> Markdown version of [/jobs/ext/616354-information-system-security-engineer-isse](https://www.wearedevelopers.com/jobs/ext/616354-information-system-security-engineer-isse). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Engineer (ISSE) - **Company:** JMA Resources, Inc. - **Location:** Mechanicsburg, PA, United States (Remote available) - **Experience:** Experienced - **Salary:** $83,000.0 - $115,000.0 - **Contract:** Permanent contract - **Skills:** Comptia Cloud+, Systems Engineering, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Security Management, Information Systems Security Architecture Professional, Microsoft Security Essentials, Package Development Process, SC Clearance, Vulnerability Analysis - **Published:** June 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7ea435572dbb969d ## About the Role Do you have experience in Vuls?, * Current or ability to obtain a Department of Defense (DoD) Secret Clearance is required. Note: To obtain a security clearance, you must be a U.S. citizen and meet the 13 adjudicative guidelines., * 3 or more years of experience supporting cybersecurity engineering, information assurance, RMF, systems security, or related technical activities. * At least 2 years of experience supporting RMF Assessment and Authorization activities. * Experience documenting RMF requirements and supporting RMF package development, review, and submission. * Experience supporting RMF testing, security control assessment, and analysis needed to complete authorization documentation. * Experience performing vulnerability risk analysis on deficiencies identified during RMF testing or security assessments. * Experience with IA tools and vulnerability scanners used to evaluate the security posture of systems or enclaves. * Experience supporting POA&M development, tracking, remediation, and closure activities. * Experience with eMASS or similar tools used to document RMF status, artifacts, findings, and workflows. * Knowledge of DoD and Navy RMF requirements, cybersecurity policy, and security control implementation. * Ability to provide RMF authorization experience details, including the total number of RMF authorizations supported, as required. * Ability to communicate cybersecurity risks, findings, and status clearly to technical teams, program stakeholders, and leadership. * Current or ability to obtain one of the following certifications within two weeks of the start date: + Certified Chief Information Security Officer (CCISO) + Certified Cloud Security Professional (CCSP) + Certified in Governance Risk and Compliance (CGRC) + Certified Information Systems Security Officer (C)ISSO-A) + CompTIA Cloud+ + CompTIA Security+ + CompTIA SecurityX (formerly CASP+) + GIAC Cloud Security Automation (GCSA) + GIAC Continuous Monitoring Certification (GMON) + GIAC Security Essentials Certification (GSEC) + Systems Security Certified Practitioner (SSCP), * Experience supporting Department of the Navy or other DoD cybersecurity environments. * Experience using and complying with the Navy RMF Process Guide and applicable RMF business rules. * Experience concurrently supporting multiple RMF packages. * Experience supporting cybersecurity testing during system sustainment, annual reviews, or authorization renewals. * Experience working with ISSOs, ISSMs, Security Control Assessors, Authorizing Officials, system owners, and program management teams. Creating an Environment of Respect and Opportunity ## Description We are seeking an Information System Security Engineer to develop and maintain cybersecurity architecture and support RMF activities for systems within a Navy environment. This role supports the implementation of security controls, cybersecurity testing, vulnerability risk analysis, RMF documentation, and authorization activities for assigned systems, programs, or enclaves., * Develop and maintain cybersecurity solutions for assigned systems, programs, or enclaves. * Identify system authorization requirements, including Authorizing Official and Security Control Assessor cognizance, reciprocity considerations, cross-domain requirements, and applicable overlays. * Identify, tailor, and document the security control baseline based on system categorization and applicable requirements. * Develop, maintain, and track System Security Plans and related RMF artifacts. * Lead or support security control implementation and testing activities. * Plan and perform cybersecurity testing to assess security controls and document compliance status. * Execute approved Security Assessment Plans and support testing required for Assessment and Authorization or annual reviews. * Perform vulnerability-level risk analysis on deficiencies identified during RMF testing. * Support POA&M and Corrective Action Plan development, tracking, mitigation, and closure. * Ensure vulnerabilities are traceable from raw assessment results to POA&M entries. * Ensure eMASS records, POA&M entries, and RMF artifacts are accurate and consistent with implementation results. * Support preparation of Security Assessment Reports, executive summaries, and related assessment documentation. * Use eMASS workflow and collaboration functions to support formal coordination during the RMF process. * Document requested rework and provide updates to program management, cybersecurity leadership, and system stakeholders. * Participate in the system engineering process to ensure cybersecurity requirements, design considerations, and testing needs are addressed throughout the system lifecycle. * Perform other related duties as assigned to support evolving customer and company needs. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)