> Markdown version of [/jobs/ext/436568-nissc-3-information-systems-security-engineer-iii](https://www.wearedevelopers.com/jobs/ext/436568-nissc-3-information-systems-security-engineer-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # NISSC 3 Information Systems Security Engineer III - **Company:** AMERICAN SYSTEMS - **Location:** Colorado Springs, CO, United States - **Experience:** Expert - **Salary:** $116,200.0 - $194,000.0 - **Contract:** Permanent contract - **Skills:** Adobe Analytics, Xacta, Cyber Security, Information Systems, Issue Tracking Systems, Package Development Process, Security Content Automation Protocol, Nessus, Checkmarx, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** June 1, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=b62883c50976500f ## About the Role Do you have experience in Vulnerability scanning implementation?, Do you have a Bachelor's degree?, Education: Bachelors in IT, Cyber, CS, IS, Data Science, or SW Engineering OR equivalent DoD/Military training Clearance: Top Secret/ SCI Certifications: CCSP, Cloud+, CSC, GCLD, GSEC, and/or SecurityX/CASP+ certification. Experience: 7-10 Years * Advanced knowledge of systems security engineering to design and implement technical security controls is critical. * Skills in performing configuration, vulnerability, and risk assessments, and setting up security tools ensure ongoing compliance with RMF, NIST, and DoD requirements. Capabilities in incident tracking, remediation, and participation in security assessments and authorization package development are necessary. * Proficiency in developing advanced security solutions and overseeing cybersecurity integration ensures robust protection for information systems. * Experience leveraging tools such as eMASS, XACTA, CORE, ACAS, SCAP tools, Nessus, Checkmarx, and/or ZAP DAST. Holds DoD 8140 qualifying certification. ## Description AMERICAN SYSTEMS is seeking an Information Systems Security Engineer III with 7-10 years of experience and a TS/SCI Clearance to support The North American Aerospace Defense Command (NORAD), Cheyenne Mountain Complex (NCMC) -Integrated Tactical Warning/Attack Assessment (NCMC-ITW/AA) and Space Support Contract III Mission. Responsibilities: * Analyze, design, and implement technical security controls to protect information systems and support continuous compliance with RMF, NIST, and DoD requirements. * Perform configuration, vulnerability, and risk assessments, set up and validate security tools, and assist in the development/maintenance of assessment and authorization packages. * Participate in incident tracking and remediation and provide technical leadership, documentation, and guidance to support ongoing cybersecurity readiness. * Provide expertise in systems security engineering, develop advanced security solutions, oversee cybersecurity integration across systems. Support vulnerability/risk assessments, authorization packages, and incident response activities. * Develop and submit security reports and threat analysis. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)