> Markdown version of [/jobs/ext/2001847-cnic-n6-information-system-security-engineer](https://www.wearedevelopers.com/jobs/ext/2001847-cnic-n6-information-system-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cnic N6 Information System Security Engineer... - **Company:** Serco - **Location:** Springfield, IL, United States - **Experience:** Expert - **Contract:** Contract - **Skills:** Business Software, Cyber Security, Information Systems, Information Security Management, Red Hat Enterprise Linux, Information Security Management System, Information Technology, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 9, 2026 - **Apply:** https://www.juju.com/job/00000000gm8a1s ## About the Role + An active DoD Top Secret/SCI security clearance + U.S Citizenship required + An up to date Information Assurance Technical (IAT) Level II baseline certification + A Bachelors Degree with Technical training related to Information Technology, Cyber Security, Computer Science, or related discipline + Or a High School diploma/GED with Technical training related to Information Technology, Cyber Security, Computer Science, or related discipline with a minimum of 10 years of Cybersecurity or IT related knowledge and experience in lieu of degree + Minimum 8 years of Cybersecurity or IT related knowledge and experience + RMF and eMASS knowledge and experience + Ability to travel up to 10% of the time + Ability to pass and maintain physical health standards required for travel to the AFRICOM AOR, to include getting the required vaccinations + Valid/Active U.S Passport Additional desired experience and skills: + At least HBSS or ACAS certification/training certificate or both (both courses are desired) + RHEL certification and experience (desired) ## Description Are you an **Information System Security Engineer (ISSE)** looking for a place where you can make an impact every day? Serco is the place for you! Join our Defense team supporting our CNIC program in this exciting role based out of **Naples, Italy.** CNIC Regional Offices enable improving operational performance and cost reductions through business process definition, analysis, and development of technical capabilities which automate processes or improve transparency for analytics and decision making. In support of this effort the CNIC N6 Engineer Scientist will support the authorization of systems through the Risk Management Framework (RMF) in order to get an Interim Authority to Operate (IATO) or an Authority to Operate (ATO). In this role, you will: + Support the categorization of the Information System (IS) to be accredited through the RMF process and support the development of the System Security Plan (SSP). + Support the determination and selection of the required and or applicable security controls, inherited controls, and Common Control Identification (CCI) for the IS, Security Technical Implementation Guide (STIG). + Support the development of Memorandum of Understanding (MOU) or Memorandum of Agreement (MOA) and develop and implement an Information Security Continuous Monitoring (ISCM) plan/strategy. + Support the implementation of required and or applicable security controls. + Support the development, review, and approval of Security Assessment Plan. + Implement, maintain, and upgrade the approved IS security scanning tool and perform periodic security scans of the IS and business application code. + Support the development and review of the System Assessment Report (SAR). + Support the development of the Plan of Action and Milestones (POA&M). + Support the development and update of the Security Authorization Package. + Perform periodic assessment of the IS' security controls. + Conduct remediation actions based on the results of ongoing monitoring of activities, assessment or risk, and outstanding items. + Update the SSP, SAR, RAR and POA&M based on the results of the continuous monitoring process. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Open Source: The Engine of Innovation in the Digital Age](https://www.wearedevelopers.com/videos/1103-open-source-the-engine-of-innovation-in-the-digital-age) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)