Information Systems Security Engineer
Application Security
Container Security
Cybersecurity Tools
DevSecOps
Identity and Access Management
Image Scanning
Incident Response
Information Security
InfoSec
Security Automation
Security Compliance
Security Information And Event Management
Security Monitoring
Security Operations
Security Standards
Service Mesh Security
Software Security
Job Description
MetroStar is hiring a Senior Information Systems Security Engineer (ISSE II) to design, implement, and sustain cybersecurity infrastructure and controls for containerized and DevSecOps environments.
Responsibilities
- Act as a security engineering SME for containerized environments, service mesh, and microservices.
- Design, implement, and operate security controls for containerized workload solutions, including:
- image scanning firewalls
- intrusion detection and prevention systems
- endpoint protection
- encryption mechanisms
- runtime protection
- role-based access control (RBAC)
- network segmentation
- Embed security into CI/CD pipelines and DevSecOps workflows to support compliance with RMF, NIST SP 800-53, ICD 503, and FedRAMP.
- Configure and optimize security monitoring and logging capabilities; partner with teams using container security tooling such as Prisma Cloud or comparable solutions.
- Monitor network traffic, system logs, and security alerts to identify and respond to potential incidents, including:
- analyzing anomalies
- investigating security breaches
- mitigating risks based on findings
- Monitor and assess threat intelligence feeds, perform threat analysis, and execute risk assessments to identify emerging threats and vulnerabilities.
- Collaborate with platform engineers, ISSOs, developers, and other cross-functional teams to establish and enforce security policies, standards, and procedures throughout the system lifecycle.
- Perform recurring security assessments for container orchestration platforms, microservices, and APIs to uncover vulnerabilities in systems, networks, and applications and recommend mitigations.
- Develop and implement incident response plans to address security breaches and related incidents.
- Work with IT, software development, and compliance teams to integrate security throughout the development lifecycle.
- Maintain detailed documentation covering security architecture processes, control implementation procedures, configurations, and continuous monitoring strategies; prepare reports on security findings, incidents, and actions taken.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field.
- 7+ years of experience as a cybersecurity engineer specializing in:
- designing and implementing required security controls
- building continuous monitoring and auditing capabilities for compliance with security controls
- Hands-on experience securing containerized / Kubernetes environments (with OpenShift preferred).
- Strong experience specifying and implementing log collection into tools such as Splunk, including querying and analyzing aggregated logs to identify security-relevant anomalies or risks.
- Strong experience designing and implementing security controls and continuous monitoring aligned to NIST SP 800-53, RMF, ICD 503, FISMA, and FedRAMP.
- Experience implementing controls for cloud, container, and DevSecOps services within IL5 to IL6+ environments.
- Strong understanding of network protocols, operating systems, and infrastructure components.
- Experience performing periodic security checks (Daily, Weekly, Monthly) to support continuous monitoring aligned with the NIST Risk Management Framework.
- Proficiency in incident response, security incident handling, and forensic analysis techniques.
- Experience with security tools such as Fortify, Acunetix, and Prisma Cloud.
- Effective communication skills to explain complex technical concepts to technical and non-technical stakeholders.
- CISSP or equivalent certification to support DoD 8140 requirements.
- Active TS//SCI clearance with CI poly.
Technologies
- Kubernetes
- OpenShift
- Service mesh technologies
- Prisma Cloud
- Splunk
- Fortify
- Acunetix
- CI/CD
- DevSecOps
- RBAC
Benefits
- Health, dental, and vision insurance
- 401(k) retirement plan with company match
- Paid time off (PTO) and holidays
- Parental Leave and dependent care
- Flexible work arrangements
- Professional development opportunities
- Employee assistance and wellness programs
Compensation
- Salary: $180,000 per year
- Salary range: $180,000 - $200,00
- Additional compensation: May be eligible for bonuses and/or additional incentives based on individual and company performance
Location and work mode
- Reston, VA (onsite)
Application details
- Applications accepted on a rolling basis until the position is filled; candidates are encouraged to apply as early as possible for full consideration.