> Markdown version of [/jobs/ext/2846408-information-system-security-engineer](https://www.wearedevelopers.com/jobs/ext/2846408-information-system-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Engineer - **Company:** Navstar Inc. - **Location:** United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Agile Methodology, Application Layers, Software Applications, Systems Engineering, Acceptance Test-Driven Development, Behavior-Driven Development, C++ (Programming Language), Cloud Computing, Cyber Security, Continuous Integration, Enterprise JavaBeans, Java Platform Enterprise Edition (J2EE), Network Interface Controllers, Firmware, FitNesse, Global Positioning Systems (GPS), Information Security Management, Networking Hardware, Java Persistence API, Java Transaction API, Java API for RESTful Web Services (JAX-RS), Python (Programming Language), PostgreSQL, MongoDB, Network Architecture, Oracle (Applications), Pair Programming, Windows PowerShell, Mockito, Zero Trust Network Access, Requirements Management, Scaled Agile Framework, Selenium, Simple Object Access Protocol (SOAP), Software Engineering, SQL Databases, Web Services Description Language, Scripting, Computer Network Technologies, Test-Driven Development (TDD), Jax Ws, Cucumber (Software), Code Restructuring - **Published:** September 11, 2026 - **Apply:** https://www.thejobnetwork.com/job/1c5b6d9a-8e01-45f8-aa1e-20bed73b5140/information-system-security-engineer ## About the Role * Bachelor of Science degree from an accredited university ideally in Computer Science, Information Assurance, Information Security System Engineering or related field with a minimum of 14 years of experience as an Information Systems Security Engineer (ISSE) or System Engineer. \n * CISSP OR CASP certification required. \n * Strong writing skills. \n * Confidence and ability to present briefing to senior level DoD officials in both prepared briefings and/or in ad hoc discussions. \n * Expertise in the Risk Management Framework (RMF) and conducting cybersecurity risk assessments. \n * Expertise in network technology and systems security engineering. Experience in identifying, researching, characterizing, and documenting security weaknesses related to operating systems, software applications, firmware, network hardware components, as well as network architecture design to identify protection needs and documented policies and procedures. \n * Experience developing and documenting system security requirements and conducting requirements gap analysis. \n * Experience with security monitoring and incident response capabilities. \n * Experience with emerging technologies such as Zero Trust, Cloud Computing, etc. \n * Knowledge of, and practical experience with the NIST Special Publications 800 Series, CNSSI 1253, and DoD 8500. \n * Ability to work independently within a schedule and with little direction. \n, * Experience with the following: JEE (EJB, JPA, JTA, JAX-B, JAX-RS, JAX-WS), SQL, application servers (Tomcat, WebLogic, JBoss), scripting. \n * Experience with high level requirements management including requirements decomposition, secure systems engineering and development, trade-off analysis, interface control, and testing and continuous integration. \n * Experience in software development on Agile teams using Agile Developer practices such as Pair Programming, TDD, Refactoring, and ATDD. \n * Experience with FITNesse, Mockito, Cucumber, Unified Functional Tester (UFT), Selenium. \n * Experience with Behavior Driven Development (BDD). \n * Secure Software development (i.e., Layer 7 Policy). \n * Experience with the Scaled Agile Framework (SAFe) methodology, SAFe Agilest Certification, or experience as a member of an agile team. \n * Additional experience in J2EE, Python, C/C++, SQL, SOAP, WSDL, Postgres, Oracle, Mongo, PowerShell a plus. ## Description The Senior ISSE shall deliver and lead threat-informed cybersecurity products - cybersecurity risk assessments, architecture reviews, and engineering guidance that bring sound, accurate, timely, and actionable service to mission partners. This includes ## Related Videos - [Test-Driven Development: It's easier than you think!](https://www.wearedevelopers.com/videos/1598-test-driven-development-it-s-easier-than-you-think) - [40 Minutes to Build a Serverless COVID-19 REST and GraphQL APIs](https://www.wearedevelopers.com/videos/208-40-minutes-to-build-a-serverless-covid-19-rest-and-graphql-apis) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [ChatGPT and Java: A Match Made in Heaven or Hell?](https://www.wearedevelopers.com/videos/536-chatgpt-and-java-a-match-made-in-heaven-or-hell) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [NoSQL Data Modeling for Front-end Developers](https://www.wearedevelopers.com/videos/297-nosql-data-modeling-for-front-end-developers) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)