> Markdown version of [/jobs/ext/2834353-information-systems-security-engineer](https://www.wearedevelopers.com/jobs/ext/2834353-information-systems-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Engineer - **Company:** Inc. (spa) - **Location:** Lorton, VA, United States - **Experience:** Expert - **Salary:** $180,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Access, Java (Programming Language), Amazon Web Services, Software Applications, Systems Engineering, Microsoft Azure, Burp Suite, C++ (Programming Language), Cloud Computing, Cloud Computing Security, Cloud Engineering, Configuration Management, Cyber Security, Linux, Monitoring of Systems, Identity and Access Management, Information Security Management, Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Python (Programming Language), Nmap, Fortify (Software), Ruby, SAP Implementation, Security Information and Event Management, Software Engineering, Systems Architecture, Trusted Systems, Software Vulnerability Management, Data Logging, Software Security, Information Technology, Nessus, Burpsuite, Vulnerability Analysis - **Published:** September 10, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9056328/information-systems-security-engineer ## About the Role * Ability to support onsite in Lorton Virginia, up to full-time, based upon the needs of the client * Master's degree in engineering, computer science, cybersecurity, networking, or programming * Requires experience working with Special Access Programs (SAPs), along with strong proficiency in cloud architecture and associated security elements * Must possess excellent analytical skills with the ability to quantify risk to enterprise systems and assess compliance with security policy, backed by 12+ years of technical experience in cybersecurity, information technology, or systems engineering * TS/SCI with CI Polygraph, and the ability to maintain this throughout employment Advanced knowledge in one or more of the following areas: * Secure systems engineering practices, including threat modeling, security architecture design, and/or system hardening * Software Development in Java, Python, Ruby and/or C++ * Linux Expertise * Dynamic & Static Application Security Scanning (e.g., OPSWAT, OWASP ZAP, BurpSuite, Fortify * Experience with vulnerability management tools (e.g., Tenable, Defender), SIEM technologies, and secure configuration baselines * Infrastructure Security Scanning, Vulnerability Scanning (NMAP, Azure Defender, AWS Inspector, ACAS/Nessus) Certification Requirements in one or more of the following: * Information Systems Security Engineering Professional (ISSEP) * Certified Cloud Security Professional (CCSP) * Certified Information Systems Security Professional (CISSP) * CompTIA Advanced Security Practitioner (CASP) * GIAC Cloud Security Essentials Certification (GCLD) Desired Qualifications: * Strong oral and written communication Skills. ## Description The Senior Cloud Information Systems Security Engineer (SCISSE) will support the Government Program Manager by integrating cybersecurity requirements into system architecture, design, and engineering activities from concept through deployment. Working across the system lifecycle, the SCISSE will develop and maintain security artifacts, including Security Plans, Security Controls Traceability Matrices, architectural diagrams, and engineering documentation. Responsibilities include performing security engineering analyses such as threat modeling, vulnerability assessments, and security impact analyses for proposed system changes. The SCISSE will select, tailor, and implement security controls in accordance with NIST SP 800-53, CNSSI 1253, the Joint SAP Implementation Guide, and other applicable cybersecurity frameworks. To support informed decision-making, the SCISSE will communicate engineering risk assessments, including mitigation strategies, residual risks, and risk-benefit recommendations. The role also encompasses requirements analysis, system design, and integration for complex software applications and collaboration infrastructures. As part of the configuration management process, the SCISSE will submit and review Change Requests while assessing the security implications of proposed modifications. Additional responsibilities include creating and maintaining information system security documentation, developing Standard Operating Procedures, and providing guidance on active Plans of Action and Milestones (POA&Ms). The SCISSE will conduct continuous and periodic monitoring of systems, documentation, and operational procedures to ensure ongoing compliance with authorization requirements. Close collaboration with ISSOs, system administrators, and development teams will be essential to remediate vulnerabilities, maintain secure system configurations, and support secure engineering practices. Working with multiple system owners, the SCISSE will address security-related design and integration requirements for hybrid environments while evaluating cloud technologies in areas such as encryption, identity and access management, boundary protection, logging, and monitoring. The position also supports incident response and forensic activities in coordination with cybersecurity teams and contributes to the development and execution of governance frameworks for managing and authorizing national security systems. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Coffee with Developers: David Heinemeier Hansson](https://www.wearedevelopers.com/videos/875-coffee-with-developers-david-heinemeier-hansson) - [Hacking MSSQL on Cloud. All of them. How I became sysadmin on Azure, AWS, GCP and Alibaba.](https://www.wearedevelopers.com/videos/100339-hacking-mssql-on-cloud-all-of-them-how-i-became-sysadmin-on-azure-aws-gcp-and-alibaba) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Coroutine explained yet again 60 years later](https://www.wearedevelopers.com/videos/690-coroutine-explained-yet-again-60-years-later) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)