Senior Information Systems Security Engineer (ISSE)

Amentum Services, Inc.
Chantilly, VA, United States
21 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$190,000.0 - $225,000.0
Working hours
Regular working hours
Job source

Tech stack

Agile Methodology Amazon Web Services Cloud Computing Cyber Security Information Security Management Network Management System Software Engineering Verification and Validation (Software) Systems Integration Software Vulnerability Management Software Security Containerization
+2 more
Splunk Plan of Action and Milestones

Job description

  • Oversee cybersecurity measures for applications within an agile software environment.
  • Manage the assessment and authorization (A&A) efforts for accrediting and reaccrediting system authorizations.
  • Utilize common control provider (CCP) knowledge to secure authorization for applications on new platforms.
  • Work closely with stakeholders to ensure seamless decommissioning and accreditation of replacement systems with no downtime.
  • Conduct technical exchange meetings (TEMs) and liaise with key departments to facilitate A&A efforts.
  • Track and manage Plan of Action and Milestones (POAMs) across all systems, ensuring completion and recommending remediation steps.
  • Conduct system self-scans to support initial, update, and reaccreditation efforts.
  • Perform technical planning, system integration, verification and validation, and risk assessments.
  • Create Basis of Estimate (BOE) documentation and other critical artifacts for system A&A efforts.
  • Develop and document security evaluation of test plans and procedures.
  • Provide documentation and recommendations for security best practices and risk management framework (RMF) accreditation.
  • Drive application security and secure software development lifecycles, including containerization security as per NIST SP 800190.
  • Conduct hands-on security testing, analyze test results, and recommend countermeasures.
  • Provide guidance on cloud computing services, deployment architecture, and network management tools.
  • Review project requirements and assist in the development and tracking of project tasks and client deliverables.
  • Communicate with clients on project specific activities and manage project related deliverables.
  • Facilitate process working groups to analyze existing processes and create new business strategies., Safety - Amentum enforces a safety culture whereby all employees have the responsibility for continuously developing and maintaining a safe work environment. As appropriate, each employee is responsible for completing all training requirements and fulfilling all self-aid/buddy aid responsibilities, participating in emergency response tasks and serving on safety committees and teams.

Quality - Quality is the foundation for the management of our business and the keystone to our goal of customer satisfaction. It is our policy to consistently provide services that meet customer expectations. Accordingly, each employee must conform to the Amentum Quality Policy and carry out job activities in compliance with applicable Amentum Quality System documents and customer contracts. Each employee must read and understand his/her Quality Management and Customer Satisfaction responsibilities.

Requirements

We are seeking a highly skilled and experienced Principal Information System Security Engineer to join our team. The successful candidate will bring extensive knowledge and hands-on experience in cybersecurity engineering, risk management frameworks, and secure software development lifecycle management. This role involves leading and managing accreditation efforts, conducting risk assessments, and collaborating with cross-functional teams to ensure the highest standards of information security across our applications and systems., * Bachelor’s Degree in Security and Intelligence, or a related field.

  • Security+ CE, AWS Advanced Architect, and Splunk Fundamentals 1 and 2 certifications.
  • Extensive experience in information system security engineering, risk assessment, and vulnerability management.
  • Strong understanding of cloud computing services, secure software development lifecycles, and containerization security.
  • Proficient in creating and maintaining security documentation and Standard Operating Procedures (SOPs).
  • Demonstrated experience in leading technical exchange meetings, managing project deliverables, and ensuring compliance with security standards and policies.

Clearance Required:

  • TS/SCI w/ poly

Minimum Education:

  • B.S. in Mathematics and/or Security and Intelligence, or a related field.

Minimum Years of Experience:

  • 8

Preferred:

  • Excellent technical writing and documentation skills
  • Proven ability to collaborate with multidisciplinary teams

Benefits & conditions

Our health and welfare benefits are designed to support you and your priorities. Offerings include:

  • Health, dental, and vision insurance
  • Paid time off and holidays
  • Retirement benefits (including 401(k) matching)
  • Educational reimbursement
  • Parental leave
  • Employee stock purchase plan
  • Tax-saving options
  • Disability and life insurance
  • Pet insurance

Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O’Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:27 min

Introduction to WebAssembly in a cloud computing context

Edo Edo · World Congress 2024

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:51 min

Alibaba Cloud developer resources and cloud computing training

Cheng Zhang · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all