Information Systems Security Engineer (ISSE) - Journeyman

Goldbelt
Mechanicsburg, PA, United States
3 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source

Tech stack

Systems Engineering Cyber Security Information Security Management System Information Technology

Job description

The Information Systems Security Engineer (ISSE) - Journeyman supports the design, implementation, and maintenance of cybersecurity architecture for systems and enclaves. This role focuses on executing RMF activities, supporting security control implementation, and assisting with system authorization efforts. Responsibilities: Essential Job Functions:

  • Support the development and maintenance of system cybersecurity architecture and solutions
  • Assist in identifying Authorizing Official (AO) and Security Control Assessor (SCA) cognizance and applicable authorization requirements (e.g., reciprocity, cross domain, overlays)
  • Help identify and tailor security control baselines in accordance with system categorization
  • Support development, maintenance, and tracking of the System Security Plan (SSP)
  • Assist in implementing and testing security controls
  • Perform vulnerability-level risk assessments and support POA&M/CAP tracking
  • Support execution of required security testing for Authorization & Accreditation (A&A) and annual reviews
  • Assist in preparing Security Assessment Plans (SAPs) with program support
  • Support mitigation and closure of vulnerabilities through change control processes
  • Execute cybersecurity testing to assess security controls and document compliance status
  • Ensure accurate data entry into eMASS and alignment with implementation results
  • Maintain traceability of vulnerabilities from assessment results to POA&M entries
  • Support development of the Security Assessment Report (SAR) and associated documentation
  • Utilize the eMASS Collaboration Board for RMF coordination and document findings in the Artifacts repository
  • Participate in system engineering activities to ensure cybersecurity requirements are integrated throughout the lifecycle

Requirements

  • Familiarity with RMF, NIST 800-53 controls, and DoD cybersecurity policies, * Minimum 2 years of experience of the following:
  • Experience in documenting RMF Assessment and Authorization requirements.
  • Experience in RMF testing of all CS requirements and analysis required to complete an RMF package document for submittal and approval.
  • Experience performing vulnerability risk analysis on the deficiencies found during RMF testing.
  • Must be able to supply total number of RMF authorizations performed.
  • Experience with IA tools and scanners used to evaluate the security posture of the system/enclave.
  • Experience with DoD-specific, DoN-specific, and NAVSUP-specific RMF services (including RMF package services) and using and complying with the Navy RMF Process Guide version 4.1 (or 4.0 or the latest version) and the NAVSUP FAO RMF Business Rules version 1.0 (or latest version).
  • Experience with concurrently supporting over 10 RMF packages.
  • Must have a Tier III Level Clearance

Preferred Qualifications:

  • Bachelor’s degree in Cybersecurity, Information Technology, Engineering, or related field

Benefits & conditions

Health insurance, 401(k) matching, Paid time off, Vision insurance, Dental insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

42 sec

Energy forecasts and resource demands of information technology

Marjolein Pordon · LIVE

4:08 min

Introduction to speakers and model-based systems engineering goals

Daniel Siegl +1 · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:09 min

Balancing data science skillings alongside systems engineering rigor

Nico Schmidt · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all