> Markdown version of [/jobs/ext/2962597-cybersecurity-information-system-security-engineer](https://www.wearedevelopers.com/jobs/ext/2962597-cybersecurity-information-system-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity Information System Security Engineer - **Company:** LMI - **Location:** Fort Belvoir, VA, United States - **Experience:** Expert - **Salary:** $92,075.0 - $158,138.0 - **Contract:** Contract - **Skills:** Agile Methodology, Systems Engineering, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Information Systems, Computer Networks, Continuous Delivery, Continuous Integration, Data Integrity, Infrastructure as a Service (IaaS), Information Security Management, Network Security, Platform as a Service (PAAS), Software Engineering, Information Technology, Cybercrime, Devsecops, Vulnerability Analysis - **Published:** September 17, 2026 - **Apply:** https://careers-lmi.icims.com/jobs/14386/cybersecurity-information-system-security-engineer---clearance-required/job?mode=apply&apply=yes&in_iframe=1&hashed=-336058770 ## About the Role * In-depth knowledge of computer networking concepts, protocols, and methodologies to ensure effective network security. * Expertise in risk management processes, including methodologies for identifying, assessing, and mitigating risks. * Comprehensive understanding of national and international laws, regulations, policies, and ethical standards impacting cybersecurity operations. * Proficient knowledge of core cybersecurity principles and best practices for protecting information systems and data. * Awareness of cyber threats, vulnerabilities, and emerging attack vectors that could compromise systems and information. * Strong understanding of the specific operational impacts that cybersecurity lapses can impose on systems, data integrity, and organizational objectives. * Expertise in cloud computing service models, including Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS). * Solid understanding of cloud computing deployment models, including private, public, hybrid, and the key differences between on-premises and off-premises environments. * Knowledge of cloud computing deployment models in private, public, and hybrid environment and the difference between on-premises and off-premises environments., * Active SECRET security clearance (minimum requirement). * Bachelor's degree in Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, or Software Engineering from an ABET-accredited or NCAE-C designated institution. * 5+ years of hands-on experience in system and/or security engineering within U.S. Government systems. * Practical experience working within government cloud platforms (e.g., Azure, Amazon C2S, Commercial Cloud, or GovCloud), including secure implementation of security planning, design, and operations. * Proven ability to develop and maintain Risk Management Framework (RMF) documentation, including System Security Plans (SSPs) and Plans of Action and Milestones (POAMs). * Experience working with DoD technologies, systems, and command & control policies and procedures. * Hands-on experience utilizing Enterprise Mission Assurance Support Service (eMASS) for compliance management and reporting. * Familiarity with federal IT security requirements, including DoD cyber regulations, FedRAMP, and FISMA compliance. * Knowledge of DoD STIGs, SRGs, and security requirements outlined in NIST SP 800-53 and its corresponding assessment procedures. * Strong communication and interpersonal skills, capable of effectively interacting with both technical teams and non-technical stakeholders. * One or more of the following certifications: GISF, Security+, CASP+, CSSP, Cloud+, CSSLP, GSEC, or GSEC-equivalent. (If not currently held, must obtain within the first 30 days of employment). Preferred Additional Qualifications: * Expertise in cloud security planning, design, and operations. * Experience with systems engineering lifecycle processes and Agile development methodologies. * Familiarity with Continuous Integration/Continuous Delivery (CI/CD) frameworks and DevSecOps practices. * Tactical military experience is strongly preferred., Applicants must meet eligibility requirements for a U.S. Government security clearance. Only US Citizens are eligible for a security clearance. For this position, LMI will only consider applicants with security clearances or applicants who are eligible for security clearances, due to the nature of the work. ## Description * Collaborate with system engineers, program managers, and Authorizing Officials (or their delegates) to define and implement system security requirements. * Lead efforts to ensure continuous monitoring and verification of cybersecurity requirements throughout the system lifecycle. * Serve as a trusted cybersecurity advisor, providing guidance and recommendations to government stakeholders and contractor teams. * Design, review, and refine system security architectures for cloud, on-premises, and hybrid environments. * Support the Risk Management Framework (RMF) process to achieve and maintain Authority to Operate (ATO) approvals. * Identify, track, and mitigate security control gaps and areas of non-compliance, ensuring alignment with security standards. * Conduct risk assessments, vulnerability assessments, and develop and maintain critical documentation, such as System Security Plans (SSPs). * Manage and facilitate Interim Authority to Test (IATT) activities, risk assessments, and all ATO-related processes. * Analyze and interpret security control deficiencies to assess their impact on enterprise risk levels and cybersecurity program effectiveness. * Partner with the Information System Security Manager (ISSM) and product teams to identify control gaps, propose mitigations, and prepare Program of Action and Milestone (POAM) plans for ATO submission. * Guide system engineers on the mitigation of vulnerability findings using state-of-the-art security scanning tools, DoD policies, and industry best practices. * Provide cybersecurity engineering expertise in evaluating alternatives, assessing trade-offs, and recommending risk treatment strategies. * Collaborate with cross-functional teams to ensure the delivery of secure and dependable systems. * Develop and maintain dashboards to monitor platform system controls, logs, and compliance status, ensuring seamless reporting. * Demonstrate expertise in implementing cloud cybersecurity solutions and practices. * Apply NIST SP 800-53 Revision 4 or 5 security controls and security assessment procedures from NIST SP 800-53A. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Fighting the Next Wave of Cybercrime](https://www.wearedevelopers.com/videos/100331-fighting-the-next-wave-of-cybercrime) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)