> Markdown version of [/jobs/ext/2697001-information-systems-security-engineer](https://www.wearedevelopers.com/jobs/ext/2697001-information-systems-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Engineer - **Company:** Caci Inc - **Location:** Chantilly, VA, United States - **Experience:** Expert - **Salary:** $86,600.0 - $181,800.0 - **Contract:** Permanent contract - **Skills:** Xacta, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Disaster Recovery, Systems Development Life Cycle, Software Engineering, Cloud Platform System, Information Technology, Nessus, Splunk, Vulnerability Analysis - **Published:** September 3, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9136857/information-systems-security-engineer ## About the Role * Bachelor's Degree in Computer Science, Information Technology, Cybersecurity, Engineering, or related degree. * Minimum of 5 years of progressive experience in Cybersecurity, Information Assurance, or related background. Clearance & Certifications: * Active TS/SCI. * DoD 8570 IAT Level II Compliance (e.g., Security+, CCNA Security, or CySA+). Risk Management & Compliance * Full RMF Lifecycle Mastery: Deep experience navigating the Risk Management Framework (NIST 800-37) to secure and maintain Authority to Operate (ATO). * Control Implementation: Expert knowledge of NIST 800-53 and 800-171 control sets, including managing control inheritance and applying overlays. * Governance & Documentation: Ability to author cybersecurity policies, manage POA&Ms, and develop Contingency/Disaster Recovery plans., Communication & Professionalism * Stakeholder Engagement: Proven ability to brief complex technical risks to large groups and coordinate directly with SCAs and DAOs. * Resilience: Ability to manage high-pressure tasks and mission-critical deadlines both independently and in team settings. Desired: * Basic understanding of the software development lifecycle (SDLC). * Experience working with governance risk and compliance tools (i.e. Xacta, SNOW, etc.). * Experience utilizing common industry tools (i.e. Nessus, Splunk, Anchore, etc.). ## Description * RMF & ATO Management: Lead the end-to-end Risk Management Framework (RMF) process, managing NIST 800-53/171 control sets and coordinating with cybersecurity entities (SCA/DAO) to secure and maintain Authority to Operate (ATO). * Security Engineering & Cloud Oversight: Drive "security by design" by reviewing technical change requests, evaluating new technologies, and providing security oversight for cloud-based platforms (AWS/Azure). * Vulnerability & Risk Mitigation: Conduct system inspections and vulnerability assessments to manage POA&Ms, prioritize system patching, and ensure robust disaster recovery and contingency planning. * Technical Compliance & Monitoring: Establish continuous monitoring protocols to track security posture, enforce cybersecurity policies, and brief complex technical risks to senior stakeholders., * Technical Oversight: Experience reviewing system changes for security impact and collaborating with dev teams to integrate new technologies securely. * Continuous Monitoring: Proficiency in conducting security inspections, audits, and vulnerability analysis to track patch effectiveness and system health. * Cloud Security: Functional understanding of security operations within AWS or Azure environments. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)