> Markdown version of [/jobs/ext/3138147-information-system-security-engineer-isse](https://www.wearedevelopers.com/jobs/ext/3138147-information-system-security-engineer-isse). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Engineer (ISSE) - **Company:** Kentro LLC - **Location:** Washington, United States - **Experience:** Expert - **Salary:** $150,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cloud Computing Security, Configuration Management, Encodings, Cyber Security, Information Systems, Continuous Integration, Federal Information Processing Standards (FIPS), Identity and Access Management, Information Security Management, Information Systems Security Engineering Professional, JSON, Python (Programming Language), Automation of Marketing, Windows PowerShell, Zero Trust Network Access, Security Information and Event Management, Systems Architecture, Systems Integration, Extensible Markup Language (XML), YAML, Data Processing, Scripting, Google Cloud, SARS Software Products, Data Classification, Large Language Models, Prompt Engineering, Model Validation, Information Technology, RSA Archer Platform, CIS Benchmarks, Restful APIs, Splunk, Devsecops, Qualys, Servicenow, Plan of Action and Milestones, Vulnerability Analysis - **Published:** September 29, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9199377/information-system-security-engineer-isse ## About the Role * Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or a related field. Equivalent experience may substitute. * 8+ years of experience in information security, with at least 5 years of hands-on RMF implementation and ATO support for federal or DoD systems. * Deep working knowledge of NIST SP 800-37, 800-53 Rev. 5, 800-53A, 800-137, and FIPS 199/200. * Demonstrated experience with eGRC or compliance automation platforms, preferably ServiceNow and RegScale. * Experience integrating security tools through REST APIs and working with structured data formats (JSON, XML, YAML). * Scripting or automation skills in Python, PowerShell, or similar languages for compliance data processing and tool integration. * DoD 8140 / 8570 IAT Level III or IAM Level II-III compliant certification, such as CISSP, CISM, or CGRC (formerly CAP). * Excellent written communication skills, with a track record of producing high-quality security documentation., * Hands-on experience authoring or consuming OSCAL content. * Experience applying generative AI or LLM tools in a regulated environment, including prompt design, output validation, and governance. * Familiarity with FedRAMP authorization processes, including FedRAMP 20x modernization efforts. * Knowledge of cloud security architecture in AWS GovCloud, Azure Government, or Google Cloud for Government. * Experience with DevSecOps pipelines and embedding security gates into CI/CD workflows. * Knowledge of CMMC, NIST SP 800-171, or the DoD Cybersecurity Reference Architecture. * Additional certifications such as CCSP, CISSP-ISSEP, CISA, AWS/Azure security specialty, or ServiceNow/RegScale platform training/certification. Clearance Requirement: * Must be able to obtain and maintain a Public Trust clearance. * US Citizen or Lawful Permanent Resident (Green Card) ## Description RMF Engineering and Authorization Support * Lead security engineering across all seven steps of the RMF lifecycle (NIST SP 800-37 Rev. 2), from categorization through continuous monitoring, for complex on-premises, cloud, and hybrid systems. * Build security and privacy requirements into system architecture and design reviews, applying NIST SP 800-53 Rev. 5 controls, tailored baselines, and applicable overlays. * Support to develop, review, and maintain authorization packages. These include System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and supporting artifacts. * Advise Authorizing Officials and stakeholders on risk posture, residual risk, and risk acceptance decisions. Compliance Automation and Architecture * Architect, configure, and administer GRC platforms (i.e. ServiceNow) and automated tools (i.e. RegScale, etc.) to automate control implementation tracking, evidence collection, assessments, and POA&M management. * Design a compliance-as-code approach using OSCAL to create machine-readable SSPs, component definitions, assessment plans, and results. * Integrate the eGRC platform and automated tools (i.e. RegScale) with enterprise tools through APIs. Examples include vulnerability scanners (Tenable, Qualys), SIEM (Splunk, Elastic), configuration management, CI/CD pipelines, and asset inventories. The aim is near-real-time compliance visibility. * Where applicable, build data exchanges with authoritative government systems of record such as ServiceNow, eMASS, CSAM, or Xacta. * Establish reusable control inheritance models, common control providers, and standardized component libraries across the client's system portfolio. AI-Enabled Security and Compliance * Evaluate, pilot, and put into operation automated/AI tools that support compliance work. Uses include drafting control implementation narratives, mapping controls across frameworks, analyzing evidence, identifying gaps, and prioritizing POA&M items. * Set up human-in-the-loop review processes, validation criteria, and quality controls so that AI-generated content is accurate, traceable, and defensible to assessors. * Assess AI tools and systems against relevant security and governance requirements, including the NIST AI Risk Management Framework (AI RMF 1.0), applicable OMB AI guidance, and agency AI policies. Address data handling, model risk, and supply chain concerns. * Ensure AI tool use complies with data classification, CUI handling, and FedRAMP authorization requirements. Continuous Monitoring and Modernization * Design and implement Information Security Continuous Monitoring (ISCM) strategies that support ongoing authorization and cATO objectives. * Support Zero Trust Architecture initiatives aligned with federal and DoD Zero Trust strategies, and map ZT capabilities to control requirements. * Develop dashboards and metrics that give leadership clear, current views of compliance status, risk trends, and program maturity. * Oversee secure configuration baselines and hardening using DISA STIGs, SRGs, and CIS Benchmarks, and automate compliance verification where possible. Technical Leadership and Collaboration * Serve as a technical advisor to government leadership on RMF modernization and automation strategy, tool selection, and process improvement. * Develop standard operating procedures, playbooks, and training so ISSOs and system teams can use the new automated workflows. * Mentor junior security engineers and compliance analysts. * Communicate complex technical and risk concepts clearly to technical and non-technical audiences. ## Related Videos - [Tips and Tricks for Working with JSON](https://www.wearedevelopers.com/videos/1229-tips-and-tricks-for-working-with-json) - [CI/CD with Github Actions](https://www.wearedevelopers.com/videos/856-ci-cd-with-github-actions) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Introducing JSON Structure](https://www.wearedevelopers.com/videos/100219-introducing-json-structure) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)