Information System Security Engineering (ISSE) Onsite

BDR Solutions
Quantico, VA, United States
6 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$160,000.0 - $175,000.0
Working hours
Regular working hours

Tech stack

Amazon Web Services Systems Engineering Microsoft Azure Cloud Computing Security Cyber Security Identity and Access Management Information Security Management Network Administration Systems Development Life Cycle Software Engineering SARS Software Products Information Technology
+3 more
Nessus Devsecops Vulnerability Analysis

Job description

BDR Solutions is seeking a highly motivated Information Systems Security Engineer (ISSE) to support a mission-critical Department of Defense customer. The ISSE will play a key role in the implementation, assessment, and maintenance of cybersecurity controls across classified information systems and networks. This individual will work closely with government stakeholders, system owners, developers, network administrators, and cybersecurity professionals to ensure systems comply with DoD cybersecurity requirements and maintain authorization to operate (ATO)., * Support the implementation and maintenance of cybersecurity requirements throughout the system development lifecycle.

  • Apply Risk Management Framework (RMF) principles and processes to support system authorization and continuous monitoring activities.
  • Develop, maintain, and update cybersecurity documentation, including:
  • System Security Plans (SSPs)
  • Security Assessment Reports (SARs)
  • Plans of Action & Milestones (POA&Ms)
  • Security Control Traceability documentation
  • Continuous Monitoring artifacts
  • Assist with the preparation and maintenance of Authority to Operate (ATO) packages.
  • Analyze systems and architectures to identify security risks, vulnerabilities, and compliance gaps.
  • Implement and validate security controls in accordance with NIST SP 800-53 requirements.
  • Conduct security assessments and recommend mitigation strategies to reduce cybersecurity risks.
  • Evaluate vulnerability scan results and coordinate remediation efforts with technical teams.
  • Support implementation and compliance activities related to:
  • DISA Security Technical Implementation Guides (STIGs)
  • Security Requirements Guides (SRGs)
  • DoD cybersecurity policies and directives
  • Collaborate with developers, engineers, ISSOs, and system administrators to ensure security requirements are integrated into system designs.
  • Participate in cybersecurity working groups, audits, inspections, and compliance reviews.
  • Support continuous monitoring activities and maintain cybersecurity posture across authorized systems.
  • Provide security engineering recommendations for new technologies, applications, and infrastructure changes.

Requirements

The ideal candidate brings strong Risk Management Framework (RMF) expertise, hands-on experience with NIST 800-53 security controls, and a proven ability to develop authorization documentation and security solutions within secure DoD environments., * Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Information Assurance, or related field.

  • 4-6 years of Information Systems Security Engineering, Cybersecurity, or Information Assurance experience supporting DoD or Federal Government environments.
  • Strong experience implementing and supporting the Risk Management Framework (RMF).
  • Demonstrated experience applying NIST SP 800-53 security controls.
  • Experience developing and maintaining:
  • System Security Plans (SSPs)
  • Security Assessment Reports (SARs)
  • Plans of Action & Milestones (POA&Ms)
  • Experience supporting Authority to Operate (ATO) processes.
  • Working knowledge of DoD cybersecurity policies, procedures, and compliance requirements.
  • Experience reviewing, implementing, and validating DISA STIGs and SRGs.
  • Strong analytical and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Ability to work effectively in a collaborative, mission-focused environment.

Candidates must possess an active TS/SCI clearance with a current CI Polygraph at the time of hire. Clearance sponsorship or polygraph processing will not be provided for this position.

Required Certifications

Must possess and maintain a current DoD 8140/8570 IAT Level II or IAM Level II certification, such as:

  • Security+ CE
  • CISSP
  • CASP+
  • CYSA+
  • Other DoD-approved equivalent certification

Preferred Qualifications

  • Experience supporting Intelligence Community (IC), DoD, or classified federal programs.
  • Experience with eMASS.
  • Experience with ACAS, Nessus, or other vulnerability assessment tools.
  • Experience supporting Continuous Monitoring (ConMon) programs.
  • Knowledge of cloud security principles (Azure Government, AWS GovCloud, etc.).
  • Familiarity with security architecture design and system engineering practices.
  • Experience supporting DevSecOps and secure software development initiatives.

The compensation range for this position is $160,000-175,000. Compensation decisions depend on a wide range of factors, including but not limited to location, skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs.

About the company

BDR Solutions, LLC, (BDR) supports the U.S. Federal Government in successfully achieving its mission and goals. Our service and solution delivery starts with understanding each client’s end-state, and then seamlessly integrating within each Agency’s organization to improve and enhance business and technical operations and deployments.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all