> Markdown version of [/jobs/ext/2383482-senior-information-systems-security-engineer-sr-isse](https://www.wearedevelopers.com/jobs/ext/2383482-senior-information-systems-security-engineer-sr-isse). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Systems Security Engineer (Sr. ISSE) - **Company:** ARRO SYSTEMS LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Microsoft Antivirus, Software System Penetration Testing, Systems Engineering, Microsoft Azure, Cloud Computing Security, Cloud Engineering, Static Program Analysis, Cyber Security, Information Systems, Continuous Integration, Github, Information Technology Operations, Systems Development Life Cycle, Role-Based Access Control, Azure Active Directory, Fortify (Software), Zero Trust Network Access, Secure Coding, Software Engineering, SonarQube, Systems Architecture, Sonatype, Software Security, Veracode, Infrastructure Automation Frameworks, Information Technology, Microsoft Sentinel, Checkmarx, Devsecops - **Published:** August 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=013793d5390732fa ## About the Role * Bachelor's degree in cybersecurity, computer science, information systems, engineering, or a related discipline; equivalent relevant experience may be considered. * Five or more years of experience in cybersecurity engineering, cloud security, systems engineering, application security, or a related technical role. * Experience implementing or assessing NIST SP 800-53 controls and applying the NIST Risk Management Framework. * Experience securing cloud-hosted systems, analyzing technical vulnerabilities, producing assessment-ready evidence, and communicating technical risk., * Experience with Azure Government, GCC High, Microsoft Entra ID, Microsoft Defender, Microsoft Sentinel, or comparable cloud-security technologies. * Experience supporting DoD RMF, eMASS, DISA authorization, FedRAMP, CMMC, StateRAMP/GovRAMP, or SOC 2. * Experience with DevSecOps, CI/CD pipelines, infrastructure as code, container security, and secure code-review tools such as Snyk, SonarQube, GitHub Advanced Security, Checkmarx, Veracode, or Fortify. * Experience protecting CUI or other regulated and mission-sensitive information. ## Description The Senior Information Systems Security Engineer serves as ARRO Systems' primary technical cybersecurity resource. The Sr. ISSE translates federal, Department of Defense, state, and commercial cybersecurity requirements into practical and sustainable engineering solutions. Working across software development, cloud engineering, DevSecOps, system architecture, IT operations, and GRC, the Sr. ISSE integrates security throughout the system development lifecycle and validates that documented security controls are effectively implemented, tested, and supported by objective evidence. Primary Responsibilities * Design and review secure application, cloud, network, identity, and data architectures using defense-in-depth, least privilege, zero-trust, and secure-by-design principles. * Translate NIST, DoD, FedRAMP, CMMC, StateRAMP/GovRAMP, and SOC 2 requirements into implementable technical specifications and security controls. * Implement and validate security controls, configuration baselines, hardening requirements, system diagrams, technical procedures, and assessment evidence. * Integrate application security testing and control validation into DevSecOps and CI/CD processes, including code analysis, dependency scanning, secret detection, and software composition analysis. * Analyze vulnerability scans, penetration tests, configuration assessments, and code-review findings; recommend and validate corrective actions. * Support DoD RMF, ATO, FedRAMP, CMMC, SOC 2, independent assessments, and continuous-monitoring activities. * Evaluate system and software changes for security, compliance, and authorization impact before implementation. * Communicate technical deficiencies and residual risks to engineering teams, the ISSO, GRC leadership, assessors, and other stakeholders. ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Open sourcing a library: how hard can that be?](https://www.wearedevelopers.com/videos/1058-open-sourcing-a-library-how-hard-can-that-be) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)