EngineerJobs.io
← Back to all jobs

Job Description

General Dynamics Information Technology is seeking a mid-level Information Systems Security Engineer (ISSE) to support Assessment and Authorization (A&A) and Continuous Monitoring (ConMon) efforts. In this role, you will help maintain RMF compliance across multi-level classification environments for DSMS, with responsibilities spanning security engineering support, documentation, and lifecycle-oriented security activities.

This position is based onsite in Fort Belvoir, VA. The likely salary range is USD 107,950 - 146,050 per year, with Secret clearance required and less than 10% travel.

What You’ll Do

  • Coordinate with other DSMS program teams to plan and create cybersecurity architecture and design documents for DSMS, ensuring compliance with DoD and other organizational IA policies and guidance.
  • Apply best practices when implementing security controls in an IS, including software engineering methodologies, system/security engineering principles, secure design, secure architecture, and secure coding techniques.
  • Develop cybersecurity architecture and design plans for communication and collaboration products, operating system platforms (servers and devices), management products, applications, and related security considerations for implementation.
  • Provide security engineering support for accreditation of DSMS Networks.
  • Integrate cybersecurity expertise into lifecycle management, including planning architecture and design management, migration and deployment, and system testing and implementation.
  • Research, develop, test, and document architectures and solutions for new cybersecurity technologies that improve information collaboration and cybersecurity capabilities for the program and its user base.
  • Develop and provide criticality analysis for logic-bearing system components (hardware, firmware, and software), including how components implement, protect, or introduce vulnerabilities to each function.
  • Develop and maintain mission criticality analysis, vulnerability assessments, risk assessments, and countermeasure implementation for Mission-Critical Functions, and ensure updated assumptions, rationale, results, supply chain risk information, and mitigations are available for Government review.
  • Prepare and submit Interim Authorization to Test (IATT) and Authority to Operate (ATO) requests, including Plans of Action and Milestones (PoAMs).
  • Develop, maintain, and coordinate required Body of Evidence (BoE) documentation for system assets.
  • Collaborate across Technical Services and Security Services teams, along with customer agency stakeholders, to support compliance.
  • Track workflow for lien remediation and resolution activities and enter updates in tracking tools.
  • Evaluate system change requests and assess system and organizational risks tied to modifications.
  • Execute ConMon activities within established timelines, including BoE collection and tracking tool updates.
  • Conduct recurring reviews of system state and security posture to confirm secure operation and implementation of information systems security policies and procedures.
  • Recommend security control implementations and identify countermeasures or mitigating controls where needed.
  • Respond to requests and queries for security information and reports.
  • Support investigations of security incidents and provide reporting as required.
  • Assist with communication, implementation, and enforcement of security policies and plans for data, applications, hardware, and telecommunications systems.
  • Advise stakeholders on information assurance standards, dependencies, and emerging security technologies.
  • Use Enterprise Security Services tools (including Trellix and ACAS) to track and remediate vulnerabilities and compliance deficiencies.

Required Qualifications

  • Education: Bachelor of Arts or Bachelor of Science
  • Experience: 2+ years of related experience
  • Security Clearance: Secret clearance required
  • Citizenship: U.S. Citizenship Required
  • Travel: Less than 10%

Technologies and Tools

  • Trellix
  • ACAS
  • Plans of Action and Milestones (PoAMs)
  • Body of Evidence (BoE)

Benefits

  • 401K with company match
  • Comprehensive health and wellness packages
  • Internal mobility team dedicated to helping you own your career
  • Professional growth opportunities including paid education and certifications
  • Cutting-edge technology you can learn from and apply to solve real world problems

Additional Job Details

  • Location: Fort Belvoir, Virginia (Onsite Workplace)
  • Requisition Number: RQ229469
  • Category: Cyber and IT Risk Management
  • Requisition Type: Regular
  • Public Trust: None
  • Work Requirements: On Customer Site; travel less than 10%; years of experience may vary based on technical training, certification(s), or degree

Identity Verification Process: During virtual interviews, you are expected to be on camera. The company may take your picture to verify your identity and prevent fraud. You authorize the collection, processing, and use of biometric data for identity verification and security purposes.

Similar Jobs