> Markdown version of [/jobs/ext/2559180-information-system-security-engineer-sme](https://www.wearedevelopers.com/jobs/ext/2559180-information-system-security-engineer-sme). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Engineer SME - **Company:** ECS Corporate Services, LLC - **Location:** Washington, DC, United States - **Experience:** Expert - **Salary:** $175,000.0 - $190,000.0 - **Contract:** Permanent contract - **Skills:** Information Systems, Information Security Management, Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Software Security, Information Technology - **Published:** August 16, 2026 - **Apply:** https://www.jofdav.com/jobs/59272042-information-system-security-engineer-sme ## About the Role Security Clearance: Top Secret (TS) with SCI eligibility * 10+ years of progressive technical security engineering experience to include use of GRC and RMF tools * Hold at least one of the following certifications: * Certified Information Systems Security Professional (CISSP) (or Associate); * CompTIA Advanced Security Practitioner (CASP) CASP CE; * Certified Secure Software Lifecycle Professional (CSSLP); * CISSP- Information System Security Engineering Professional (ISSEP); or * CISSP- Information System Security Architecture Professional (ISSAP). Minimum 10 years' experience, or equivalent education/experience; Doctorate plus 6 years; Master's plus 6 years; Associates plus 10 years; or H.S./GED plus 14 years. ## Description Responsible for leading the implementation of the Security Assessment and Authorization (SAA) Program: * Lead, mentor, and supervise a team of security professionals responsible for the end-to-end implementation of the RMF lifecycle for Enterprise IT systems. * Oversee and coordinate activities within the Prepare step, ensuring roles, responsibilities, and risk management strategies are clearly defined and maintained. * Guide system categorization efforts to ensure all information systems are appropriately classified based on mission/business impact and regulatory requirements. * Direct the selection, tailoring, and documentation of security controls aligned with system categorizations, Enterprise risk appetite, and compliance requirements. * Oversee the implementation of technical, operational, and management controls throughout system and application lifecycles, with a particular focus on quality and completeness of all deliverables. * Ensure comprehensive security control assessments are planned, executed, and documented to validate the effectiveness of implemented safeguards. * Prepare risk management documentation for system authorization and executive decision making. * Direct ongoing monitoring and continuous assessment activities, collecting metrics to adjust security strategies and ensure sustained compliance. * Serve as a principal technical advisor on cybersecurity, bringing subject-matter expertise to risk analysis, incident response, system remediation, and audit support efforts. * Foster a culture of security awareness, providing technical guidance and training to both team members and stakeholders. * Track, report, and communicate status, risks, and improvement opportunities related to security engineering activities to leadership and stakeholders. * Maintain up-to-date knowledge of RMF, NIST guidance, and industry best practices in support of continuous process improvement. Salary Range: $175,000 - $190,000 ## Related Videos - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) - [Demystifying Crypto & Web3: A Technical Journey Through 15 Years of Innovation](https://www.wearedevelopers.com/videos/1516-demystifying-crypto-web3-a-technical-journey-through-15-years-of-innovation) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [What is Software Engineering?](https://www.wearedevelopers.com/magazine/289-what-is-software-engineering) - [Software Engineer Career: Things You Should Know](https://www.wearedevelopers.com/magazine/143-software-engineer-career-things-you-should-know)