> Markdown version of [/jobs/ext/3300969-senior-information-system-security-engineer-isse](https://www.wearedevelopers.com/jobs/ext/3300969-senior-information-system-security-engineer-isse). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information System Security Engineer (ISSE) - **Company:** B.R.S. Inc. - **Location:** Bethesda, MD, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Apple Mac Systems, BitLocker Drive Encryption, Cyber Security, Information Systems, Linux, Information Security Management, Key Management, Microsoft Security Essentials, Information Technology Security Auditing, Security Content Automation Protocol, Security Information and Event Management, Microsoft Sentinel, Splunk, Vulnerability Analysis - **Published:** September 17, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ddff7fb8a8bc0d59 ## About the Role * Minimum 5 years of cybersecurity engineering, information assurance, or security compliance experience, preferably supporting Federal or DoD environments. * Active DoD Secret security clearance required. * Current DoD IAT Level II-compliant certification, such as Security+ CE, CySA+, or GSEC, as applicable to current DoD requirements. * Demonstrated experience implementing or assessing DISA STIGs and DoD cybersecurity requirements. * Experience with vulnerability assessment, remediation tracking, and security configuration validation. * Working knowledge of the DoD Risk Management Framework (RMF) and A&A processes. * Experience developing or maintaining cybersecurity documentation, including STIG checklists, POA&Ms, security control evidence, and ATO artifacts. * Experience with enterprise endpoint security technologies and Windows endpoint security controls. * Knowledge of encryption technologies and key-management concepts, including BitLocker and FileVault. * Ability to analyze technical security findings and communicate risks and remediation recommendations to technical and non-technical stakeholders. Preferred: * Advanced cybersecurity certification such as CISSP, CISM, or CASP+/SecurityX, as applicable. * Microsoft security certification relevant to Microsoft Defender, Microsoft 365, or security operations. * Experience with Microsoft Defender security technologies. * Experience with DISA STIGs, STIG Viewer, and SCAP compliance tools. * Experience with ACAS, eMASS, RMF, and A&A processes. * Experience with Splunk SIEM and/or Microsoft Sentinel. * Experience with BitLocker and FileVault. * Experience with Trellix/ePO environments. * Experience supporting Windows, macOS, and Linux endpoint security. * Experience developing and tracking POA&Ms through remediation and closure. ## Description The Senior ISSE will serve as a key cybersecurity engineering and compliance resource responsible for ensuring Microsoft Defender configurations, endpoint security controls, and transition activities align with Department of Defense (DoD) cybersecurity requirements and applicable Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs)., * Perform STIG assessments, security hardening, and compliance validation for Microsoft Defender tenant configurations and Windows, macOS, and Linux endpoints. * Conduct Security Content Automation Protocol (SCAP) scans and manual configuration reviews to validate DISA STIG compliance. * Develop and maintain STIG Compliance Checklists and supporting security documentation required for enterprise deployment. * Identify security findings, recommend corrective actions, and coordinate remediation to achieve required compliance thresholds, including resolution of Category I findings. * Validate endpoint security safeguards before removal of legacy Trellix components, including BitLocker and FileVault encryption and associated key escrow. * Verify security audit and telemetry integration with Splunk Security Information and Event Management (SIEM) and Microsoft Sentinel. * Review security exceptions, deployment variances, and enclave-specific requirements and assess associated cybersecurity risks. * Support the Risk Management Framework (RMF) lifecycle, including development, maintenance, and submission of Assessment & Authorization (A&A) artifacts and Authorization to Operate (ATO) documentation within eMASS. * Perform vulnerability assessments and patch-compliance verification using Assured Compliance Assessment Solution (ACAS). * Develop, maintain, and track Plans of Action and Milestones (POA&Ms) through remediation and closure. * Coordinate with cybersecurity, endpoint engineering, infrastructure, and operational stakeholders to ensure security requirements are incorporated throughout the Microsoft Defender transition. * Provide cybersecurity engineering recommendations and technical guidance to program leadership and Government stakeholders. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers)