Job Description:
Job Summary
The Information Systems Security Engineer is responsible for designing, implementing, and maintaining secure information system architectures. The role focuses on risk assessment, security engineering, compliance, vulnerability management, security documentation, and supporting cybersecurity audits while ensuring systems meet organizational and regulatory security requirements.
Key Responsibilities:
- Design and implement secure architectures for information systems.
- Ensure security designs align with organizational goals and industry standards.
- Conduct security risk assessments and recommend mitigation strategies.
- Integrate security controls throughout the System Development Life Cycle (SDLC).
- Collaborate with software developers, network engineers, and system administrators to maintain secure system configurations.
- Implement and manage security technologies such as encryption, firewalls, and access controls.
- Ensure compliance with security frameworks including NIST, ISO 27001, and FISMA.
- Prepare documentation for security certifications, audits, SOPs, POA&Ms, and configuration management.
- Lead remediation efforts for security audits, vulnerability assessments, and IAVM findings.
- Support cybersecurity compliance assessments (e.g., CMMC, DCSA).
- Monitor systems for compliance with organizational policies and regulatory requirements.
- Communicate security risks, compliance status, and recommendations to technical and non-technical stakeholders.
Requirements:
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Minimum of 6 years of cybersecurity or information assurance experience.
- Strong knowledge of RMF, NIST 800-53, and security engineering principles.
- Experience with security tools such as ACAS, Nessus, SCC, and Splunk.
- Knowledge of system hardening, encryption, access control, and network security.
- Strong analytical, problem-solving, communication, and presentation skills.
- Understanding of DoD security standards and compliance requirements.
- Relevant cybersecurity certification (CISSP, CASP+, CEH, Security+, or equivalent).
- Active Secret Security Clearance with Top Secret/SCI eligibility.
- Master's degree, Kubernetes experience, or customer-facing consulting experience is preferred.