Information Systems Security Engineer (ISSE)
Job Description
The Information Systems Security Engineer (ISSE) will deliver cybersecurity and security-engineering support to the National Military Command Center (NMCC) in alignment with Air Force missions. The position emphasizes security assessments, vulnerability management, system hardening, and administration of security tools and servers.
Onsite Location and Schedule
Location: Arlington, VA (onsite)
Work setting: Full-time onsite at the NMCC at the Pentagon in Arlington, VA. Ad hoc telework may be available based on mission requirements and prior client approval.
Schedule: Flexible. Core hours are 7am to 3pm.
Salary
The anticipated salary range for this requisition is USD 120,000 - 206,000 per year. Salary is commensurate with education, experience, knowledge, skills, abilities, and qualifications.
Key Responsibilities
- Provide cybersecurity and security-engineering services, including system security engineering, cybersecurity risk assessments, and security architecture support.
- Perform and review technical security assessments of computing environments.
- Identify system vulnerabilities, cybersecurity risks, and instances of noncompliance with established security standards and regulations.
- Develop and recommend mitigation strategies and corrective courses of action.
- Build, deploy, maintain, and patch HBSS Windows servers and ACAS Red Hat Enterprise Linux 7.9 and 8 servers.
- Build, maintain, secure, and patch McAfee ePolicy Orchestrator, Tenable SecurityCenter, and Nessus servers.
- Create and manage SecurityCenter accounts for vulnerability managers conducting ACAS scans.
- Analyze ACAS scan results and support remediation of identified vulnerabilities.
- Obtain and manage required licenses for HBSS ePO and Tenable SecurityCenter environments.
- Obtain HBSS and ACAS Kickstart ISO images from the Defense Information Systems Agency.
- Build and administer virtual servers supporting cybersecurity operations.
- Deploy, configure, and patch McAfee modules through ePolicy Orchestrator and develop McAfee policies appropriate to each supported environment.
- Apply Security Technical Implementation Guides (STIGs) and related cybersecurity benchmarks to HBSS Windows operating systems, McAfee policies, and ACAS Red Hat Enterprise Linux servers.
- Configure McAfee policies to comply with applicable security benchmarks.
- Run Security Content Automation Protocol (SCAP) scans on Windows and Red Hat Enterprise Linux servers.
- Update Red Hat Enterprise Linux 7.9 and 8 RPM packages as releases become available.
- Establish and maintain local YUM repositories to patch offline ACAS servers.
- Deploy Rogue System Detection sensors across applicable network subnets, identify rogue subnets and endpoints, and support remediation actions.
- Troubleshoot Tenable SecurityCenter and Nessus scanner issues.
- Document technical solutions, assessment results, cybersecurity risks, and recommended courses of action.
- Communicate complex technical findings clearly to technical teams, government stakeholders, and leadership.
- Work independently, exercise sound judgment, and initiate appropriate action without requiring continuous direction.
Required Qualifications
- Active TS/SCI security clearance
- Current CompTIA Security+ certification
- At least five years of relevant systems-engineering experience
- Demonstrated understanding of systems engineering, including system design and architecture
- Hands-on experience administering and securing HBSS, ACAS, ePO, Tenable SecurityCenter, or Nessus environments
- Experience building, deploying, maintaining, and patching Windows and Red Hat Enterprise Linux servers
- Experience applying STIGs and other cybersecurity benchmarks to operating systems, security tools, and enterprise environments
- Ability to interpret vulnerability scan results and develop or implement appropriate remediation actions
- Demonstrated ability to identify cybersecurity risks across information-system and network architectures, including operating systems, hardware, and data-transfer protocols
- Strong planning, organizational, prioritization, and time-management skills
- Effective written, verbal, briefing, and presentation skills
- Ability to communicate technical information effectively in both formal and informal settings
- Demonstrated initiative and ability to work independently
- Ability to work full-time onsite in the NMCC environment
Education and Experience Options
- Bachelor’s degree: At least five years of relevant experience
- Master’s degree: At least three years of relevant experience
- No degree: At least 12 years of intensive and progressive experience demonstrating the required technical proficiency
Qualifying degrees should be in computer science, information technology, cybersecurity, engineering, or a closely related discipline.
Technologies and Tools
- Host-Based Security System (HBSS)
- Assured Compliance Assessment Solution (ACAS)
- Tenable SecurityCenter
- Nessus
- Windows
- Red Hat Enterprise Linux
- McAfee ePolicy Orchestrator
- HBSS ePO
- Red Hat Enterprise Linux 7.9
- Red Hat Enterprise Linux 8
- McAfee modules
- Security Technical Implementation Guides (STIGs)
- Security Content Automation Protocol (SCAP)
- Rogue System Detection
- YUM
- RPM packages
Benefits
- Generous PTO plus 11 federal holidays
- 401(k) retirement plan with company match and immediate vesting
- Annual health and wellness allowance
- Annual professional-development funding for education, training, certifications, and technology tools
- Eight hours of paid volunteer time annually
- Charitable-donation matching
- Internal and external employee referral bonuses
- Living Our Values recognition and bonus awards
Security Clearance
An active TS/SCI security clearance is required.