> Markdown version of [/jobs/ext/2708751-information-systems-security-engineer-isse-dow-skillbridge](https://www.wearedevelopers.com/jobs/ext/2708751-information-systems-security-engineer-isse-dow-skillbridge). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Engineer (ISSE) - DoW Skillbridge - **Company:** HTX Labs, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Internship / Graduate position - **Skills:** Kubernetes Security, Artificial Intelligence, Microsoft Azure, Bash Shell, Cloud Computing Security, Cloud Engineering, Configuration Management, Cyber Security, Continuous Integration, Information Leak Prevention, Identity and Access Management, IT Management, Python (Programming Language), Linux System Administration, Network Segmentation, Open Web Application Security, Windows PowerShell, Role-Based Access Control, Zero Trust Network Access, Software Engineering, Systems Integration, Software Vulnerability Management, YAML, Scripting, Large Language Models, Azure Powershell, Generative AI, Infrastructure as Code (IaC), Kubernetes, Infrastructure Automation Frameworks, Terraform, Devsecops, Plan of Action and Milestones - **Published:** September 4, 2026 - **Apply:** https://startup.jobs/skillbridge-intern-isse-htx-labs-8757352 ## About the Role * U.S. Citizen. * 5+ years of experience in cybersecurity, cloud engineering, DevSecOps, or information systems security engineering. * Experience with Azure or Azure Government, Kubernetes, Linux administration, networking, scripting, and Infrastructure as Code. * Experience implementing RMF, CMMC, STIGs, or other government cybersecurity frameworks. * Strong troubleshooting and communication skills., * Experience supporting DoW IL4/IL5 environments and Authority to Operate (ATO) efforts. * Experience with managed/self-managed Kubernetes. * Experience with CI/CD platforms, GitOps deployment solutions, IaC tools, Kubernetes policy enforcement, container runtime security, cloud IAM, and WAF technologies. * Experience securing AI-enabled applications, Azure AI Foundry, Azure OpenAI, RAG architectures, or MCP integrations. * Knowledge of NIST AI RMF, OWASP Top 10 for LLM Applications, secure AI software supply chains, and AI governance. * Preferred certifications include Security+, CASP+, CKA, CKS, Azure Security Engineer Associate, Azure Administrator Associate, Terraform Associate, or RHCSA., * Hands-on security engineer focused on building secure cloud-native platforms. * Collaborates across software engineering, DevSecOps, cybersecurity, AI engineering, and program management. * Passionate about automation, Zero Trust, AI Security Engineering, and continuous improvement. Technologies * Cloud-native architectures * Managed and self-managed Kubernetes * Containers and container orchestration * CI/CD platforms * GitOps deployment solutions * Infrastructure as Code (IaC) * Kubernetes policy enforcement ## Description HTX Labs is seeking a hands-on Information Systems Security Engineer (ISSE) to design, implement, automate, and maintain secure cloud and edge infrastructure supporting Department of War (DoW) systems. This position partners daily with the DevSecOps Engineer to build and operate secure Microsoft Azure Government and disconnected/on-premise deployments while translating RMF, CMMC Level 2, and DoW security requirements into technical implementations. Approximately 15% of this role focuses on AI Security Engineering, ensuring AI-enabled capabilities are deployed securely and governed in accordance with NIST AI RMF, DoW guidance, and industry best practices., * Harden and maintain secure cloud and edge infrastructure supporting DoW workloads. * Partner with the DevSecOps Engineer to build secure CI/CD pipelines using modern software delivery and Infrastructure as Code (IaC) practices. * Implement Zero Trust principles including RBAC, workload identity, network segmentation, private networking, and least privilege. * Engineer and maintain security controls for cloud IAM, WAF, container security, runtime protection, and Kubernetes policy enforcement. * Automate security validation, compliance monitoring, evidence collection, vulnerability remediation, and configuration management using PowerShell, Python, Bash, Azure CLI, and YAML. * Implement and maintain NIST SP 800-53 Rev. 5, RMF, CMMC Level 2, STIG, and DISA security controls through technical implementations. * Support ATO packages, Cybersecurity Impact Analyses (CIAs), SSP updates, POA&M remediation, security assessments, and continuous monitoring. * Collaborate with engineering teams to secure software supply chains through SBOM generation, image signing, container security, and secure CI/CD. AI Security Engineering (Approximately 15% of Role) * Design and implement security controls for AI-enabled applications, LLMs, Retrieval-Augmented Generation (RAG), AI agents, and Model Context Protocol (MCP) integrations. * Evaluate AI technologies for security, privacy, compliance, and supply chain risks before deployment. * Mitigate AI-specific threats including prompt injection, model poisoning, jailbreak attacks, insecure tool usage, and data leakage. * Integrate AI security testing and policy validation into CI/CD pipelines. * Perform AI threat modeling and architecture reviews using the NIST AI Risk Management Framework (AI RMF) and OWASP Top 10 for LLM Applications. * Support secure deployment of AI workloads in Azure Government and disconnected Edge environments. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline)