Information Systems Security Engineer
Role details
Job location
Tech stack
Job description
The ISSE will be responsible for engineering, implementing, and maintaining cybersecurity solutions across enterprise information systems and networks. This role partners closely with system engineers, architects, cybersecurity analysts, developers, and program leadership to ensure systems are designed, implemented, and maintained in accordance with Risk Management Framework (RMF) requirements, DoD cybersecurity directives, and industry security best practices., * Develop and maintain system security documentation, including:
- System Security Plans (SSPs)
- Security Assessment Reports (SARs)
- Plans of Action & Milestones (POA&Ms)
- STIG compliance documentation
- Apply NAVINTEL ICD 503 Risk Management Framework (RMF) policies and DoD/Navy cybersecurity directives to system design and implementation.
- Collaborate with ISSOs, ISSMs, Program Managers, and Systems Engineers to ensure security controls are effectively implemented and maintained.
- Support system categorization, security control selection, assessment, authorization, and continuous monitoring activities in accordance with NIST SP 800-53 and RMF requirements.
- Provide guidance on secure architecture, authentication, encryption, network security, and system hardening strategies.
- Support vulnerability management efforts, remediation planning, and STIG compliance activities.
- Work directly with stakeholders to resolve vulnerabilities and complete security checklists and compliance requirements.
- Maintain awareness of cybersecurity threats, compliance requirements, and emerging security technologies.
- Support security initiatives within cloud and enterprise environments including AWS, Azure, Windows, and Linux platforms.
- Utilize Governance Risk and Compliance (GRC) tools such as eMASS and Xacta.
Requirements
Certification: IAT Level III certification required (see approved certifications below), * Active TS/SCI Security Clearance
- Active IAT Level III Certification, including one of the following:
- CISSP (or Associate of ISC )
- CASP+
- CCNP Security
- CISA
- GCED
- GCIH
- Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Technology, or a related field (or equivalent experience).
- 3-6 years of experience in cybersecurity, information assurance, or information systems security engineering.
- Working knowledge of NAVINTEL ICD 503 RMF implementation policies and DoD/Navy cybersecurity directives.
- Understanding of ISSO responsibilities under SECNAV M-5239.2.
- Experience with:
- NIST SP 800-53
- RMF
- DoD STIGs
- Secure systems architecture
- Familiarity with enterprise network architectures, Windows/Linux operating systems, and cloud platforms.
- Strong understanding of authentication, encryption, network security, vulnerability management, and secure design principles.
Preferred Qualifications
- Experience with DevSecOps methodologies, CI/CD pipelines, and Infrastructure as Code (Terraform, Ansible).
- Knowledge of containerized environments and security best practices (Docker, Kubernetes).
- Experience with enterprise security technologies including SIEM, IAM, endpoint protection, and security monitoring tools.
- Previous support of Navy, Intelligence Community (IC), or other classified programs.
- Knowledge of virtualization technologies and concepts.
- Familiarity with cloud architecture, engineering, and design principles.
- Experience using code repositories such as GitHub and GitLab.
- Understanding of Linux operating systems and distributions.
- Excellent written and verbal communication skills with the ability to brief technical and non-technical stakeholders.