> Markdown version of [/jobs/ext/2898461-information-system-security-engineer](https://www.wearedevelopers.com/jobs/ext/2898461-information-system-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Engineer - **Company:** Nabout Leidos - **Location:** United States - **Experience:** Expert - **Salary:** $107,900.0 - $195,050.0 - **Contract:** Contract - **Skills:** Cloud Computing, Cyber Security, Security Software, Software Vulnerability Management, Computer Networking Systems, Information Technology, Data Analytics, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 14, 2026 - **Apply:** https://jobs.military.com/career/336693/senior-information-system-security-engineer-remote ## About the Role u2022 Bachelor's degree and 8-12 years of prior relevant experience or Master's with 6-10 years of prior relevant experience in Cybersecurity, Information Security, IT, EE, Network Engineering, Computer Science, or related field. \n \u2022 Must be a US Citizen and possess an active DoD Secret Clearance.\n \u2022 Hold an active security certification that meets DOD 8570 IAT level III or higher.\n \u2022 Must have complete understanding of the RMF steps, especially Steps 4 through Steps 7.\n \u2022 Ability to identify upon review of a system authorization boundary and its components to identify all applicable STIGs.\n \u2022 Ability to decompose a security control/security check and ensure the provided artifact and test result satisfies said control/AP/check.\n \u2022 Understanding of techniques and tactics used to exploit systems (MITRE ATTACK) to determine risk and possible mitigations.\n \u2022 Ability to understand technical mitigations/know resources to identify proper mitigating factors (i.e. https://attack.mitre.org/mitigations/enterprise/).\n \u2022 Experience with eMASS to include control inheritance, TR Import, and POAM import functionality.\n \u2022 Support conducting cybersecurity authorization activities to comply with all current Cybersecurity and IA manuals, instructions, and guides within the DoDI 8500.01, DON 5239, the RMF Process Guide, and the RMF Risk Assessment Guide.\n \u2022 Verify patch compliance using the approved technical solution (i.e., Assured Compliance Assessment Solution (ACAS)), Information Assurance Vulnerability Alert (IAVA) compliance dashboards, and Microsoft Defender for Endpoints.\n \u2022 Assist with the implementation of security procedures, and verify information system security requirements, including coordinating the execution, review, and disposition of Security Technical Implementation Guide (STIG) checklists for systems, applications, developed code and other components.\n \u2022 Independently develop and maintain system security documentation, including drafting, reviewing, editing and recommending guidance for Standard Operating Procedures (SOP), Tactics, Techniques, & Procedures (TTP), Plan of Action and Milestones (POA&M) and Federal Information Security Management Act (FISMA) Score Card.\n \u2022 Assist with the development and application of business processes to ensure they have the appropriate level of security.\n \u2022 Discuss and document the Ports, Protocols and Services (PPS) to include ensuring the dataflows are accurate, CAL boundaries crossed are compliant, and registrations with the AO are completed per DODI 8551.1\n \u2022 Hands-on experience with a variety of cybersecurity tools.\n \u2022 Hands-on experience in working with DoD networks.\n \u2022 Experience in FISMA and other information assurance assurance-related compliance reporting.\n \u2022 Attention to detail is a must.\n \u2022 Ability to multi-task, self-assign work in a dynamic, fast-paced environment.\n \u2022 Analytical, communication and troubleshooting skills that enable proactive and effective collaboration with a virtual team, including the ability to clearly articulate status and present to both customers and program leadership.\n \u2022 Experience in one of the following areas: cybersecurity assessment, vulnerability scanning, integration and testing, data analytics or security operations.\n \u2022 Experience leading cybersecurity tasks and collaborate with customers, stakeholders, and team members.\n \u2022 Knowledge of cybersecurity assessment and authorization (A&A) and associated processes, procedures, and activities in accordance with DoDID 8500.01, DoDI 8551.01, the RMF Process Guide, the RMF Risk Assessment Guide, and other applicable NIST instructions, guidelines.\n \u2022 Experience supporting the formal Cybersecurity/IA testing required by government accrediting authorities and preparing System Security Plans.\n \u2022 Communication abilities, both verbal and written, including business writing on complex topics. Able to reach out across different teams and disciplines to include internal/external stakeholders.\n \u2022 Understanding of supporting security initiatives, conducting security monitoring, reporting and maintaining security compliance following security regulations and policies.\n \u2022 Knowledge of Security Engineering and Architecture, Assessment and Authorization, Vulnerability Assessment, Incident Management, Vulnerability Management, Security Operations, and Policy and Program Development.\n \u2022 Motivated self-starter with ability to lead and work in a matrix organization and communicate effectively with peers and program leadership.\n, u2022 Hands-on experience in working with Cloud Authorizations.\n \u2022 Hands-on experience in working with NMCI authorizations.\n \u2022 Experience with ITIL processes and/or ITIL Foundation V4 certification.\n \u2022 An entrepreneurial spirit with the ability to drive innovation independently; have a passion to improve at every opportunity.\n \u2022 Proven ability to credibly coordinate between technical teams and business stakeholders.\n ## Description u2022 Serve as a primary information system security engineer (ISSE) for Authorization to Operate (ATO) packages under the Navy Risk Management Framework (RMF).\n \u2022 Assist in the development and review of ATO submissions and coordinate all updates and corrections to assessment and authorization (A&A) artifacts.\n \u2022 Evaluate software and hardware during pre-acquisition phases to determine its ability to meet minimum security requirements based on NIST SP 800-53 Rev 5 security controls.\n \u2022 Author, review, coordinate and submit cybersecurity authorization required artifacts to eMASS (including change requests) to achieve milestones such as Interim Authority to Test (IATT) and ATO in accordance with the project schedule. \n \u2022 Support conducting cybersecurity authorization activities to comply with all current Cybersecurity and IA manuals, instructions, and guides within the DoDI 8500.01, DON 5239, the RMF Process Guide, and the RMF Risk Assessment Guide.\n \u2022 Continuously monitor system resources through automated scanning and implement automated reporting feeds to support cybersecurity authorizations.\n \u2022 Verify patch compliance using the approved technical solution (i.e., Assured Compliance Assessment Solution (ACAS)), Information Assurance Vulnerability Alert (IAVA) compliance dashboards, and Microsoft Defender for Endpoints.\n \u2022 Coordinate with local administrators to troubleshoot and elevate patching issues in a timely manner in order to meet patch compliance timelines.\n \u2022 Assist with the implementation of security procedures, and verify information system security requirements, including coordinating the execution, review, and disposition of Security Technical Implementation Guide (STIG) checklists for systems, applications, developed code and other components.\n \u2022 Independently develop and maintain system security documentation, including drafting, reviewing, editing and recommending guidance for Standard Operating Procedures (SOP), Tactics, Techniques, & Procedures (TTP), Plan of Action and Milestones (POA&M) and Federal Information Security Management Act (FISMA) Score Card.\n \u2022 Participate in regular briefings with the customer on cybersecurity statuses, including preparing briefing materials. Work closely with government Cyber team to support ATO conditions and requirements.\n \u2022 Support site visits / audits, including System Readiness Reviews (SRR).\n \u2022 Ensure secure, effective and efficient operation of network systems, architecture, and topology.\n \u2022 Assist with the development and application of business processes to ensure they have the appropriate level of security. \n \u2022 Participate in strategic network, security, and operations new technology planning.\n \u2022 As a cybersecurity authorization services security expert, assist the engineering managers in employing approved defense-in-depth principles and practices (e.g., defense-in-multiple places, layered defenses, and security robustness)\n \u2022 Discuss and document the Ports, Protocols and Services (PPS) to include ensuring the dataflows are accurate, CAL boundaries crossed are compliant, and registrations with the AO are completed per DODI 8551.1.\n \u2022 Develop innovative solutions to complex, cross-discipline cybersecurity authorization challenges spanning multiple technical areas.\n \u2022 Serve as a technical point of contact with external stakeholders, including subcontractors and vendors, on cybersecurity authorization matters.\n \u2022 Influence project and government team leadership on ISSE solution design, process, and approach decisions.\n \n ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [PySpark - Combining Machine Learning & Big Data](https://www.wearedevelopers.com/videos/44-pyspark-combining-machine-learning-big-data) - [Green Cloud Computing](https://www.wearedevelopers.com/videos/592-green-cloud-computing) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)