> Markdown version of [/jobs/ext/2849430-information-systems-security-engineer](https://www.wearedevelopers.com/jobs/ext/2849430-information-systems-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Engineer - **Company:** JMA Resources, Inc. - **Location:** Mechanicsburg, PA, United States (Remote available) - **Experience:** Experienced - **Salary:** $90,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** Systems Engineering, Cyber Security, Information Systems, Federal Information Processing Standards (FIPS), Information Systems Security Architecture Professional, Software Vulnerability Management, Information Security Management System, Information Technology, Plan of Action and Milestones - **Published:** September 11, 2026 - **Apply:** https://www.thejobnetwork.com/job/4658f711-50ed-416c-b84c-2b22dd56c922/information-system-security-engineer-isse ## About the Role * Current or ability to obtain a Department of Defense (DoD) Secret Clearance is required.Note: To obtain a security clearance, you must be a U.S. citizen and meet the 13 adjudicative guidelines., * 3+ years of experience in information security engineering, system assessment, or related field, including experience in: + Documenting RMF A&A requirements (U.S. Navy RMF process preferred). + Performing RMF testing of all CS requirements and analysis needed to complete an RMF package for submittal and approval. + Conducting vulnerability risk analysis and documenting deficiencies found during RMF testing. + Using IA tools and scanners to evaluate the security posture of the system/enclave. + Managing documentation within eMASS. * Working knowledge of the RMF and A&A processes. * Strong understanding of federal security standards, including FISMA, FIPS, and NIST Special Publications. * Proficiency in vulnerability management processes, security control implementation, and audit preparation. * Strong analytical and problem-solving skills. * Excellent verbal and written communication skills for preparing documentation and collaborating with cross-functional teams. * Attention to detail and accuracy. * Ability to work independently as well as in a collaborative team environment. * Flexibility to adapt to changing priorities while supporting both team members and client requirements. * Must hold one of the following certifications: + Certified Information Systems Security Professional (CISSP) + Certified Information Security Manager (CISM) + Certified Governance, Risk, and Compliance (CGRC) + GIAC Security Leadership (GSLC) + CompTIA Advanced Security Practitioner (CASP+) + Certified Chief Information Security Officer (C-CISO) Preferred Qualifications: * Bachelors degree in Cybersecurity, Computer Science, Information Systems, or related field. * Understanding of the U.S. Navy RMF Process Guide. Creating an Environment of Respect and Opportunity ## Description JMA Resources is seeking a highly motivated Information Systems Security Engineer (ISSE) to join our team. In this role, you will assess and validate the implementation of approved security controls and evaluate system weaknesses. You will prepare security assessment reports with findings and results, as well as supporting documentation and remediation efforts. As a trusted partner to both the client and team, the ISSE ensures compliance, strengthens security posture, and supports operational objectives., * Oversee the development and maintenance of a systems cybersecurity solutions. * Identify Authorizing Official (AO) and Security Control Assessor (SCA) cognizance of the system, as well as any specific authorization requirements such as reciprocity, cross-domain, and applicable overlays to support system categorization * Identify and tailor the security control baseline with applicable overlays. * Assist with the development, maintenance, and tracking of the System Security Plan (SP). * Lead the security control implementation and testing efforts. * Perform vulnerability-level risk assessment on the Plan of Action and Milestones (POA&M) or Corrective Action Plan (CAP). * Execute security testing required as part of Assessment & Authorization (A&A) or annual reviews. * Ensure the mitigation and closure of open vulnerabilities under the systems change control process. * Plan and perform cybersecurity testing to assess security controls and record security control compliance status during sustainment. * Oversee cybersecurity testing to assess security controls and record security control compliance status during the continuous monitoring phase of the lifecycle. * Ensure data entered in the Enterprise Mission Assurance Support Services (eMASS) record and POA&M is consistent with implementation results. * Utilize the Collaboration Board in the eMASS for all formal coordination during the RMF process; post detailed findings in the Artifacts tab as required. * Document and provide all requested rework to the Program Security Office (PSO) or Program Management Office (PMO) for review. * Participate in the system engineering process to ensure the system's security and cybersecurity requirements, design, and testing are addressed throughout the system lifecycle. * Carry out other related duties as assigned, demonstrating flexibility and adaptability in meeting evolving client and company needs. ## Related Videos - [Model Based Systems Engineering in an Agile Product Development Process](https://www.wearedevelopers.com/videos/68-model-based-systems-engineering-in-an-agile-product-development-process) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)