> Markdown version of [/jobs/ext/2541195-information-system-security-engineer-isse](https://www.wearedevelopers.com/jobs/ext/2541195-information-system-security-engineer-isse). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Engineer, (ISSE) - **Company:** Cinteot Inc. - **Location:** Fort Meade, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Computing Platforms, CompTIA Security+, Cyber Security, Federal Information Processing Standards (FIPS), Information Security Management, Networking Hardware, Virtual Private Networks (VPN), Information Systems Security Architecture Professional, Network Security, Network Diagrams, Information Technology, CIS Benchmarks, Vulnerability Analysis - **Published:** August 9, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=65a794478bf714e6 ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, or related field. * Must hold and maintain an appropriate DoD 8140.03 / 8570.01-M certification baseline for this labor category (e.g., Security+, CISSP, CISM, or equivalent as required). * At least 7 years of experience in cybersecurity engineering, RMF/DIACAP accreditation, and compliance documentation in DoD environments. * Expertise in the application of DISA STIGs/SRGs, ACAS/HBSS vulnerability analysis, and eMASS package preparation. * Strong written and verbal communication skills, with demonstrated experience producing accreditation documentation and presenting risk findings to senior stakeholders. Desired Qualifications * Master's degree in Cybersecurity or related discipline. * Experience supporting DISA programs and preparing for CCRI inspections. * Advanced certifications such as CISSP-ISSAP or CISM. Clearance Requirement * Active Top Secret clearance ## Description * Facilitate sub-projects as they go through the Risk Management Framework (RMF) accreditation life cycle. * Support the periodic system security scans as required by policy and the RMF. * Validate and verify system security requirement definitions and analyze system security designs. * Perform technical security assessments of computing environments to identify points of vulnerability, and then recommend mitigation strategies for those that do not comply with established Information Assurance (IA) standards. * Experience manually reviewing network diagrams, network device configurations, termination points for VPNs, and a working knowledge of software TLS security. * Able to maintain a flexible and non-traditional RMF review of secure networks to assess and prescribe countermeasures for secure communications e.g. analog radio, mobile cellular, remote kits, software/hardware-based VPN solutions and VDI technologies. * Familiar with applying different standards and security frameworks to include CIS benchmarks, FIPS 140-2, DISA Stigs, CNSA cryptographic suite compliance, etc. * Participated as a security engineering representative on engineering teams for the design, development, implementation and/or integration of secure networking, computing, and enclave environments. * Participated as a security engineering representative on engineering teams for the design, development, implementation and/or integration of IA architectures, systems, or system components. * Supported the Government in the enforcement of the design and implementation of trusted relationships among external systems and architectures. * Applied knowledge of IA policy, procedures, and workforce structure to design, develop, and implement secure networking, computing, and enclave environments * Supported security planning, assessment, risk analysis, and risk management. * Identified overall security requirements for the proper handling of Government data. ## Related Videos - [Small, Secure, Interconnected: The next Internet Protocol](https://www.wearedevelopers.com/videos/100062-small-secure-interconnected-the-next-internet-protocol) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again)