Information Systems Security Engineer - TS/SCI

Parsons Corporation
Centreville, VA, United States
5 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$88,400.0 - $154,700.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Windows Systems Engineering JIRA Microsoft Azure Bash Shell Configuration Management CompTIA Security+ Cyber Security Linux Elasticsearch Issue Tracking Systems Networking Hardware
+16 more
Python (Programming Language) Log Analysis Microsoft Visio Windows PowerShell Red Hat Enterprise Linux Security Content Automation Protocol Security Information and Event Management Software Vulnerability Management Scripting Information Security Management System Information Technology Tenable Nessus Patch Management OpenSearch Plan of Action and Milestones Vulnerability Analysis

Job description

We are seeking a highly skilled Information Systems Security Engineer (ISSE) / Cyber Systems Engineer to support our Department of Defense (DoD) system.

In this role, you will be the primary technical engineer responsible for mitigating vulnerabilities, ensuring system compliance, and maintaining the security posture of our systems. You will work directly with the ISSO to remediate findings identified in ACAS Vulnerability and SCAP scans, manage Jira tickets tied to the Plan of Action and Milestones (POA&M), and ensure continuous compliance with the NIST Risk Management Framework (RMF) and NIST SP 800-53 controls. This is a hands-on technical role requiring a strong background in vulnerability management, system patching, and scripting.

What You’ll Be Doing:

  • Vulnerability Management: Conduct monthly System Security Plan (SSP) ACAS Vulnerability Scans and quarterly ACAS Security Technical Implementation Guide (STIG) / SCAP Scans.
  • System Maintenance & Patching: Perform monthly SSP patch version upgrades to ensure systems remain secure and compliant.
  • Compliance & Auditing: Conduct annual manual STIG checks on system components that cannot be scanned automatically.
  • POA&M Remediation: Act as the primary technical remediator for POA&M findings, executing remediation tasks tracked via Jira tickets generated by the ISSO.
  • Incident & Alert Response: Assist the ISSO with investigating and responding to security alerts and logs.
  • Documentation & Configuration Management: Maintain and update critical security documentation, including network/system diagrams, Hardware/Software (HW/SW) lists, and Ports, Protocols, and Services Management (PPSM) documentation.
  • RMF Support: Assist the ISSO in drafting, updating, and maintaining NIST RMF documentation in accordance with NIST SP 800-53 guidelines.

Requirements

  • Active TS/SCI
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field (or equivalent years of relevant work experience).
  • Minimum of 4+ years of hands-on experience in cybersecurity engineering, systems administration, or a related technical role within a DoD or federal environment.
  • Must hold an active baseline certification for Information Assurance Technical (IAT) Level II or Level III (e.g., CompTIA Security+ CE, CASP+ CE, CISSP, or equivalent).
  • Proven hands-on experience using Assured Compliance Assessment Solution (ACAS) / Tenable Nessus for vulnerability and compliance scanning.
  • Strong technical background in applying and validating DISA STIGs across various operating systems (e.g., Windows, Linux) and network devices.
  • In-depth knowledge of the NIST Risk Management Framework (RMF) and NIST SP 800-53 security controls.
  • Experience with patch management and system upgrades in a secure, air-gapped, or highly regulated environment.
  • Familiarity with tracking workflows and remediating technical tasks using Jira or similar ticketing systems.
  • Ability to translate technical vulnerabilities into actionable remediation steps.
  • Excellent communication skills and the ability to work collaboratively with the ISSO and other stakeholders.
  • Advanced scripting skills (e.g., PowerShell, Python, Bash) to automate STIG application and compliance checks.

What Desired Skills You’ll Bring:

  • Advanced degree is preferred.
  • Experience configuring and analyzing logs within OpenSearch, Elasticsearch, or similar SIEM/log analysis tools.
  • Familiarity with DoD PPSM (Ports, Protocols, and Services Management) processes and registry requirements.
  • Operating System/Computing Environment (CE) certifications (e.g., Microsoft Certified: Azure Administrator, Red Hat Certified System Administrator).
  • Experience with developing network and rack diagrams in Visio.

Benefits & conditions

An active Top Secret SCI security clearance is required for this position.

This position is part of our Federal Solutions team.

The Federal Solutions segment delivers resources to our US government customers that ensure the success of missions around the globe. Our intelligent employees drive the state of the art as they provide services and solutions in the areas of defense, security, intelligence, infrastructure, and environmental. We promote a culture of excellence and close-knit teams that take pride in delivering, protecting, and sustaining our nation’s most critical assets, from Earth to cyberspace. Throughout the company, our people are anticipating what’s next to deliver the solutions our customers need now.

Salary Range: $88,400.00 - $154,700.00

We value our employees and want our employees to take care of their overall wellbeing, which is why we offer best-in-class benefits such as medical, dental, vision, paid time off, 401(k), life insurance, flexible work schedules, and holidays to fit your busy lifestyle!

This position will be posted for a minimum of 3 days and will continue to be posted for an average of 30 days until a qualified applicant is selected or the position has been cancelled.

About the company

Parsons is aware of fraudulent recruitment practices. To learn more about recruitment fraud and how to report it, please refer to https://www.parsons.com/fraudulent-recruitment/ ., Parsons is a digitally enabled solutions provider focused on the defense, security, and infrastructure markets. With nearly 75 years of experience, Parsons is uniquely qualified to deliver cyber/converged security, technology-based intellectual property, and other innovative services to federal, regional, and local government agencies, as well as to private industrial customers worldwide.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Loading talks and stories from around this role…