> Markdown version of [/jobs/ext/2610396-information-systems-security-engineer](https://www.wearedevelopers.com/jobs/ext/2610396-information-systems-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Engineer - **Company:** Spear AI - **Location:** Washington, DC, United States (Remote available) - **Contract:** Temporary contract - **Skills:** Artificial Intelligence, Amazon Web Services, Systems Engineering, Microsoft Azure, Configuration Management, Cyber Security, Information Systems, Information Systems Security Architecture Professional, Secure Coding, Security Content Automation Protocol, Software Vulnerability Management, Data Logging, Data Ingestion, Nessus, Data Management, Machine Learning Operations, Data Pipelines, Devsecops, Vulnerability Analysis - **Published:** August 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=6b912ca7ea609533 ## About the Role * Active TS/SCI required; must be able to obtain a Polygraph. * Hands-on expertise implementing NIST RMF, ICD 503, CNSSI 1253, and NIST SP 800-53 controls in classified environments * Demonstrated experience engineering systems through ATO - building the technical body of evidence, not just documenting it * Strong background in system hardening, vulnerability management, and security tooling (STIGs, SCAP, ACAS/Nessus) on JWICS or similar classified networks * Experience with secure architecture design across cloud, on-prem, and cross-domain environments * DoW 8570/8140 IASAE Level II compliance required (Level III preferred) Nice to have * Experience securing AI/ML systems and data pipelines * AWS GovCloud or Azure Government security engineering experience * DevSecOps tooling experience (container security, pipeline scanning, IaC security) * Cross Domain Solution (CDS) integration experience * Military Intelligence or IC experience ## Description * Design and engineer security architectures for program information systems, ensuring security is built in from the ground up rather than bolted on * Translate RMF, ICD 503, CNSSI 1253, and NIST SP 800-53 requirements into implemented, testable technical controls across multiple classified systems * Develop and maintain the body of evidence supporting ATO packages - system security plans, control implementation details, test results, and supporting artifacts - in partnership with the ISSM and ISSOs * Harden systems to DISA STIG and IC baselines; run and remediate vulnerability scans (ACAS/Nessus, SCAP) across the environment * Integrate security into the development pipeline (DevSecOps), advising engineers on secure design, secure coding, and control implementation early in the lifecycle * Engineer and tune continuous monitoring, auditing, and logging capabilities for classified systems * Assess security impacts of proposed system changes and support configuration management boards * Engineer security for AI/ML pipelines and data platforms, addressing emerging threats unique to model training, data ingestion, and edge deployment * Support incident response with technical analysis, containment engineering, and remediation * Coordinate with ISSM/ISSO staff, system owners, and government security stakeholders to keep engineering decisions aligned with mission requirements and applicable directives ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Building Sovereign AI: Lessons from Deploying Secure RAG Systems using Confidential Computing](https://www.wearedevelopers.com/videos/100108-building-sovereign-ai-lessons-from-deploying-secure-rag-systems-using-confidential-computing) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems) - [Dev Digest 137 - AI'm not sure about this](https://www.wearedevelopers.com/magazine/485-dev-digest-137-ai-m-not-sure-about-this)