Senior Information Systems Security Engineer (Sr. ISSE)

ARRO SYSTEMS LLC
United States
about 1 month ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security Microsoft Antivirus Software System Penetration Testing Systems Engineering Microsoft Azure Cloud Computing Security Cloud Engineering Static Program Analysis Cyber Security Information Systems Continuous Integration Github
+18 more
Information Technology Operations Systems Development Life Cycle Role-Based Access Control Azure Active Directory Fortify (Software) Zero Trust Network Access Secure Coding Software Engineering SonarQube Systems Architecture Sonatype Software Security Veracode Infrastructure Automation Frameworks Information Technology Microsoft Sentinel Checkmarx Devsecops

Job description

The Senior Information Systems Security Engineer serves as ARRO Systems’ primary technical cybersecurity resource. The Sr. ISSE translates federal, Department of Defense, state, and commercial cybersecurity requirements into practical and sustainable engineering solutions.

Working across software development, cloud engineering, DevSecOps, system architecture, IT operations, and GRC, the Sr. ISSE integrates security throughout the system development lifecycle and validates that documented security controls are effectively implemented, tested, and supported by objective evidence.

Primary Responsibilities

  • Design and review secure application, cloud, network, identity, and data architectures using defense-in-depth, least privilege, zero-trust, and secure-by-design principles.

  • Translate NIST, DoD, FedRAMP, CMMC, StateRAMP/GovRAMP, and SOC 2 requirements into implementable technical specifications and security controls.

  • Implement and validate security controls, configuration baselines, hardening requirements, system diagrams, technical procedures, and assessment evidence.

  • Integrate application security testing and control validation into DevSecOps and CI/CD processes, including code analysis, dependency scanning, secret detection, and software composition analysis.

  • Analyze vulnerability scans, penetration tests, configuration assessments, and code-review findings; recommend and validate corrective actions.

  • Support DoD RMF, ATO, FedRAMP, CMMC, SOC 2, independent assessments, and continuous-monitoring activities.

  • Evaluate system and software changes for security, compliance, and authorization impact before implementation.

  • Communicate technical deficiencies and residual risks to engineering teams, the ISSO, GRC leadership, assessors, and other stakeholders.

Requirements

  • Bachelor’s degree in cybersecurity, computer science, information systems, engineering, or a related discipline; equivalent relevant experience may be considered.

  • Five or more years of experience in cybersecurity engineering, cloud security, systems engineering, application security, or a related technical role.

  • Experience implementing or assessing NIST SP 800-53 controls and applying the NIST Risk Management Framework.

  • Experience securing cloud-hosted systems, analyzing technical vulnerabilities, producing assessment-ready evidence, and communicating technical risk., * Experience with Azure Government, GCC High, Microsoft Entra ID, Microsoft Defender, Microsoft Sentinel, or comparable cloud-security technologies.

  • Experience supporting DoD RMF, eMASS, DISA authorization, FedRAMP, CMMC, StateRAMP/GovRAMP, or SOC 2.

  • Experience with DevSecOps, CI/CD pipelines, infrastructure as code, container security, and secure code-review tools such as Snyk, SonarQube, GitHub Advanced Security, Checkmarx, Veracode, or Fortify.

  • Experience protecting CUI or other regulated and mission-sensitive information.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:37 min

Executing verified publishing workflows on Sonatype Maven Central

Johan Hutting Johan Hutting · World Congress 2024

3:15 min

Correlating OpenSSF scorecard metrics with real vulnerability data

Niels Tanis Niels Tanis · World Congress 2024

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · World Congress 2023

3:44 min

Integrating static security scanning in the build phase

Milecia Mcgregor · LIVE

2:41 min

Dynamic application security testing during the test phase

Milecia Mcgregor · LIVE

Videos

See all

Related articles

See all