> Markdown version of [/jobs/ext/2695932-information-systems-security-engineer](https://www.wearedevelopers.com/jobs/ext/2695932-information-systems-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Engineer - **Company:** System One - **Location:** Clarksburg, MD, United States - **Salary:** $180,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Cyber Security, Red Hat Enterprise Linux, Security Software, Software Vulnerability Management, Cloud Platform System, Information Technology, Tenable Nessus, Vulnerability Analysis - **Published:** September 3, 2026 - **Apply:** https://www.techcareers.com/job.asp?id=3375522003&tx=KL9797FFU&pt=1&aff=0B19D771-A501-4A5E-8338-2A822B784D54&utm_source=Job%20Feed&utm_medium=textkernel&utm_campaign=DE&utm_term=0B19D771-A501-4A5E-8338-2A822B784D54 ## About the Role * Active TS/SCI with Polygraph security clearance * DoD 8570/8140 IASAE Level II compliant certification (required) * Strong working knowledge of RMF * Experience supporting A&A activities and ATO processes * Experience implementing/validating security controls and supporting continuous monitoring * Familiarity with NIST SP 800-37 and NIST SP 800-53 (Rev. 3 and/or Rev. 5) * Experience with RMF/cybersecurity tools such as: LATTEART, XACTA, BISCOTTI, WATCHCAT, STE * Experience using compliance and configuration scanning tools * Strong documentation, analytical, and troubleshooting skills NICE TO HAVE * Experience working in classified cybersecurity environments * Familiarity with enterprise Linux, networking, and/or cloud environments * Experience partnering with ISSOs, ISSMs, SCAs, and System Owners * Experience supporting large-scale enterprise or mission systems * Exposure to vulnerability management automation and reporting workflows ## Description We're hiring an Information Systems Security Engineer (ISSE) to support mission-critical work in a classified environment. In this role, you'll help build, secure, and maintain systems by applying cybersecurity engineering best practices across design, implementation, authorization, and ongoing compliance. You'll be hands-on with the Risk Management Framework (RMF), Assessment & Authorization (A&A), ATO sustainment, control validation, continuous monitoring, and vulnerability/stig compliance efforts-partnering closely with security and technical teams. WHAT YOU'LL DO * Support the full RMF lifecycle for classified systems (from planning through continuous monitoring) * Contribute to A&A packages and help maintain ATOs over time * Implement, assess, and validate security controls and technical requirements * Build and maintain RMF documentation and "body of evidence" artifacts * Support system boundary definition and security architecture documentation * Run and analyze compliance/vulnerability scans; validate results (including false positives) * Support STIG implementation, configuration hardening, and remediation verification * Help manage patch validation and ongoing security compliance activities * Participate in Continuous Monitoring (ConMon) activities and reporting, System One, and its subsidiaries including Joulé, ALTA IT Services, CM Access, TPGS, and MOUNTAIN, LTD., are leaders in delivering workforce solutions and integrated services across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible full-time employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)