> Markdown version of [/jobs/ext/2069480-systems-security-engineer](https://www.wearedevelopers.com/jobs/ext/2069480-systems-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Systems Security Engineer - **Company:** Bowhead - **Location:** Dahlgren, VA, United States - **Experience:** Experienced - **Salary:** $100,000.0 - $125,000.0 - **Contract:** Contract - **Skills:** Information Systems, Package Development Process, Software Vulnerability Management, Nessus - **Published:** August 15, 2026 - **Apply:** https://www.dice.com/job-detail/934e886e-9b3d-47bf-9547-89dd65ba1710 ## About the Role * Three or more (3+) years of experience in RMF A&A package development * Strong knowledge of NIST SP 800-53, NIST SP 800-37, and other relevant cybersecurity standards and guidelines * Experience with the Enterprise Mission Assurance Support Service (eMASS) or managing DoD and DoN IA Portfolios is a plus * Prefer a working knowledge of STIG Viewer, Vulnerability Remediation Asset Manager (VRAM) reporting and understanding of Compliance Task Orders (CTO)s * Knowledge of RDT&E and/or tactical systems * Knowledge of Interim Authority to Test (IATT) * Ability to communicate effectively with all levels of employees and outside contacts * Strong interpersonal skills and good judgment with the ability to work alone or as part of a team * Experience with security assessment tools such as Nessus * Experience with security control implementation and testing * Strong problem-solving skills and attention to detail * Ability to work independently as well as in a team environment, * Must be able to lift up to 10 pounds * Must be able to stand and walk for prolonged amounts of time * Must be able to twist, bend and squat periodically SECURITY CLEARANCE REQUIREMENTS: Must currently hold a security clearance at the Top Secret level. ship is a requirement for Top Secret clearance at this location. Please note that the salary information is a general guideline only. Bowhead considers factors such as (but not limited to) scope and responsibilities of the position, candidate's work experience, education/training, key skills, internal peer equity, as well as, market and business considerations when extending an offer. ## Description Bowhead is seeking a Systems Security Engineer in Dahlgren, VA. In this role, you will be responsible for developing and maintaining Risk Management Framework (RMF) Assessment and Authorization (A&A) packages for our clients. You will work closely with other developers, as well as with stakeholders from different departments, to ensure that our RMF A&A packages are accurate, complete, and meet all necessary requirements., Essential functions for the Systems Security Engineer include, but are not limited to: * Develop and maintain RMF A&A packages for our clients * Work closely with stakeholders to gather information and ensure that RMF A&A packages meet their needs * Conduct security assessments of information systems to identify vulnerabilities and risks * Strong oral and written communication skills; write clear and concise reports detailing assessment findings and recommendations for risk mitigation * Collaborate with other developers to ensure that RMF A&A packages are integrated smoothly with other systems * Keep up-to-date with the latest trends and technologies in RMF A&A package development ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How AWS Generates Polyglot Libraries Based on a Single TypeScript Codebase](https://www.wearedevelopers.com/videos/1026-how-aws-generates-polyglot-libraries-based-on-a-single-typescript-codebase) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [The Developer Workstation Blind Spot: Why Your Security Stack Can't See What Matters Most](https://www.wearedevelopers.com/videos/100254-the-developer-workstation-blind-spot-why-your-security-stack-can-t-see-what-matters-most) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Giving AI eyes: How to build a dashboard you can't see](https://www.wearedevelopers.com/videos/100193-giving-ai-eyes-how-to-build-a-dashboard-you-can-t-see) ## Related Articles - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)