> Markdown version of [/jobs/ext/2655294-senior-information-systems-security-engineer-isse](https://www.wearedevelopers.com/jobs/ext/2655294-senior-information-systems-security-engineer-isse). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Systems Security Engineer (ISSE) - **Company:** ASEC Inc - **Location:** Lexington Park, MD, United States - **Experience:** Expert - **Salary:** $160,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** User Authentication, Cyber Security, Information Systems, Live Virtual and Constructive, Systems Development Life Cycle, Security Content Automation Protocol, Software Engineering, Systems Integration, Software Vulnerability Management, Information Technology, Enterprise Integration, Vulnerability Analysis - **Published:** August 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=fc22410ab8ae4248 ## About the Role * At least 10 years of related experience is required. * Demonstrated experience implementing and maintaining the DoD Risk Management Framework (RMF) in accordance with DoDI 8510.01, including development and maintenance of System Security Plans (SSPs), security control implementation documentation, authorization packages, and Authority to Operate (ATO) artifacts. * Experience conducting continuous monitoring activities, managing system authorization status, supporting annual cybersecurity reviews and inspections, and maintaining Plans of Action and Milestones (POA&Ms). * Experience reviewing and remediating cybersecurity vulnerabilities using ACAS, SCAP, DISA Security Technical Implementation Guides (STIGs), and other security assessment tools to maintain compliance with DoD cybersecurity requirements. * Experience assessing cybersecurity impacts associated with system modifications, software updates, and new capabilities while supporting secure integration of mission systems, networks, and training environments. * Experience supporting Navy, NAVAIR, or other DoD programs involving classified information systems, simulation, modeling, or Live, Virtual, and Constructive (LVC) training environments is highly desired. Education and Certification Requirements: Qualified candidates should have one of the following: * A master's degree or Ph.D. in Engineering, Cybersecurity, Data Science, Information Systems or Information Technology, or Software Engineering. * One of the following industry certifications: CISSP-ISSMP, FITSP-M, GCIA, GCIH, GICSP, GSLC, * Ability to build positive, collaborative relationships across teams and with external partners. * Effective communicator with strong verbal and written skills. * Proactive, self-directed work style with the ability to operate independently. * Analytical thinker with proven problem-solving capabilities. * Highly organized, with the ability to balance competing priorities in a fast-paced environment. ## Description As the Senior Information Systems Security Engineer (ISSE), you will play a critical role in maintaining the cybersecurity posture of advanced Live, Virtual, and Constructive (LVC) training environments that support warfighter readiness. You will oversee continuous monitoring activities, vulnerability management, security compliance, and RMF sustainment efforts across complex training systems and networks. Working closely with system administrators, network engineers, cybersecurity professionals, and government stakeholders, you will help ensure mission systems remain secure, compliant, and available to support realistic, high-fidelity combat training. This position will be based fully on-site at our Lexington Park, MD office. Periodic travel to the NAS Oceana Dam Neck Annex in Virginia Beach, VA, where the Global LVC Operations Center is located, will be required. Candidates interested in relocating to the Virginia Beach area may also have the option to work from the government site., * Lead cybersecurity engineering and security design activities for simulation, modeling, and Live, Virtual, and Constructive (LVC) training systems. * Integrate cybersecurity requirements throughout the system development lifecycle (SDLC), ensuring security is incorporated into system design, implementation, and modernization efforts. * Support accreditation of systems that connect live platforms, virtual simulators, and constructive training environments. * Define and implement cybersecurity requirements for mission systems, training networks, simulators, and supporting infrastructure. * Design enclave boundaries, authentication, encryption, auditing, and cross-domain solutions. * Ensure cybersecurity engineering activities align with DoDI 8510.01 (RMF), NIST SP 800-53, DISA Security Technical Implementation Guides (STIGs), and applicable Navy and NAVAIR cybersecurity policies. * Coordinate cybersecurity requirements for major training exercises and distributed events. * Assess security impacts of new training capabilities, software updates, and system integrations. * Support all phases of the Risk Management Framework (RMF) lifecycle for assigned systems and enclaves. * Maintain cybersecurity documentation, including System Security Plans (SSPs), security control implementation statements, POA&Ms, and authorization artifacts. * Track and manage system authorization status and accreditation milestones. * Execute continuous monitoring activities in accordance with RMF requirements. * Review and assess security controls to ensure ongoing effectiveness. * Support annual security reviews and cybersecurity inspections. * Review vulnerability scan results from ACAS, SCAP, and other assessment tools. * Track vulnerabilities through remediation and closure. * Maintain Plans of Action and Milestones (POA&Ms) and provide status reporting to Support to LVC Training Systems. * This position may require up to 25% annual travel. This description outlines the general nature and scope of the role. Additional duties may be assigned as necessary. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [SRE Methods In an Agency Environment](https://www.wearedevelopers.com/videos/348-sre-methods-in-an-agency-environment) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What is Software Engineering?](https://www.wearedevelopers.com/magazine/289-what-is-software-engineering)