> Markdown version of [/jobs/ext/2292543-information-systems-security-engineer](https://www.wearedevelopers.com/jobs/ext/2292543-information-systems-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Engineer - **Company:** BOAB Ventures - **Location:** United States - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Microsoft Azure, Bash Shell, Cloud Computing Security, Configuration Management, Cyber Security, Continuous Integration, Linux, Python (Programming Language), Linux System Administration, Network Architecture, Windows PowerShell, Systems Development Life Cycle, Ansible, Azure Machine Learning, SAP (Applications), Security Content Automation Protocol, Systems Architecture, Software Vulnerability Management, Windows Desktop, Data Logging, Kubernetes, Nessus, CIS Benchmarks, Data Pipelines, Devsecops, Vulnerability Analysis - **Published:** August 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9125979/information-systems-security-engineer ## About the Role * Active TS/SCI security clearance. * Ability and willingness to obtain a polygraph. * Demonstrated hands-on experience implementing cybersecurity controls within classified DoD or Intelligence Community environments. * Strong understanding of RMF, NIST SP 800-53, ICD 503, and CNSSI 1253. * Experience engineering or supporting systems through ATO. * Hands-on experience with DISA STIG implementation and system hardening. * Experience with vulnerability-management and compliance tools such as ACAS, Nessus, SCAP, or equivalent technologies. * Experience securing and troubleshooting Windows and/or Linux environments. * Ability to translate cybersecurity requirements into actionable technical solutions. * Strong understanding of vulnerability, risk, compensating controls, and security-control implementation. * Ability to communicate effectively with both technical engineering teams and government/customer stakeholders. * DoD 8570/8140 IASAE Level II certification or equivalent qualification. Desired Skills * IASAE Level III qualification. * Experience supporting JWICS, SAP, or similar highly classified environments. * Experience with AWS GovCloud, Azure Government, or other secure cloud environments. * Experience with DevSecOps, CI/CD pipelines, containers, Kubernetes, or Infrastructure as Code. * Experience automating security or system-hardening activities using PowerShell, Bash, Python, Ansible, or similar technologies. * Experience with cross-domain solutions or complex classified network architectures. * Experience securing AI/ML platforms, data pipelines, or emerging technologies. * Prior Military Intelligence, DoD, or Intelligence Community experience. ## Description BOAB Ventures is seeking an experienced Information Systems Security Engineer (ISSE) to support mission-critical systems within a highly secure Department of Defense and Intelligence Community environment. This is a hands-on security engineering position for someone who can go beyond documenting compliance requirements and actively design, implement, integrate, harden, and validate security controls within complex classified systems. The ideal candidate understands the intent behind cybersecurity requirements and can work directly with system administrators, software engineers, infrastructure teams, and government stakeholders to develop secure technical solutions that satisfy both mission and compliance objectives. What You'll Do * Engineer and integrate cybersecurity controls throughout the system development lifecycle. * Translate RMF, ICD 503, CNSSI 1253, and NIST SP 800-53 requirements into implemented and testable technical controls. * Support systems through the ATO lifecycle, including development and validation of technical security evidence. * Implement and validate DISA STIGs and Intelligence Community security baselines across Windows, Linux, network, and infrastructure environments. * Conduct vulnerability assessment and remediation using tools such as ACAS, Nessus, SCAP, and related security technologies. * Analyze STIG and security-control requirements to understand the underlying vulnerability and develop appropriate technical solutions, alternative implementations, or compensating controls when standard configurations conflict with mission requirements. * Work directly with engineering and development teams to incorporate security into system architecture, infrastructure, applications, and deployment processes. * Integrate cybersecurity requirements into DevSecOps and CI/CD environments where applicable. * Engineer and validate security monitoring, logging, auditing, and continuous-monitoring capabilities. * Assess proposed system changes for security impact and recommend appropriate technical controls or remediation. * Support secure cloud, on-premises, containerized, and classified computing environments. * Assist with incident response, vulnerability remediation, configuration management, and technical security investigations. * Collaborate with ISSMs, ISSOs, system owners, engineers, developers, and government stakeholders throughout authorization and operational activities. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Dev & Test in the Cloud? Deploy your cloud environments with Ansible & Terraform](https://www.wearedevelopers.com/videos/1607-dev-test-in-the-cloud-deploy-your-cloud-environments-with-ansible-terraform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Eclipse Che for Infrastructure Automation](https://www.wearedevelopers.com/videos/1611-eclipse-che-for-infrastructure-automation) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)