> Markdown version of [/jobs/ext/1992549-information-systems-security-engineer](https://www.wearedevelopers.com/jobs/ext/1992549-information-systems-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Engineer - **Company:** CareerCircle - **Location:** Annapolis, MD, United States - **Experience:** Expert - **Salary:** $104,000.0 - $114,400.0 - **Contract:** Temporary contract - **Skills:** Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, Systems Engineering, CompTIA Security+, Cyber Security, Firmware, Fuzz Testing, Networking Hardware, Information Systems Security Architecture Professional, Network Architecture, Network Protocols, Software Systems, SonarQube, Software Vulnerability Management, Network Routing, Software Security, Firewalls (Computer Science), Information Technology, Tenable Nessus, CIS Benchmarks, Cloudwatch, Splunk, Devsecops, Plan of Action and Milestones, Static Application Security Testing, Dynamic Application Security Testing - **Published:** August 8, 2026 - **Apply:** https://www.careercircle.com/jobs/all/all/usa/md/annapolis/500fb226-d4df-4735-9840-5078492b333d ## About the Role Visionary SonarQube DevSecOps Innovation Mitigation Fuzz Testing Cyber Security Security Tools Threat Modeling Security Controls CompTIA Security+ Penetration Testing Amazon Web Services Application Security Artificial Intelligence Effective Communication Risk Management Framework Authorization (Computing) Engineering Design Process Information Systems Security Plan Of Action And Milestones (POA&M) Static Application Security Testing (SAST) Dynamic Application Security Testing (DAST) CompTIA Advanced Security Practitioner (CASP+) Enterprise Mission Assurance Support Service (eMASS), * 5+ years as an ISSE for US Department of Defense (DoD) software projects. * Experience with DoD tools like eMASS and STIG Viewer. * Proficient in generating and submitting SSPs, POA&Ms, and related artifacts for RMF and STIG. * Experience with static application security tools (SAST) such as SonarQube, and container scanning tools. * Obtaining and maintaining DoD Authorization to Operate (ATO) for AWS-deployed container-based workloads. * CISSP, CASP, and/or Security+ certifications. Additional Skills & Qualifications * Experience with US Intelligence Community (IC) system cybersecurity processes and tools. * Experience with SOC functions and tools, such as Splunk or CloudWatch. * Experience with AWS security services like Security Hub and GuardDuty. * Experience as an ISSE on a DevSecOps team through multiple software releases. * Familiarity with system security tools such as Wiz or eMASSter. * Familiarity with CIS benchmarks and industry security standards. * Exposure to penetration testing, fuzz testing, and dynamic application security testing (DAST) tools and techniques. Work Environment This position involves working with advanced DoD and AWS technologies to ensure the security and integrity of critical systems. The role requires effective communication and collaboration with various stakeholders, including engineering, cybersecurity, and business teams. The ideal candidate will thrive in a dynamic and fast-paced environment, continuously adapting to new challenges and technologies. Job Type & Location ## Description We are seeking an experienced Information Systems Security Manager with over 5 years of experience as an Information Systems Security Engineer (ISSE) in US Department of Defense (DoD) software projects. The ideal candidate will have a strong background in generating and submitting System Security Packages (SSPs), Plans of Action and Milestones (POA&Ms), and other artifacts for DoD Risk Management Framework (RMF), Security Technical Implementation Guide (STIG), and related processes. Additionally, obtaining and maintaining at least one DoD Authorization to Operate (ATO) for an Amazon Web Services-deployed container-based workload is required., * Serve as an Information Systems Security Engineer (ISSE) for DoD software projects for over 5 years. * Generate and submit System Security Packages (SSPs), Plans of Action and Milestones (POA&Ms), and other artifacts for DoD RMF, STIG, and related processes. * Apply DoD tools such as eMASS and STIG Viewer to create security packages and supporting artifacts. * Inform software mitigation requirements based on static application security tools results, such as SonarQube, and container scanning tools. * Obtain and maintain at least one DoD Authorization to Operate (ATO) for an AWS-deployed container-based workload. * Recommend and validate data protections, test security controls, conduct threat modeling, manage vulnerabilities, and monitor security of deployed workloads. * Communicate and collaborate effectively throughout the RMF cybersecurity lifecycle with engineering, cybersecurity, business, and customer stakeholders., Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools. Related Jobs Cybersecurity Systems Engineer Leidos Linthicum Heights, MD*On-Site Planning Teamwork Equities Market Data Cryptography Cyber Security Ancient History Computer Science Software Systems Security Testing Technical Support Systems Engineering Information Assurance Engineering Management Requirements Elicitation Vulnerability Management Verbal Communication Skills Requirements Specifications Security Requirements Analysis Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) +0 Information Systems Security Engineer Leidos Linthicum, MD*On-Site Planning Firewall Firmware Equities Mitigation CNSSI 1253 Market Data Gap Analysis Risk Analysis Risk Management Network Routing Ancient History Computer Science Security Systems Operating Systems Security Policies Network Protocols Information Privacy Networking Hardware Network Engineering Network Architecture Information Assurance Communications Systems Information Systems Security Security Requirements Analysis Certified Information Systems Security Professional Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) +0 Google IT Support Cybersecurity Systems Engineer Leidos Linthicum Heights, MD*On-Site Planning Equities Innovation Market Data Cryptography Cyber Security Systems Design Risk Mitigation Ancient History Computer Science Security Testing Influencing Skills Systems Engineering Technical Leadership Information Assurance Engineering Management Cyber Security Systems Requirements Elicitation Vulnerability Management Verbal Communication Skills Influencing Without Authority Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) +0 Login | JoinContact ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)