> Markdown version of [/jobs/ext/1995871-information-systems-security-engineer-1](https://www.wearedevelopers.com/jobs/ext/1995871-information-systems-security-engineer-1). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Engineer 1 - **Company:** Columbia Technology Partners - **Location:** Annapolis Junction, MD, United States - **Experience:** Expert - **Salary:** $145,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Systems Engineering, Configuration Management, Cyber Security, Systems Architecture, Trusted Systems, Software Vulnerability Management, Information Technology, Patch Management, Vulnerability Analysis - **Published:** August 8, 2026 - **Apply:** https://www.careerjet.com/jobad/us2340fd7a5c3e5f2f3277e2fa4e6c91f4 ## About the Role (e.g., XACTA, LATTEART, BISCOTTI, WATCHCAT, STE) to manage authorization data and workflowsReview and maintain system security documentation to ensure completeness, accuracy, and audit readinessSupport incident handling, auditing, configuration control, and change management processesWork with customers and cross-functional teams to meet operational and security objectivesQualifications: Bachelor's degree in Computer Science, Information Assurance, or related field (4 additional years of experience may substitute)Minimum 7 years of experience as an ISSE or in a related roleDoD 8570 IASAE Level II certification (or equivalent)Experience with the Risk Management Framework (RMF), including A&A processes, ATOs, and continuous monitoringHands-on experience with RMF tools, NIST 800-53/800-37, vulnerability scanning, STIG implementation, and security control validationRequirements: U.S. Citizenship is required for all applicants. CTP is an equal opportunity employer and abides by applicable ## Description Description: Columbia Technology Partners is seeking an Information Systems Security Engineer 1 to support the design, development, and implementation of secure systems across complex computing and network environments. This role focuses on identifying security risks, ensuring compliance with established standards, and integrating security throughout the system lifecycle.The ideal candidate will collaborate with engineering teams and stakeholders to embed security into system architecture, support risk management activities, and contribute to system authorization efforts in mission-driven environments.This position requires hands-on experience with the Risk Management Framework (RMF), system authorization processes, and continuous monitoring activities, including the use of industry-standard RMF and vulnerability management tools.Key Responsibilities: Conduct technical security assessments to identify vulnerabilities, compliance gaps, and risksDefine and validate system security requirements and contribute to secure system designDesign, develop, and integrate security solutions across networks, systems, and enclave environmentsCollaborate with systems engineers and architects to incorporate security controls into system architecturesSupport risk identification, analysis, and mitigation throughout the system lifecycleParticipate in RMF-based security planning, Assessment & Authorization (A&A), and system accreditation effortsDevelop, maintain, and validate RMF artifacts, including security control traceability, boundary definitions, and authorization packagesPerform security control assessments aligned to NIST SP 800-53 and NIST 800-37Execute continuous monitoring activities, including vulnerability remediation, compliance validation, and reportingConduct STIG implementation, patch management, and technical validation activitiesAnalyze scan results, perform false positive validation, and ensure timely remediation of findingsUtilize RMF and security compliance tools ## Related Videos - [Security Challenges of Breaking A Monolith](https://www.wearedevelopers.com/videos/362-security-challenges-of-breaking-a-monolith) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Real-world Threat Modeling](https://www.wearedevelopers.com/videos/936-real-world-threat-modeling) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)