security testing (DAST) tools and techniques.

Work Environment

This position involves working with advanced DoD and AWS technologies to ensure the security and integrity of critical systems. The role requires effective communication and collaboration with various stakeholders, including engineering, cybersecurity, and business teams. The ideal candidate will thrive in a dynamic and fast-paced environment, continuously adapting to new challenges and technologies. Job Type & Location

Benefits & conditions

This is a Contract position based out of Annapolis, MD. Pay and Benefits

The pay range for this position is $50.00 - $55.00/hr.

Eligibility requirements apply to some benefits and may depend on your job classification and length of employment. Benefits are subject to change and may be subject to specific elections, plan, or program terms. If eligible, the benefits available for this temporary role may include the following: * Medical, dental & vision * Critical Illness, Accident, and Hospital * 401(k) Retirement Plan - Pre-tax and Roth post-tax contributions available * Life Insurance (Voluntary Life & AD&D for the employee and dependents) * Short and long-term disability * Health Spending Account (HSA) * Transportation benefits * Employee Assistance Program * Time Off/Leave (PTO, Vacation or Sick Leave) Workplace Type

About the company

Actalent is a global leader in engineering and sciences services and talent solutions. We help visionary companies advance their engineering and science initiatives through access to specialized experts who drive scale, innovation and speed to market. With a network of almost 20,000 consultants and 5,000 clients across the U.S., Canada, Asia and Europe, Actalent serves many of the Fortune 500. We are proud to be an Engineering News-Record (ENR) Top 500 Design Firm for our engineering design services and a ClearlyRated Best of Staffing® winner for both client and talent service.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careercircle.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac · WWC 2021

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all