> Markdown version of [/jobs/ext/2297714-cyber-isse-top-secret](https://www.wearedevelopers.com/jobs/ext/2297714-cyber-isse-top-secret). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber ISSE Top Secret - **Company:** Insight Global - **Location:** Lincoln, MA, United States - **Experience:** Expert - **Salary:** $114,400.0 - $135,200.0 - **Contract:** Permanent contract - **Skills:** Code Review, Cyber Security, SAP (Applications), Security Content Automation Protocol, Software Requirements Analysis, Cisco Discovery Protocol, Information Technology, Nessus, Devsecops, Vulnerability Analysis - **Published:** August 29, 2026 - **Apply:** https://www.businessworkforce.com/job.asp?id=3369504600&tx=ZT1514TYZ&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role Active Top Secret Clearance/ ability to obtain SAP access RMF experience 5+ years supporting DoD programs Experience with vulnerability/compliance tools (Nessus, ACAS, STIGs, SCC/SCAP) Cybersecurity engineering experience supporting system authorization and accreditation efforts Experience working with weapon systems, defense acquisition programs, or Platform IT systems ## Description An Insight Global client is seeking a Senior Information Systems Security Engineer (ISSE) to support cybersecurity and information assurance efforts for Department of Defense (DoD) programs at Hanscom Air Force Base. This individual will play a critical role in ensuring cybersecurity compliance, supporting Risk Management Framework (RMF) activities, advising program teams on security strategy, and reducing risk across complex weapon systems and information technology environments. The ideal candidate will have extensive experience in DoD cybersecurity, RMF implementation, system security engineering, and security compliance activities throughout the system lifecycle. Day-to-Day Responsibilities Support system and application Authorization & Accreditation (A&A) efforts for weapon systems and Platform IT (PIT) systems. Provide RMF guidance and oversight to ensure compliance with DoD and Air Force cybersecurity requirements. Advise program teams on cybersecurity requirements, risk management strategies, and authorization activities throughout the acquisition lifecycle. Review and assess system architectures and recommend cybersecurity solutions for both developmental and legacy environments. Evaluate security threats, identify vulnerabilities, and recommend mitigation strategies to reduce overall program risk. Translate program and system requirements into effective cybersecurity architectures and technical solutions. Collaborate with engineering and development teams throughout the system lifecycle to integrate security into system design and implementation. Support DevSecOps initiatives by identifying security flaws and vulnerabilities during code reviews and development activities. Develop, implement, and maintain cybersecurity strategies and program protection documentation, including Program Protection Plans (PPP). Conduct Critical Program Information (CPI) and Critical Components (CC) assessments. Review and recommend system security contingency plans, disaster recovery plans, and TEMPEST requirements. Utilize security compliance and vulnerability assessment tools including STIGs, Nessus, ACAS, SCC, and SCAP. Review cybersecurity-related Contract Data Requirements Lists (CDRLs) and provide recommendations to program management teams regarding compliance and technical adequacy. Promote cybersecurity awareness and best practices across cross-functional stakeholders. Perform additional duties as assigned. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Are Code Reviews Worth It? Insights from 16 Years of Review Data](https://www.wearedevelopers.com/videos/1135-are-code-reviews-worth-it-insights-from-16-years-of-review-data) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)