> Markdown version of [/jobs/ext/507221-information-system-security-engineer](https://www.wearedevelopers.com/jobs/ext/507221-information-system-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Engineer - **Company:** Science Applications International Corporation - **Location:** McLean, VA, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Configuration Management, Cyber Security, Computer Networks, Databases, Linux, Information Security Management, System Testing, Webinspect, Information Security Management System, Malware, Vulnerability Analysis - **Published:** June 5, 2026 - **Apply:** https://dejobs.org/x/x/5883D50164094916A1A1C9B392201707/job/ ## About the Role * Active TS/SCI with Polygraph. * Bachelor's degree and 14 years or more experience; Master's degree and 12 years or more experience; PhD and 9 years or more experience. * CISSP Certification. * Demonstrated experience with: * Computer networking in Windows AND Linux. * Website configuration. * Basic software development knowledge. * Eliciting information on complex technical problems from non-technical personnel for use in diagnosis, analysis, resolution of problems. * Customer regulations and standards, including Information Security (INFOSEC) and Communications Security (COMSEC). * Managing security aspects of deployed infrastructure and technical solutions. Desired Skills: * Demonstrated experience with Rapid7, WebInspect, AppDetective, CIS-CAT, and other vulnerability assessment tools and processes. * Information security certifications such as CISSP, CISSE, CISA, CEH, CCSP, etc. * Demonstrated experience with computer and network vulnerabilities (e.g., malware, zero-day attacks, denial of service attacks, etc.). ## Description * Support the Lifecycle Assessment and Authorization (A&A) process. * Develop a Systems Security Plan (SSP). * Assist and maintain a formal Information Security Program that includes recommendations on continuous improvement of the processes and architectures. * Maintain and make accessible documentation of all operational and business process activities in the form of Standard Operating Procedures (SOPs). * Monitor and track projects in the A&A queue. * Analyze SSPs to develop an understanding of the customer's systems and applications. * Coordinate A&A actions and system testing with appropriate security personnel. * Develop risk assessments, recommend mitigating countermeasures, and write short, succinct risk assessments, and certification reports for submission to the Chief Information Officer (CIO). * Monitor and track projects in the A&A queue. * Maintain a document repository where A&A project documentation is stored and recorded and register actions concerning project approvals to operate in the A&A database. * Assemble and submit A&A packages to the Principal Accreditation Authority or Designated Accreditation Authority. * Review and approve product requests for procurements. * Provide security guidance in terms of policy and technical implementation of those policies. * Produce and assist with production of technical artifacts required for A&A packages such as a System Security Plan, Audit Strategy. * Configuration Management Plan, Security Controls Traceability Matrix, Project Plan of Action and Milestones. * Monitor and address cyber risks such as malware, zero-day attacks, denial of service attacks, as well as associated mitigations regarding computer and network devices. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Enhancing Workload Security in Kubernetes](https://www.wearedevelopers.com/videos/356-enhancing-workload-security-in-kubernetes) - [Kubernetes and Microservices with Multi-Model Databases](https://www.wearedevelopers.com/videos/382-kubernetes-and-microservices-with-multi-model-databases) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)