> Markdown version of [/jobs/ext/2016340-cleared-on-site-information-systems-security-engineer](https://www.wearedevelopers.com/jobs/ext/2016340-cleared-on-site-information-systems-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cleared On Site Information Systems Security Engineer - **Company:** SMX, LLC - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $105,200.0 - $176,900.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Cloud Computing, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, System Configuration, Data Security, Document Management Systems, Internet Security, Information Systems Security Architecture Professional, Microsoft Security Essentials, Information Technology Security Auditing, Systems Architecture, Software Vulnerability Management, Information Technology, Devsecops, Vulnerability Analysis - **Published:** August 10, 2026 - **Apply:** https://www.careerbuilder.com/job-details/cleared-on-site-information-systems-security-engineer-isse-5362-washington-dc--8ca3178a-eb7d-406c-af0b-d5c37dd8e232 ## About the Role systems, This position is on site in Washington, DC and requires an active TS/SCI clearance., * Active TS/SCI clearance required * Minimum of 5 years of professional experience supporting cybersecurity, information assurance, security engineering, or related disciplines * Experience supporting Risk Management Framework (RMF) activities and NIST-based security compliance programs * Experience developing and maintaining SSPs, POA&Ms, security control documentation, and related authorization artifacts * Experience conducting vulnerability assessments, security testing, and risk analysis activities * Experience evaluating and implementing security controls in accordance with federal cybersecurity requirements * Familiarity with NIST 800-53, NIST 800-37, and federal information security requirements * Experience supporting Authorization to Operate (ATO) activities and continuous monitoring programs * Experience reviewing system architectures, boundary definitions, access controls, and security configurations * Knowledge of vulnerability management processes and remediation methodologies * Strong analytical, troubleshooting, and problem-solving skills * Ability to assess technical findings and develop practical risk mitigation recommendations * Strong written and verbal communication skills * Ability to work independently and collaboratively in a team environment Desired Skills & Experience * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Information Systems, or related field * Experience supporting federal government, law enforcement, intelligence community, or national security programs * Experience supporting cloud-based environments and cloud security controls * Experience supporting Governance, Risk, and Compliance (GRC) platforms * Familiarity with enterprise security tools including vulnerability scanning and security monitoring solutions * Experience supporting security audits, assessments, and compliance reviews * Familiarity with Agile development methodologies and DevSecOps practices * One or more of the following certifications preferred: * Security+ * CAP (Certified Authorization Professional) * CISSP Associate * SSCP * GSEC * CASP+ Other relevant cybersecurity certifications, Access Control, Agile Programming Methodologies, Analysis Skills, Best Practices, Business Continuity Planning (BCP), Business Development, Business impact analysis (BIA), CISSP - Certified Information Systems Security Professional, Cloud Computing, Communication Skills, CompTIA Security+, Compensation Management, Computer Science, Computer Security, Continuous Improvement, Corrective Action, Document Management, Documentation, Documentation Plan, Enterprise Protection, Federal Government, GSEC - GIAC Security Essentials Certification, Government, Government Regulations, Healthcare, Identify Issues, Information Systems Security Engineering (ISSE), Information Technology & Information Systems, Information/Data Security (InfoSec), Intelligence Community, Internet Security, Law Enforcement, Maintain Compliance, Operations Processes, Operations Security (OPSEC), Presentation/Verbal Skills, Problem Solving Skills, Regulatory Compliance, Risk, Risk Analysis, Risk Management, Risk Management Framework (RMF), SSCP - Systems Security Certified Practitioner, Security Analysis, Security Architecture, Security Auditing, Security Compliance, Security Monitoring, Sensitive Compartmented Information (SCI), System Architecture, System Lifecycle, Systems Administration/Management, Technical Analysis, Test Plan/Schedule, Testing, Top Secret Clearance, U.S. National Institute of Standards and Technology (NIST), United States Department of Defense (DoD), Vulnerability Scanners, Writing Skills ## Description SMX is seeking a highly motivated Information Systems Security Engineer (ISSE) - Mid to support a mission-critical federal program in Washington, DC. This individual will support the design, implementation, assessment, and continuous improvement of security controls across enterprise information systems and technology environments. The selected candidate will work closely with system owners, cybersecurity personnel, engineers, architects, and government stakeholders to ensure systems meet federal cybersecurity requirements while supporting mission objectives. The ideal candidate will possess experience supporting Risk Management Framework (RMF) activities, security engineering, vulnerability management, security testing, and system authorization efforts within complex federal environments. This role requires strong technical and analytical skills with the ability to evaluate security risks, implement mitigation strategies, and, contribute to the secure operation of mission-critical, * Support the design, implementation, and maintenance of security controls for enterprise information systems and applications * Develop, maintain, and update security documentation including System Security Plans (SSPs), security control implementation documentation, mitigation plans, and supporting RMF artifacts * Assist with system categorization, authorization boundary development, and security architecture documentation * Create and maintain security test plans, procedures, and supporting documentation to validate implementation of security controls * Perform security assessments, control validations, vulnerability analyses, and risk evaluations to identify security weaknesses and recommend corrective actions * Support vulnerability remediation activities and validate effectiveness of implemented mitigations * Analyze security findings and recommend technical solutions to reduce risk and improve security posture * Support audit preparation, compliance assessments, and continuous monitoring activities * Review system configurations, software inventories, hardware inventories, and user access controls to ensure compliance with security requirements * Assist in the development and maintenance of business impact analyses, continuity of operations documentation, and security-related operational procedures * Monitor security alerts, vulnerability reports, and threat information to identify potential risks to information systems * Collaborate with system administrators, developers, cybersecurity personnel, and government stakeholders to address security requirements throughout the system lifecycle * Participate in security engineering reviews, architecture discussions, and technical planning activities * Support implementation of security best practices and contribute to program cybersecurity initiatives ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)