> Markdown version of [/jobs/ext/2825759-nissc-3-information-systems-security-engineer-iii](https://www.wearedevelopers.com/jobs/ext/2825759-nissc-3-information-systems-security-engineer-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # NISSC 3 Information Systems Security Engineer III - **Company:** AMERICAN SYSTEMS - **Location:** Colorado Springs, CO, United States - **Experience:** Expert - **Salary:** $116,200.0 - **Contract:** Permanent contract - **Skills:** Adobe Analytics, Xacta, Cyber Security, Information Systems, Issue Tracking Systems, Package Development Process, Security Content Automation Protocol, Nessus, Checkmarx, Dynamic Application Security Testing - **Published:** September 10, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8740211/nissc-3-information-systems-security-engineer-iii ## About the Role * Education: Bachelors in IT, Cyber, CS, IS, Data Science, or SW Engineering OR equivalent DoW/Military training * Clearance: Top Secret/ SCI * Certifications: CCSP, Cloud+, CSC, GCLD, GSEC, and/or SecurityX/CASP+ certification. * Experience: 7-10 Years * Advanced knowledge of systems security engineering to design and implement technical security controls is critical. * Skills in performing configuration, vulnerability, and risk assessments, and setting up security tools ensure ongoing compliance with RMF, NIST, and DoW requirements. Capabilities in incident tracking, remediation, and participation in security assessments and authorization package development are necessary. * Proficiency in developing advanced security solutions and overseeing cybersecurity integration ensures robust protection for information systems. * Experience leveraging tools such as eMASS, XACTA, CORE, ACAS, SCAP tools, Nessus, Checkmarx, and/or ZAP DAST. Holds DoW 8140 qualifying certification. ## Description AMERICAN SYSTEMS is seeking an Information Systems Security Engineer III with 7-10 years of experience and a TS/SCI Clearance to support The North American Aerospace Defense Command (NORAD), Cheyenne Mountain Complex (NCMC) -Integrated Tactical Warning/Attack Assessment (NCMC-ITW/AA) and Space Support Contract III Mission., * Analyze, design, and implement technical security controls to protect information systems and support continuous compliance with RMF, NIST, and DoW requirements. * Perform configuration, vulnerability, and risk assessments, set up and validate security tools, and assist in the development/maintenance of assessment and authorization packages. * Participate in incident tracking and remediation and provide technical leadership, documentation, and guidance to support ongoing cybersecurity readiness. * Provide expertise in systems security engineering, develop advanced security solutions, oversee cybersecurity integration across systems. * Support vulnerability/risk assessments, authorization packages, and incident response activities. * Develop and submit security reports and threat analysis. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 129 - Now that's what I call private data!](https://www.wearedevelopers.com/magazine/468-dev-digest-129-now-that-s-what-i-call-private-data)