> Markdown version of [/jobs/ext/2732542-information-system-security-engineer-iii](https://www.wearedevelopers.com/jobs/ext/2732542-information-system-security-engineer-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Engineer III - **Company:** TRISTAR INC - **Location:** Bloomington, IN, United States - **Experience:** Expert - **Contract:** Contract - **Skills:** Systems Engineering, Cloud Computing, Configuration Management, Cyber Security, Information Systems, Databases, Data Stores, Monitoring of Systems, Identity and Access Management, Information Security Management, Intrusion Detection Systems, Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Network Security, Network Segmentation, Zero Trust Network Access, Security Content Automation Protocol, Security Information and Event Management, Systems Architecture, Software Vulnerability Management, SARS Software Products, Cloud Platform System, Cyber Threat Analysis, Firewalls (Computer Science), Information Technology, Nessus, Cyber Warfare, Vulnerability Analysis - **Published:** September 5, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88258638/1 ## About the Role * Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Security, Information Assurance, Systems Engineering, or a related technical field. * Must have or be able to obtain a CASP or CISSP prior to start date. * 10+ years of progressively responsible experience in systems engineering, cybersecurity engineering, information assurance, security architecture, or a related technical discipline. * Four years of directly relevant ISSE experience may be considered in lieu of the degree requirement, subject to applicable contract and IASAE Level III baseline qualification requirements. * Must meet applicable DoD 8570/8140 IASAE Level III baseline qualification requirements. * Demonstrated experience designing, engineering, implementing, or assessing security architectures for complex information systems and networks. * Extensive experience supporting the DoD Risk Management Framework (RMF) and system authorization process. * Demonstrated experience developing, reviewing, and maintaining RMF security authorization documentation, including SSPs, SAPs, SARs, POA&Ms, IATT, and ATO documentation. * Extensive knowledge of cybersecurity controls, security architecture principles, vulnerability management, system hardening, and defense-in-depth. * Experience conducting threat modeling, security assessments, vulnerability assessments, risk assessments, and security architecture reviews. * Experience designing and implementing security solutions for networks, applications, databases, cloud environments, and enterprise infrastructure. * Strong understanding of network security architecture, boundary protection, firewalls, segmentation, access controls, identity management, encryption, and cryptographic controls. * Demonstrated understanding of Zero Trust security principles and architectures. * Experience analyzing security logs, identifying anomalous activity, and supporting cybersecurity incident response and mitigation. * Ability to independently analyze complex technical and cybersecurity problems and develop effective solutions. * Excellent written and verbal communication skills with the ability to brief technical and non-technical Government stakeholders. * Demonstrated ability to lead technical discussions, security reviews, engineering teams, and cross-functional working groups. * Active DoD 8570/8140 IASAE Level III qualification or equivalent. * Advanced cybersecurity certifications such as CISSP, CISSP-ISSAP, CISSP-ISSEP, CISM, CCSP, or equivalent. * Extensive experience with eMASS or other RMF Governance, Risk, and Compliance (GRC) platforms. * Experience with ACAS/Nessus, SCAP, vulnerability management, SIEM, HBSS/ESS, endpoint detection and response (EDR), IDS/IPS, and security monitoring technologies. * Experience applying DISA STIGs/SRGs and NIST security controls to complex enterprise environments. * Experience implementing or assessing Zero Trust Architecture in DoD environments. * Experience supporting systems with high mission impact or highly sensitive/classified information. * Experience working directly with DoD, Intelligence Community, or other Federal Government customers. * Experience leading cybersecurity architecture reviews, technical working groups, and engineering change processes. * Experience mentoring and providing technical direction to junior and mid-level cybersecurity engineers. * Familiarity with emerging cybersecurity technologies, advanced persistent threats (APTs), threat intelligence, and modern defensive cyber operations. * Ability to obtain and maintain a security clearance. * Must be a U.S. Citizen. ## Description We are seeking a dedicated Information System Security Engineer III to join our team. The Information System Security Engineer (ISSE) III provides expert-level cybersecurity engineering, security architecture, and systems security engineering support for complex and mission-critical Department of War networks and information systems. Aligned with the DoD 8570/8140 IASAE Level III (Information Assurance System Architecture and Engineering) category, the ISSE III serves as a senior technical Subject Matter Expert (SME) responsible for integrating cybersecurity requirements throughout the complete system lifecycle. The ISSE III applies advanced systems engineering and cybersecurity principles to the design, development, integration, assessment, authorization, and sustainment of secure systems. This position provides technical leadership in addressing complex cybersecurity challenges, developing resilient security architectures, mitigating sophisticated threats, and ensuring systems maintain an acceptable security posture throughout their operational lifecycle. The ISSE III serves as a primary technical security advisor to Government stakeholders, program managers, system architects, engineers, cybersecurity personnel, and other technical teams. The position requires significant independent judgment, technical leadership, and the ability to translate mission requirements and evolving cybersecurity threats into practical, secure engineering solutions., * Serve as a senior cybersecurity engineering and Information Assurance System Architecture and Engineering (IASAE) Subject Matter Expert for complex DoD systems and networks. * Integrate cybersecurity and security functional requirements throughout the system acquisition, architecture, engineering, development, integration, testing, deployment, and sustainment lifecycle. * Develop and evaluate secure system architectures that address mission requirements, cybersecurity threats, vulnerabilities, and applicable DoD security requirements. * Design and implement end-to-end security solutions for enterprise networks, applications, databases, cloud environments, infrastructure, and other mission-critical systems. * Apply systems engineering methodologies to identify and mitigate cybersecurity risks throughout the system lifecycle. * Harden application interfaces, data repositories, operating environments, cloud infrastructure, and system components in accordance with applicable security requirements and best practices. * Incorporate Zero Trust Architecture principles, defense-in-depth, boundary protection, network segmentation, firewalls, access controls, identity management, and cryptographic protections into system designs. * Evaluate system architectures, interfaces, and security boundaries to identify potential attack paths, weaknesses, and opportunities for improved protection. * Lead or support threat modeling, attack-surface analysis, vulnerability assessments, risk assessments, and security architecture reviews. * Analyze security vulnerabilities and threat intelligence to develop and implement proactive defensive measures against sophisticated adversaries. * Develop, review, and maintain comprehensive Risk Management Framework (RMF) documentation, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and other authorization artifacts. * Provide technical leadership and support for RMF authorization activities, including preparation for and maintenance of Interim Authority to Test (IATT) and Authority to Operate (ATO). * Support the development and execution of security control assessment strategies and provide technical responses to assessment findings. * Evaluate proposed system changes, engineering designs, interfaces, and configuration modifications for cybersecurity impacts. * Participate in Configuration Control Boards, Engineering Change Boards, architecture reviews, technical interchange meetings, and security working groups. * Lead technical walkthroughs, security design reviews, architecture assessments, and cybersecurity technical exchanges with Government and contractor personnel. * Serve as the primary technical cybersecurity advisor to Government stakeholders, program managers, system engineers, software developers, system administrators, and cybersecurity leadership. * Provide authoritative technical recommendations regarding cybersecurity risks, system vulnerabilities, security controls, architecture decisions, and remediation strategies. * Analyze system and security logs to identify anomalous activity, indicators of compromise, and emerging security threats. * Provide senior-level technical expertise during cybersecurity incident response, containment, mitigation, and recovery activities. * Assist with forensic investigations and root-cause analysis involving suspected or confirmed cybersecurity incidents. * Develop and implement technical solutions to address complex cybersecurity vulnerabilities and compliance deficiencies. * Evaluate the integration and effectiveness of security technologies, including SIEM, IDS/IPS, firewalls, endpoint security, vulnerability management, identity and access management, encryption, and other defensive cybersecurity capabilities. * Provide technical oversight and mentorship to junior cybersecurity engineers and other technical personnel. * Participate in intelligence-community, DoD, industry, and technical working groups to evaluate emerging cybersecurity technologies, threats, standards, and engineering practices. * Translate evolving cybersecurity policies, standards, threat information, and mission requirements into actionable engineering requirements. * Support cybersecurity assessments, audits, inspections, accreditation activities, and other Government compliance requirements. * Maintain current knowledge of DoD cybersecurity policies, NIST standards, DISA guidance, RMF requirements, Zero Trust principles, and emerging cybersecurity threats. * Perform other related cybersecurity engineering and systems security duties as assigned. ## Related Videos - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1520-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Fault Tolerance and Consistency at Scale: Harnessing the Power of Distributed SQL Databases](https://www.wearedevelopers.com/videos/1146-fault-tolerance-and-consistency-at-scale-harnessing-the-power-of-distributed-sql-databases) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Giving the individual control of their data: Open Source Decentralized Web Nodes](https://www.wearedevelopers.com/videos/1100-giving-the-individual-control-of-their-data-open-source-decentralized-web-nodes) ## Related Articles - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)