About the job (ISSE/ISSO) Information Systems Security Engineer (TS/SCI + CI Poly)
Location: On-Site, Chantilly, VA, USA
Type: Permanent/Full-Time Employment
Clearance: TS/SCI + CI Poly
Description: The Information Systems Security Engineer is vital position that informs and advises all levels of the information security process when developing and certifying systems for secure operations on the customer's network. The ISSE first must determine the clients security requirements and then take measures to build systems around those requirements to maintain the security of systems and information. The ISSE designs the architecture of an information system (IS) and chooses the pieces of the system used to perform the needed functions. The ISSE then prepares a security design for the system and chooses the components to instill system security measures. This can involve selecting commercial off-the-shelf (COTS) software or custom products.
Next, the ISSE implements system security by ensuring that the entire system works as planned. This includes testing and documenting the entire system and may include training people on the systems.
Required Skills
- Possess multi-tasking skills, as well as be a good communicator/facilitator. Comfortable at all levels from developer to senior staff.
- Knowledge of the complex network environments involving shared networks and multiple security enclaves.
- Possess the ability to bridge the technical implementation (i.e. developer talk), into commonly understood security words. Often this is a skillset and is not an actual language, but frequently translation or a basic understand needs to be conveyed by the ISSE when speaking with others or in writing the documentation in order to ensure its easy to understand.
- Document the various security control implementations as well as gather the artifacts that support the Risk Management Framework (RMF) and ICD 503 Security Accreditation for various Assessment and Authorization (A&A) efforts
- Document and obtain a general understanding of the architecture being developed or that was developed for each project in order to write the Systems Security Plans (SSP)/CONOPS in the customers compliance applications.
- Gather the information by working with various team members in order to write various additional A&A related documents such as Contingency Plan (CP), General User Guide (GUG), Privileged User Guide (PUG), Standard Operating Procedures (SOPs), etc.
- Support Accreditation and Authorization (A&A) reviews by ISSO/M, as well as the Security Controls Assessor (SCA)
- Document the Plans of Actions and Milestones (POA&Ms) implementation responses or mitigations, as well as provide all required artifacts (i.e. evidence gathering from the teams)
- Coordinating with various contractor and staff personnel to obtain the A&A content, as well as working with various customer security organizations to navigate the customers A&A process in order to achieve Authority to Develop (ATD), Interim Authority to Operation (IATT), as well as Authority to Operate (ATO).
- Keep track of where each of the various A&A projects are within the customers A&A process in order to know when its time to re-submit for accreditation or an accreditation extension.
Desired Skills
- Previous ISSE experience directly supporting the customer.
- Previous ISSO experience directly supporting the customer is also helpful.
- Various security tools and reports such as RoadRunner, Rapid7, WebInspect, App Detective, and Splunk
- Public, private and hybrid Cloud experience (AWS, Microsoft Azure, etc.)
- Virtualization experience (VDI & VMWare)
- Basic knowledge is helpful, but not required for the following general topics: Cloud security control implementation, PKI implementation, STIG compliance and vulnerability management, and Security Development and Operations (SecDevOps)
- CISSP, or GSLC
- Basic Excel and Microsoft Office365
Package Details
Health and Wellness
- 100% medical insurance premium covered for the employee and their family.
- Pet insurance and identity protection.
Compensation and Financial Benefits
- Pay for every hour worked.
- Quarterly performance bonuses.
- Recruiting bonus up to $20,000 per hired referral.
- Retirement 401(k) with company match and profit sharing.
- Government shutdown protection.
Work-Life Balance
- Paid time off (PTO) earned at 10% of billable hours, all federal holidays, and your birthday.
- Monthly team building events.
- Epic company holiday parties and summer events.
Education and Development
- Generous education reimbursement for formal education, certifications, and conferences, including paid days off for training.
Community and Support
- Matching employee donations to various organizations including veterans' organizations, children's charities, and human relations charities.