Information System Security Engineer SME

ECS Corporate Services, LLC
Washington, DC, United States
18 days ago
Apply on www.jofdav.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$175,000.0 - $190,000.0
Working hours
Regular working hours
Job source

Tech stack

Information Systems Information Security Management Information Systems Security Architecture Professional Information Systems Security Engineering Professional Software Security Information Technology

Job description

Responsible for leading the implementation of the Security Assessment and Authorization (SAA) Program:

  • Lead, mentor, and supervise a team of security professionals responsible for the end-to-end implementation of the RMF lifecycle for Enterprise IT systems.
  • Oversee and coordinate activities within the Prepare step, ensuring roles, responsibilities, and risk management strategies are clearly defined and maintained.
  • Guide system categorization efforts to ensure all information systems are appropriately classified based on mission/business impact and regulatory requirements.
  • Direct the selection, tailoring, and documentation of security controls aligned with system categorizations, Enterprise risk appetite, and compliance requirements.
  • Oversee the implementation of technical, operational, and management controls throughout system and application lifecycles, with a particular focus on quality and completeness of all deliverables.
  • Ensure comprehensive security control assessments are planned, executed, and documented to validate the effectiveness of implemented safeguards.
  • Prepare risk management documentation for system authorization and executive decision making.
  • Direct ongoing monitoring and continuous assessment activities, collecting metrics to adjust security strategies and ensure sustained compliance.
  • Serve as a principal technical advisor on cybersecurity, bringing subject-matter expertise to risk analysis, incident response, system remediation, and audit support efforts.
  • Foster a culture of security awareness, providing technical guidance and training to both team members and stakeholders.
  • Track, report, and communicate status, risks, and improvement opportunities related to security engineering activities to leadership and stakeholders.
  • Maintain up-to-date knowledge of RMF, NIST guidance, and industry best practices in support of continuous process improvement.

Salary Range: $175,000 - $190,000

Requirements

Security Clearance: Top Secret (TS) with SCI eligibility

  • 10+ years of progressive technical security engineering experience to include use of GRC and RMF tools
  • Hold at least one of the following certifications:

  • Certified Information Systems Security Professional (CISSP) (or Associate);
  • CompTIA Advanced Security Practitioner (CASP) CASP CE;
  • Certified Secure Software Lifecycle Professional (CSSLP);
  • CISSP- Information System Security Engineering Professional (ISSEP); or
  • CISSP- Information System Security Architecture Professional (ISSAP).

Minimum 10 years’ experience, or equivalent education/experience; Doctorate plus 6 years; Master’s plus 6 years; Associates plus 10 years; or H.S./GED plus 14 years.

Benefits & conditions

11 minutes ago Computational Mechanics (FEA) Engineer Thornton Tomasetti Washington, Washington DC $80,000.00 - $90,000.00 per year Other 12 minutes ago Designer Thornton Tomasetti Washington, Washington DC $75,000.00 - $85,000.00 per year

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jofdav.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · World Congress 2025

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:46 min

Missing equipment retrieval processes for departing employees

Jasmin Azemović Jasmin Azemović · World Congress 2026 Europe

Videos

See all

Related articles

See all