Information Systems Security Engineer

System One
Clarksburg, MD, United States
1 day ago
Apply on www.techcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Compensation
$180,000.0
Working hours
Regular working hours

Tech stack

Xacta Cyber Security Red Hat Enterprise Linux Security Software Software Vulnerability Management Cloud Platform System Information Technology Tenable Nessus Vulnerability Analysis

Job description

We’re hiring an Information Systems Security Engineer (ISSE) to support mission-critical work in a classified environment. In this role, you’ll help build, secure, and maintain systems by applying cybersecurity engineering best practices across design, implementation, authorization, and ongoing compliance.

You’ll be hands-on with the Risk Management Framework (RMF), Assessment & Authorization (A&A), ATO sustainment, control validation, continuous monitoring, and vulnerability/stig compliance efforts-partnering closely with security and technical teams.

WHAT YOU’LL DO

  • Support the full RMF lifecycle for classified systems (from planning through continuous monitoring)
  • Contribute to A&A packages and help maintain ATOs over time
  • Implement, assess, and validate security controls and technical requirements
  • Build and maintain RMF documentation and “body of evidence” artifacts
  • Support system boundary definition and security architecture documentation
  • Run and analyze compliance/vulnerability scans; validate results (including false positives)
  • Support STIG implementation, configuration hardening, and remediation verification
  • Help manage patch validation and ongoing security compliance activities
  • Participate in Continuous Monitoring (ConMon) activities and reporting, System One, and its subsidiaries including JoulĂŠ, ALTA IT Services, CM Access, TPGS, and MOUNTAIN, LTD., are leaders in delivering workforce solutions and integrated services across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible full-time employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

Requirements

  • Active TS/SCI with Polygraph security clearance
  • DoD 8570/8140 IASAE Level II compliant certification (required)
  • Strong working knowledge of RMF
  • Experience supporting A&A activities and ATO processes
  • Experience implementing/validating security controls and supporting continuous monitoring
  • Familiarity with NIST SP 800-37 and NIST SP 800-53 (Rev. 3 and/or Rev. 5)
  • Experience with RMF/cybersecurity tools such as: LATTEART, XACTA, BISCOTTI, WATCHCAT, STE
  • Experience using compliance and configuration scanning tools
  • Strong documentation, analytical, and troubleshooting skills

NICE TO HAVE

  • Experience working in classified cybersecurity environments
  • Familiarity with enterprise Linux, networking, and/or cloud environments
  • Experience partnering with ISSOs, ISSMs, SCAs, and System Owners
  • Experience supporting large-scale enterprise or mission systems
  • Exposure to vulnerability management automation and reporting workflows

About the company

System One, and its subsidiaries including JoulĂŠ and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman ¡ World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira ¡ Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger ¡ LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin ¡ World Congress 2022

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar ¡ World Congress 2023

Videos

See all

Related articles

See all