> Markdown version of [/jobs/ext/2038369-information-systems-security-engineer](https://www.wearedevelopers.com/jobs/ext/2038369-information-systems-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Engineer - **Company:** Markon, LLC. - **Location:** Fort Meade, MD, United States - **Salary:** $225,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Amazon Web Services, Systems Engineering, Microsoft Azure, Cloud Computing Security, Software Documentation, Cyber Security, Information Systems, Computer Telephony Integration, Linux, Identity and Access Management, Systems Architecture, Software Vulnerability Management, Data Logging, Cloud Platform System, IT Architecture, Cyber Threat Analysis, Information Technology, Nessus, Operational Systems, Vulnerability Analysis - **Published:** August 12, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88011544/1 ## About the Role * Active TS/SCI w/ Polygraph with this Customer. * Bachelor's degree in Cybersecurity, Computer Science, Information Systems, Engineering, or a related technical discipline and the required experience for the SE5 labor category. * CISSP certification required. * Experience performing security engineering and cybersecurity assessments of Government information systems. * Strong understanding of ICD 503, Risk Management Framework (RMF), A&A processes, and Government cybersecurity policies and procedures. * Experience with customer RMF processes and tools such as Xacta, LatteArt, or comparable platforms. * Experience performing vulnerability assessments using Nessus and other security scanning technologies. * Strong understanding of Linux-based operating systems and associated security principles. * Strong understanding of AWS and Azure cloud environments and associated security services. * Experience evaluating system architectures, security designs, controls, and technical countermeasures. * Experience supporting continuous monitoring, vulnerability management, and remediation activities. * Strong understanding of information security principles, security controls, and risk assessment methodologies. * Excellent written and verbal communication skills with the ability to communicate technical cybersecurity concepts to both executive and technical audiences., * Experience supporting Cyber Threat Intelligence or cybersecurity missions within the Intelligence Community. * Experience integrating cybersecurity requirements throughout the systems engineering lifecycle. * Experience securing classified and unclassified cloud environments. * Knowledge of cloud-native security controls, identity and access management, logging, monitoring, and vulnerability management. * Experience developing security architecture documentation and engineering artifacts for complex enterprise systems. * Experience working directly with Authorizing Officials, security control assessors, ISSOs, ISSMs, and systems engineering teams. ## Description Markon is seeking an experienced Information Systems Security Engineer (ISSE) to support the Fort Meade customer by providing cybersecurity engineering expertise for mission-critical systems supporting the Cyber Threat Intelligence (CTI) mission. This role evaluates system and cloud architectures, develops security requirements and technical documentation, supports authorization activities, and identifies and mitigates vulnerabilities across classified and unclassified environments. The ISSE will work closely with systems engineers, security teams, and Government stakeholders to integrate cybersecurity throughout the system lifecycle and ensure compliance with applicable Intelligence Community security requirements. Responsibilities Assess existing and proposed IT architectures for compliance with cybersecurity requirements and applicable security frameworks, including ICD 503. * Develop and maintain information security policies, standards, procedures, and technical guidance. * Support Assessment and Authorization (A&A) activities and development of associated security documentation. * Develop and review security-related artifacts, including system security designs, Concepts of Operations (CONOPS), implementation plans, operational procedures, and system documentation. * Provide security engineering support for authorization, accreditation, test, and evaluation activities. * Perform continuous monitoring of information systems and evaluate changes that may impact system security or authorization. * Develop security architecture deliverables and define technical countermeasures for operational systems and systems under development. * Evaluate proposed system and cloud security architectures to determine whether designs satisfy cybersecurity and compliance requirements. * Identify, document, track, and support remediation of system vulnerabilities throughout the system lifecycle. * Perform and analyze vulnerability scans using Nessus and other cybersecurity assessment tools. * Apply Risk Management Framework (RMF) processes to evaluate security controls, document risk, and support system authorization. * Collaborate with systems engineers, developers, cloud engineers, and security personnel to integrate security requirements into system designs. * Provide cybersecurity recommendations and communicate technical risks to both engineering teams and executive stakeholders. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)