Cybersecurity Engineer / Information Systems Security Engineer

NORTEX CYBER SOLUTIONS, LLC
Fort Meade, MD, United States
6 days ago
Apply on www.thejobnetwork.com
Prepare application

Role details

Contract type
Contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Working hours
Regular working hours

Tech stack

Xacta Agile Methodology Artificial Intelligence Configuration Management Collaborative Software CompTIA Security+ Cyber Security Information Systems Continuous Integration Package Management Systems Systems Integration Software Vulnerability Management
+8 more
Workflow Management Systems Privacy Controls Scripting Information Technology Nessus CIS Benchmarks Devsecops Vulnerability Analysis

Job description

Nortex Cyber Solutions is seeking an experienced Cybersecurity Engineer / Information Systems Security Engineer (ISSE) to support the security authorization, assessment, and continuous monitoring of mission-critical information systems.

This position requires a strong technical understanding of the Risk Management Framework (RMF), security controls, system hardening, vulnerability management, and the development and maintenance of authorization packages. The ideal candidate can independently evaluate system security, identify and document risk, maintain traceable bodies of evidence, and work with engineering teams to implement practical security solutions throughout the system lifecycle.

The individual must be comfortable working within classified environments and accessing and maintaining security packages within NSA environments.

Duties/Responsibilities:

· Support the full Risk Management Framework (RMF) lifecycle for information systems seeking or maintaining authorization.

· Develop, review, maintain, and update system security authorization packages and supporting bodies of evidence.

· Apply and interpret security controls and requirements in accordance with NIST SP 800-53 and DoD Instruction 8510.01 (RMF for DoD IT).

· Use security package management and governance tools such as eMASS and Xacta to develop, maintain, track, and manage system authorization documentation.

· Scope security assessments and conduct assessments of information systems undergoing accreditation/authorization or maintaining an existing authorization.

· Support the preparation, coordination, and approval of Interim Authorizations to Test (IATTs) for systems requiring testing prior to full authorization.

· Evaluate system configurations against applicable DISA Security Technical Implementation Guides (STIGs), CIS Benchmarks, and other security configuration standards.

· Conduct and analyze vulnerability assessments using tools such as ACAS/SecurityCenter and Nessus.

· Review vulnerability scan results, determine applicability and risk, track remediation activities, and support the development and maintenance of Plans of Action and Milestones (POA&Ms), as applicable.

· Work closely with system engineers, developers, and other technical stakeholders to implement and validate security controls.

· Support the implementation of automated solutions for continuous monitoring of security controls, vulnerabilities, configurations, and other security requirements.

· Identify opportunities to improve RMF, assessment, evidence collection, and continuous monitoring processes through automation.

· Appropriately leverage AI-enabled tools when beneficial while maintaining sufficient cybersecurity and RMF expertise to independently understand, validate, and take responsibility for the intended outcome.

· Maintain organized, accurate, and traceable documentation demonstrating the relationship between security requirements, implemented controls, assessment results, findings, remediation activities, and supporting evidence.

· Participate in Agile development and engineering environments and work effectively within SAFe Agileprocesses.

· Communicate security risks, findings, and requirements clearly to both cybersecurity and engineering stakeholders.

Requirements

· Active TS/SCI clearance with CI Polygraph required at time of hire.

· Ability to access required classified environments and security packages within NSA systems.

· Strong working knowledge of the DoD Risk Management Framework (RMF) and the complete authorization lifecycle.

· Strong knowledge of NIST SP 800-53 security and privacy controls and DoDI 8510.01.

· Experience developing, reviewing, and maintaining RMF authorization packages and supporting bodies of evidence.

· Hands-on experience with eMASS and/or Xacta for security package and authorization management.

· Strong understanding of DISA STIGs, CIS Benchmarks, system hardening, and security configuration requirements.

· Experience using ACAS/SecurityCenter and Nessus for vulnerability scanning, analysis, and remediation support.

· Experience scoping and conducting security assessments for information systems undergoing or maintaining authorization.

· Knowledge of the IATT process and experience supporting systems requiring authorization for testing.

· Understanding of continuous monitoring requirements and approaches for validating security controls throughout the system lifecycle.

· Ability to work with technical teams to develop or implement automation supporting cybersecurity and continuous monitoring activities.

· Familiarity with SAFe Agile or similar Agile development environments.

· Strong written and verbal communication skills.

· Exceptional attention to detail, organization, documentation, and configuration management.

· Ability to maintain clear traceability across security requirements, implementation details, assessment procedures, findings, and supporting evidence.

Preferred Qualifcations

· Experience supporting NSA, DoD, or Intelligence Community information systems.

· Experience working directly with system owners, ISSMs, ISSOs, security control assessors, and Authorizing Official representatives.

· Experience with continuous monitoring and automated security control validation.

· Experience integrating security activities into CI/CD or DevSecOps environments.

· Experience developing scripts, workflows, or other automation to improve security assessment, evidence collection, vulnerability management, or compliance processes.

· Familiarity with AI-assisted cybersecurity or compliance workflows, with the technical expertise necessary to independently verify AI-generated outputs.

· Relevant cybersecurity certifications such as Security+, CISSP, CAP/CGRC, CASP+/SecurityX, or equivalent.

Education & Experience

· Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field preferred.

· 10+ years of relevant cybersecurity, information assurance, RMF, or systems security engineering experience.

· Equivalent combinations of education, certifications, and directly relevant experience may be considered.

Physical Requirements

· Ability to remain seated and work at a computer for extended periods.

· Ability to occasionally lift up to 15 pounds.

· Ability to communicate effectively in person and through virtual collaboration tools.

Benefits & conditions

As an Employee First company, we offer a comprehensive and competitive total rewards package:

· 100% Company-paid medical insurance for employees

· 100% Company-paid dental and vision insurance

· Competitive salary

· Generous 401k employer contribution to your 401k with no required personal contribution with immediate vesting

· Generous PTO and parental leave

· Flexible work hours

This role requires use of technical data subject to U.S. Government contract restrictions; therefore, this posting is only for U.S. Citizens.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.thejobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:07 min

Integrating security practices for devsecops adoption

Nevelina Aleksandrova · LIVE

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all