Cybersecurity Engineer
Job Description
Nortex Cyber Solutions is seeking a Cybersecurity Engineer / Information Systems Security Engineer (ISSE) to support security authorization, assessment, and continuous monitoring for mission-critical information systems. The position requires deep RMF expertise, strong documentation and traceability practices, and the ability to work within classified environments.
Location
Fort George G Meade, MD (onsite)
Role Responsibilities
- Support the full Risk Management Framework (RMF) lifecycle for information systems seeking or maintaining authorization.
- Develop, review, maintain, and update system security authorization packages and supporting bodies of evidence.
- Apply and interpret security controls and requirements in accordance with NIST SP 800-53 and DoD Instruction 8510.01 (RMF for DoD IT).
- Use security package management and governance tools such as eMASS and Xacta to develop, maintain, track, and manage authorization documentation.
- Scope security assessments and conduct assessments of information systems undergoing accreditation/authorization or maintaining existing authorization.
- Support preparation, coordination, and approval of Interim Authorizations to Test (IATTs) for systems requiring testing prior to full authorization.
- Evaluate system configurations against applicable DISA Security Technical Implementation Guides (STIGs), CIS Benchmarks, and other security configuration standards.
- Conduct and analyze vulnerability assessments using tools such as ACAS/SecurityCenter and Nessus.
- Review vulnerability scan results, determine applicability and risk, track remediation activities, and support development and maintenance of Plans of Action and Milestones (POA&Ms) as applicable.
- Coordinate with system engineers, developers, and other technical stakeholders to implement and validate security controls.
- Support implementation of automated solutions for continuous monitoring of security controls, vulnerabilities, configurations, and related security requirements.
- Identify opportunities to improve RMF, assessment, evidence collection, and continuous monitoring processes through automation.
- Leverage AI-enabled tools when beneficial while maintaining enough cybersecurity and RMF expertise to independently understand, validate, and take responsibility for intended outcomes.
- Maintain organized, accurate, and traceable documentation showing relationships between security requirements, implemented controls, assessment results, findings, remediation activities, and supporting evidence.
- Participate in Agile development and engineering environments and work within SAFe Agile processes.
- Communicate security risks, findings, and requirements clearly to both cybersecurity and engineering stakeholders.
Required Qualifications
- Active TS/SCI clearance with CI Polygraph required at time of hire.
- Ability to access required classified environments and security packages within NSA systems.
- Strong working knowledge of DoD RMF and the complete authorization lifecycle.
- Strong knowledge of NIST SP 800-53 security and privacy controls and DoDI 8510.01.
- Experience developing, reviewing, and maintaining RMF authorization packages and supporting bodies of evidence.
- Hands-on experience with eMASS and/or Xacta.
- Strong understanding of DISA STIGs, CIS Benchmarks, system hardening, and security configuration requirements.
- Experience using ACAS/SecurityCenter and Nessus for vulnerability scanning, analysis, and remediation support.
- Experience scoping and conducting security assessments for systems undergoing or maintaining authorization.
- Knowledge of the IATT process and experience supporting systems requiring authorization for testing.
- Understanding of continuous monitoring requirements and approaches for validating security controls throughout the lifecycle.
- Ability to work with technical teams to develop or implement automation supporting cybersecurity and continuous monitoring activities.
- Familiarity with SAFe Agile or similar Agile environments.
- Strong written and verbal communication skills.
- Exceptional attention to detail, organization, documentation, and configuration management.
- Ability to maintain clear traceability across security requirements, implementation details, assessment procedures, findings, and supporting evidence.
Technologies
- Risk Management Framework (RMF)
- NIST SP 800-53
- DoD Instruction 8510.01
- eMASS
- Xacta
- DISA Security Technical Implementation Guides (STIGs)
- CIS Benchmarks
- ACAS/SecurityCenter
- Nessus
- Plans of Action and Milestones (POA&Ms)
- Interim Authorizations to Test (IATTs)
- NSA environments
- SAFe Agile
Education and Experience
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field.
- 10+ years of relevant cybersecurity, information assurance, RMF, or systems security engineering experience.
- Equivalent combinations of education, certifications, and directly relevant experience may be considered.
Preferred Qualifications
- Experience supporting NSA, DoD, or Intelligence Community information systems.
- Experience working directly with system owners, ISSMs, ISSOs, security control assessors, and Authorizing Official representatives.
- Experience with continuous monitoring and automated security control validation.
- Experience integrating security activities into CI/CD or DevSecOps environments.
- Experience developing scripts, workflows, or other automation to improve security assessment, evidence collection, vulnerability management, or compliance processes.
- Familiarity with AI-assisted cybersecurity or compliance workflows, with the technical expertise necessary to independently verify AI-generated outputs.
- Relevant certifications such as Security+, CISSP, CAP/CGRC, CASP+/SecurityX, or equivalent.
Benefits
- 100% Company-paid medical insurance for employees
- 100% Company-paid dental and vision insurance
- Competitive salary
- Generous 401k employer contribution to your 401k with no required personal contribution and immediate vesting
- Generous PTO and parental leave
- Flexible work hours
Clearance Required for Start
- Yes
- Top Secret/SCI with CI Polygraph
Physical Requirements
- Ability to remain seated and work at a computer for extended periods.
- Ability to occasionally lift up to 15 pounds.
- Ability to communicate effectively in person and through virtual collaboration tools.