Information Systems Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+16 more
Job description
BOAB Ventures is seeking an experienced Information Systems Security Engineer (ISSE) to support mission-critical systems within a highly secure Department of Defense and Intelligence Community environment.
This is a hands-on security engineering position for someone who can go beyond documenting compliance requirements and actively design, implement, integrate, harden, and validate security controls within complex classified systems.
The ideal candidate understands the intent behind cybersecurity requirements and can work directly with system administrators, software engineers, infrastructure teams, and government stakeholders to develop secure technical solutions that satisfy both mission and compliance objectives.
What You’ll Do
- Engineer and integrate cybersecurity controls throughout the system development lifecycle.
- Translate RMF, ICD 503, CNSSI 1253, and NIST SP 800-53 requirements into implemented and testable technical controls.
- Support systems through the ATO lifecycle, including development and validation of technical security evidence.
- Implement and validate DISA STIGs and Intelligence Community security baselines across Windows, Linux, network, and infrastructure environments.
- Conduct vulnerability assessment and remediation using tools such as ACAS, Nessus, SCAP, and related security technologies.
- Analyze STIG and security-control requirements to understand the underlying vulnerability and develop appropriate technical solutions, alternative implementations, or compensating controls when standard configurations conflict with mission requirements.
- Work directly with engineering and development teams to incorporate security into system architecture, infrastructure, applications, and deployment processes.
- Integrate cybersecurity requirements into DevSecOps and CI/CD environments where applicable.
- Engineer and validate security monitoring, logging, auditing, and continuous-monitoring capabilities.
- Assess proposed system changes for security impact and recommend appropriate technical controls or remediation.
- Support secure cloud, on-premises, containerized, and classified computing environments.
- Assist with incident response, vulnerability remediation, configuration management, and technical security investigations.
- Collaborate with ISSMs, ISSOs, system owners, engineers, developers, and government stakeholders throughout authorization and operational activities.
Requirements
- Active TS/SCI security clearance.
- Ability and willingness to obtain a polygraph.
- Demonstrated hands-on experience implementing cybersecurity controls within classified DoD or Intelligence Community environments.
- Strong understanding of RMF, NIST SP 800-53, ICD 503, and CNSSI 1253.
- Experience engineering or supporting systems through ATO.
- Hands-on experience with DISA STIG implementation and system hardening.
- Experience with vulnerability-management and compliance tools such as ACAS, Nessus, SCAP, or equivalent technologies.
- Experience securing and troubleshooting Windows and/or Linux environments.
- Ability to translate cybersecurity requirements into actionable technical solutions.
- Strong understanding of vulnerability, risk, compensating controls, and security-control implementation.
- Ability to communicate effectively with both technical engineering teams and government/customer stakeholders.
- DoD 8570/8140 IASAE Level II certification or equivalent qualification.
Desired Skills
- IASAE Level III qualification.
- Experience supporting JWICS, SAP, or similar highly classified environments.
- Experience with AWS GovCloud, Azure Government, or other secure cloud environments.
- Experience with DevSecOps, CI/CD pipelines, containers, Kubernetes, or Infrastructure as Code.
- Experience automating security or system-hardening activities using PowerShell, Bash, Python, Ansible, or similar technologies.
- Experience with cross-domain solutions or complex classified network architectures.
- Experience securing AI/ML platforms, data pipelines, or emerging technologies.
- Prior Military Intelligence, DoD, or Intelligence Community experience.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?
9 Ways to Make Money Hacking