Senior Information Systems Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+13 more
Job description
- Secure Architecture Design: Engineer and integrate secure Information Assurance (IA) architectures, system components, networks, and Cross Domain Solutions (CDS).
- Risk Management Framework (RMF) Execution: Lead systems through the federal NIST Risk Management Framework process to successfully achieve and maintain an Authorization to Operate (ATO).
- Security Control Implementation: Define, tailor, and implement specific security baselines and control overlays (such as CNSS 1253 or NIST SP 800-53) into system designs.
- Vulnerability & Risk Assessments: Conduct complex vulnerability testing, threat modeling, and boundary analysis using tools such as ACAS, HBSS, or SIEM platforms. Document findings in Plan of Action and Milestones (POA&M) reports.
- Technical Subject Matter Expertise: Advise Program Managers, external stakeholders, and systems/test engineers to ensure hardware and software engineering choices meet rigid security policies.
- Continuous Monitoring & Compliance: Design and manage automated workflows, audit protocols, and patch management strategies to verify ongoing system compliance.
Requirements
- Clearance: Public Trust
- Education: Bachelor’s or Master’s degree in a STEM field (Computer Science, Cybersecurity, Systems Engineering, Information Technology, or related discipline).
- Experience: 10+ years of direct experience in systems engineering and information security operations.
- Framework Proficiency: Deep understanding of NIST SP 800-37 / 800-53, FIPS 199/200, and federal ICD 503 standards.
- Infrastructure & Cloud: Hands-on knowledge of secure configurations for Linux/Windows environments and cloud spaces (e.g., AWS GovCloud or Microsoft Azure).
- Networking & Security Tools: Expertise in TCP/IP, routing, firewalls, Intrusion Detection/Prevention Systems (IDS/IPS), Data Loss Prevention (DLP), and cryptographic configurations.
- Scripting & Automation: Basic proficiency in scripting languages like Python, PowerShell, or Bash to automate security testing and repetitive validation tasks.
- CISSP (Certified Information Systems Security Professional) - Highly Preferred.
- ISSEP (Information Systems Security Engineering Professional) - Preferred.
- CISM (Certified Information Security Manager) or CASP+ (CompTIA Advanced Security Practitioner).
Benefits & conditions
Eligible full-time employees receive a comprehensive benefits package, including medical, dental, vision, life and disability coverage, retirement savings with company match, and paid time off. Additional benefits include voluntary supplemental benefits, access to an employee assistance program, and educational assistance with tuition reimbursement.
About the company
Diné Development Corporation (DDC) is a Navajo Nation-owned family of companies that provides government agencies and commercial organizations with high-quality IT, professional, environmental, and research and development services. DDC is dedicated to empowering the Navajo Nation and the communities we serve.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this role…