Information Systems Security Engineer

JMA Resources, Inc.
Mechanicsburg, PA, United States
13 days ago
Apply on www.thejobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$90,000.0 - $115,000.0
Working hours
Regular working hours

Tech stack

Systems Engineering Cyber Security Information Systems Federal Information Processing Standards (FIPS) Information Systems Security Architecture Professional Software Vulnerability Management Information Security Management System Information Technology Plan of Action and Milestones

Job description

JMA Resources is seeking a highly motivated Information Systems Security Engineer (ISSE) to join our team. In this role, you will assess and validate the implementation of approved security controls and evaluate system weaknesses. You will prepare security assessment reports with findings and results, as well as supporting documentation and remediation efforts. As a trusted partner to both the client and team, the ISSE ensures compliance, strengthens security posture, and supports operational objectives., * Oversee the development and maintenance of a systems cybersecurity solutions.

  • Identify Authorizing Official (AO) and Security Control Assessor (SCA) cognizance of the system, as well as any specific authorization requirements such as reciprocity, cross-domain, and applicable overlays to support system categorization
  • Identify and tailor the security control baseline with applicable overlays.
  • Assist with the development, maintenance, and tracking of the System Security Plan (SP).
  • Lead the security control implementation and testing efforts.
  • Perform vulnerability-level risk assessment on the Plan of Action and Milestones (POA&M) or Corrective Action Plan (CAP).
  • Execute security testing required as part of Assessment & Authorization (A&A) or annual reviews.
  • Ensure the mitigation and closure of open vulnerabilities under the systems change control process.
  • Plan and perform cybersecurity testing to assess security controls and record security control compliance status during sustainment.
  • Oversee cybersecurity testing to assess security controls and record security control compliance status during the continuous monitoring phase of the lifecycle.
  • Ensure data entered in the Enterprise Mission Assurance Support Services (eMASS) record and POA&M is consistent with implementation results.
  • Utilize the Collaboration Board in the eMASS for all formal coordination during the RMF process; post detailed findings in the Artifacts tab as required.
  • Document and provide all requested rework to the Program Security Office (PSO) or Program Management Office (PMO) for review.
  • Participate in the system engineering process to ensure the system’s security and cybersecurity requirements, design, and testing are addressed throughout the system lifecycle.
  • Carry out other related duties as assigned, demonstrating flexibility and adaptability in meeting evolving client and company needs.

Requirements

  • Current or ability to obtain a Department of Defense (DoD) Secret Clearance is required.Note: To obtain a security clearance, you must be a U.S. citizen and meet the 13 adjudicative guidelines., * 3+ years of experience in information security engineering, system assessment, or related field, including experience in:
  • Documenting RMF A&A requirements (U.S. Navy RMF process preferred).
  • Performing RMF testing of all CS requirements and analysis needed to complete an RMF package for submittal and approval.
  • Conducting vulnerability risk analysis and documenting deficiencies found during RMF testing.
  • Using IA tools and scanners to evaluate the security posture of the system/enclave.
  • Managing documentation within eMASS.
  • Working knowledge of the RMF and A&A processes.
  • Strong understanding of federal security standards, including FISMA, FIPS, and NIST Special Publications.
  • Proficiency in vulnerability management processes, security control implementation, and audit preparation.
  • Strong analytical and problem-solving skills.
  • Excellent verbal and written communication skills for preparing documentation and collaborating with cross-functional teams.
  • Attention to detail and accuracy.
  • Ability to work independently as well as in a collaborative team environment.
  • Flexibility to adapt to changing priorities while supporting both team members and client requirements.
  • Must hold one of the following certifications:
  • Certified Information Systems Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified Governance, Risk, and Compliance (CGRC)
  • GIAC Security Leadership (GSLC)
  • CompTIA Advanced Security Practitioner (CASP+)
  • Certified Chief Information Security Officer (C-CISO)

Preferred Qualifications:

  • Bachelors degree in Cybersecurity, Computer Science, Information Systems, or related field.
  • Understanding of the U.S. Navy RMF Process Guide.

Creating an Environment of Respect and Opportunity

Benefits & conditions

  • Position: Full Time
  • Work Arrangement:
  • Hybrid - On-site for a week a minimum, each quarter at our client site in Mechanicsburg, Pennsylvania.
  • Travel Requirements: Is required.
  • Location Preference: Must reside within a 6-hour drive of Mechanicsburg, Pennsylvania, due to client requirements.
  • Work Hours: A typical workday consists of eighthours, totaling a forty-hour workweek. We understand that there may be times when employees will need to adjust their work hours due to client needs or personal reasons. To help balance these demands, we offer some flexibility in work schedules.

What We Offer:

  • Competitive salary and discretionary bonuses.
  • Comprehensive health benefits, including medical, dental, and vision insurance.
  • Flexible Paid Time Off (PTO) and holidays to help you maintain a healthy work-life balance.
  • Opportunities for professional development and continued learning.
  • Hybrid/remote work arrangement with flexible hours.
  • 401(k) retirement plan with company match.
  • Employee recognition programs and company events.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.thejobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:08 min

Introduction to speakers and model-based systems engineering goals

Daniel Siegl +1 · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:09 min

Balancing data science skillings alongside systems engineering rigor

Nico Schmidt · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all