> Markdown version of [/jobs/ext/539740-information-systems-security-engineer-isse](https://www.wearedevelopers.com/jobs/ext/539740-information-systems-security-engineer-isse). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Engineer (ISSE) - **Company:** Open Systems Inc. - **Location:** Annapolis Junction, MD, United States - **Contract:** Permanent contract - **Skills:** Xacta, Cyber Security, Information Security Management, Package Development Process, Red Hat Enterprise Linux, Security Software, Software Vulnerability Management, Cloud Platform System, Tenable Nessus, Vulnerability Analysis - **Published:** June 15, 2026 - **Apply:** https://www.clearancejobs.com/jobs/8976049/information-systems-security-engineer-isse ## About the Role * Active TS/SCI with Polygraph security clearance * U.S. Citizenship * DoD 8570/8140 IASAE Level II compliant certification required * Strong understanding of the Risk Management Framework (RMF) * Experience supporting Assessment & Authorization (A&A) and Authority to Operate (ATO) processes * Experience with security control implementation, validation, and continuous monitoring * Familiarity with NIST SP 800-37 and NIST SP 800-53 (Rev. 3 and/or Rev. 5) * Experience with RMF and cybersecurity tools such as: + LATTEART + XACTA + BISCOTTI + WATCHCAT + STE * Experience with compliance and configuration scanning tools * Strong analytical, troubleshooting, and documentation skills, * Experience in classified Government cybersecurity environments * Familiarity with enterprise Linux, network, or cloud systems * Experience working with ISSOs, ISSMs, SCAs, and System Owners * Understanding of vulnerability management and cybersecurity automation tools * Experience supporting large-scale enterprise or mission systems ## Description Open Systems Technologies Corporation (OST) is seeking Information System Security Engineers (ISSEs) to support mission-critical Government programs. This role focuses on integrating cybersecurity engineering principles across system design, implementation, accreditation, and sustainment activities within complex classified environments. The ISSE will support full Risk Management Framework (RMF) execution, Assessment & Authorization (A&A) activities, and continuous cybersecurity compliance efforts while working closely with system administrators, ISSOs, ISSMs, and system owners., * Support the full RMF lifecycle for classified systems * Assist with A&A package development and Authority to Operate (ATO) maintenance * Implement, assess, and validate security controls * Perform Security Control Traceability and technical validation * Support system boundary definition and security architecture documentation * Develop and maintain RMF artifacts and body of evidence packages * Conduct compliance and vulnerability scanning analysis * Validate findings including false positive identification and remediation verification * Support STIG implementation and configuration hardening * Manage patch validation and security compliance efforts * Participate in Continuous Monitoring (ConMon) activities Core ISSE Skill Areas * Assessment & Authorization (A&A) execution and support * Security Control implementation and validation * RMF documentation and artifact development * System boundary definition and architecture support * Vulnerability management and remediation tracking * STIG implementation and compliance validation * Technical security assessment and risk analysis * Continuous Monitoring (ConMon) support ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Maturity assessment for technicians or how I learned to love OWASP SAMM](https://www.wearedevelopers.com/videos/351-maturity-assessment-for-technicians-or-how-i-learned-to-love-owasp-samm) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) ## Related Articles - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)