Information Systems Security Engineer (ISSE)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Open Systems Technologies Corporation (OST) is seeking Information System Security Engineers (ISSEs) to support mission-critical Government programs. This role focuses on integrating cybersecurity engineering principles across system design, implementation, accreditation, and sustainment activities within complex classified environments. The ISSE will support full Risk Management Framework (RMF) execution, Assessment & Authorization (A&A) activities, and continuous cybersecurity compliance efforts while working closely with system administrators, ISSOs, ISSMs, and system owners., o BISCOTTI o WATCHCAT o STE
- Experience with compliance and configuration scanning tools
-
Strong analytical, troubleshooting, and documentation skills Technical Responsibilities
- Support the full RMF lifecycle for classified systems
- Assist with A&A package development and Authority to Operate (ATO) maintenance
- Implement, assess, and validate security controls
- Perform Security Control Traceability and technical validation
- Support system boundary definition and security architecture documentation
- Develop and maintain RMF artifacts and body of evidence packages
- Conduct compliance and vulnerability scanning analysis
- Validate findings including false positive identification and remediation verification
- Support STIG implementation and configuration hardening
- Manage patch validation and security compliance efforts
-
Participate in Continuous Monitoring (ConMon) activities Core ISSE Skill Areas
- Assessment & Authorization (A&A) execution and support
- Security Control implementation and validation
- RMF documentation and artifact development
- System boundary definition and architecture support
- Vulnerability management and remediation tracking
- STIG implementation and compliance validation
- Technical security assessment and risk analysis
- Continuous Monitoring (ConMon) support
Requirements
- Active TS/SCI with Polygraph security clearance
- U.S. Citizenship
- DoD 8570/8140 IASAE Level II compliant certification required
- Strong understanding of the Risk Management Framework (RMF)
- Experience supporting Assessment & Authorization (A&A) and Authority to Operate (ATO) processes
- Experience with security control implementation, validation, and continuous monitoring
- Familiarity with NIST SP 800-37 and NIST SP 800-53 (Rev. 3 and/or Rev. 5)
-
Experience with RMF and cybersecurity tools such as: o LATTEART, + Experience in classified Government cybersecurity environments
- Familiarity with enterprise Linux, network, or cloud systems
- Experience working with ISSOs, ISSMs, SCAs, and System Owners
- Understanding of vulnerability management and cybersecurity automation tools
-
Experience supporting large-scale enterprise or mission systems IASAE Level II Certification Examples Acceptable certifications include:
- CISSP
- CASP+
Benefits & conditions
OST has been supporting Government missions since 1996 and offers a comprehensive benefits package including:
- 3 Weeks Paid Time Off
- 11 Federal Holidays
- Medical and Dental Coverage
- Short-Term Disability (STD)
- Long-Term Disability (LTD)
- Life Insurance
- AD&D Coverage
- 401(k) with up to 4% Company Match About OST Open Systems Technologies Corporation (OST) is an Equal Opportunity Employer providing innovative cybersecurity and engineering solutions to support critical Government missions. We value technical excellence, collaboration, and continuous professional growth.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.wayup.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?
Understanding and Mitigating Common Web Vulnerabilities