> Markdown version of [/jobs/ext/1995030-information-systems-security-engineer-isse](https://www.wearedevelopers.com/jobs/ext/1995030-information-systems-security-engineer-isse). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Engineer (ISSE) - **Company:** ASTRION, INC. - **Location:** Columbia, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Systems Engineering, Cyber Security, Linux, Network Security, Systems Development Life Cycle, Security Content Automation Protocol, Systems Architecture, Software Vulnerability Management, Nessus, National Industrial Security Program Operating Manual (NISPOM) - **Published:** August 8, 2026 - **Apply:** https://us.experteer.com/career/view-jobs/information-systems-security-engineer-isse-columbia-md-usa-58858645 ## About the Role * Nessus, STIG Viewer; propose risk mitigations * Support security posture reviews and continuous monitoring; develop documentation for security plans, POA&Ms, and CM plans * Evaluate security impact of hardware, software, and configuration changes; participate in CCBs * Provide technical advisory to program managers, system owners, and admins on security decisions * Collaborate with ISSM, ISSO, System Administrators, and DCSA ISSP to coordinate security efforts Tasks * Bachelor's degree with 8-10 years of experience * Minimum of 5 years of Linux and Windows administration * Experience supporting U.S. Government clients * Ability to apply systems engineering to develop and maintain a secure network environment * CAP, CISM, or CISSP certification * U.S. citizenship with active TS/SCI eligibility * Ability to obtain and maintain TS/SCI eligibility Key requirements * ## Description Experteer Overview In this role you will architect and secure classified information systems across their lifecycle, focusing on security controls for NISPOM-defined environments. You will serve as the primary security design authority for networks and systems, aligning with DoD, Navy, and MDA guidance. You will influence architecture, risk reduction, and authorization activities while collaborating with cross-functional teams. This is a mission-driven opportunity to shape secure infrastructures in a government-facing context. Compensation / Benefits * Integrate security requirements into system architecture during planning and design; ensure compliance with 32 CFR Part 117 (NISPOM) and DAAG guidance * Incorporate secure engineering principles across the SDLC; produce engineering artifacts for Assessments & Authorization (A&A) * Design and implement technical security controls; verify they function as intended with system administrators * Lead vulnerability management using ACAS, SCAP, Nessus, STIG Viewer; propose risk mitigations * Support security posture reviews and continuous monitoring; develop documentation for security plans, POA&Ms, and CM plans * Evaluate security impact of hardware, software, and configuration changes; participate in CCBs * Provide technical advisory to program managers, system owners, and admins on security decisions * Collaborate with ISSM, ISSO, System Administrators, and DCSA ISSP to coordinate security efforts Tasks * Bachelor's degree with 8-10 years of experience * Minimum of 5 years of Linux and Windows administration * Experience supporting U.S. Government clients * Ability to apply systems engineering to develop and maintain a secure network environment * CAP, CISM, or CISSP certification * U.S. citizenship with active TS/SCI eligibility * Ability to obtain and maintain TS/SCI eligibility Key requirements * ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)