Senior Information Systems Security Engineer (Sr. ISSE)
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+18 more
Job description
The Senior Information Systems Security Engineer serves as ARRO Systems’ primary technical cybersecurity resource. The Sr. ISSE translates federal, Department of Defense, state, and commercial cybersecurity requirements into practical and sustainable engineering solutions.
Working across software development, cloud engineering, DevSecOps, system architecture, IT operations, and GRC, the Sr. ISSE integrates security throughout the system development lifecycle and validates that documented security controls are effectively implemented, tested, and supported by objective evidence.
Primary Responsibilities
-
Design and review secure application, cloud, network, identity, and data architectures using defense-in-depth, least privilege, zero-trust, and secure-by-design principles.
-
Translate NIST, DoD, FedRAMP, CMMC, StateRAMP/GovRAMP, and SOC 2 requirements into implementable technical specifications and security controls.
-
Implement and validate security controls, configuration baselines, hardening requirements, system diagrams, technical procedures, and assessment evidence.
-
Integrate application security testing and control validation into DevSecOps and CI/CD processes, including code analysis, dependency scanning, secret detection, and software composition analysis.
-
Analyze vulnerability scans, penetration tests, configuration assessments, and code-review findings; recommend and validate corrective actions.
-
Support DoD RMF, ATO, FedRAMP, CMMC, SOC 2, independent assessments, and continuous-monitoring activities.
-
Evaluate system and software changes for security, compliance, and authorization impact before implementation.
-
Communicate technical deficiencies and residual risks to engineering teams, the ISSO, GRC leadership, assessors, and other stakeholders.
Requirements
-
Bachelor’s degree in cybersecurity, computer science, information systems, engineering, or a related discipline; equivalent relevant experience may be considered.
-
Five or more years of experience in cybersecurity engineering, cloud security, systems engineering, application security, or a related technical role.
-
Experience implementing or assessing NIST SP 800-53 controls and applying the NIST Risk Management Framework.
-
Experience securing cloud-hosted systems, analyzing technical vulnerabilities, producing assessment-ready evidence, and communicating technical risk., * Experience with Azure Government, GCC High, Microsoft Entra ID, Microsoft Defender, Microsoft Sentinel, or comparable cloud-security technologies.
-
Experience supporting DoD RMF, eMASS, DISA authorization, FedRAMP, CMMC, StateRAMP/GovRAMP, or SOC 2.
-
Experience with DevSecOps, CI/CD pipelines, infrastructure as code, container security, and secure code-review tools such as Snyk, SonarQube, GitHub Advanced Security, Checkmarx, Veracode, or Fortify.
-
Experience protecting CUI or other regulated and mission-sensitive information.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Dev Digest 134 - Where pixels sing?
The 12 Best Jobs for Software Engineers
9 Ways to Make Money Hacking