Information Systems Security Engineer (ISSE) - TS/SCI with Polygraph
Job Description
The Information Systems Security Engineer (ISSE) role in Herndon, VA requires TS/SCI clearance with Polygraph and focuses on maintaining and renewing security accreditations for systems using Xacta, GreenLight, and Rapid7, with cloud security and RMF/A&A expertise.
Responsibilities
- Contribute as a key member of national security efforts by applying expertise to protect against threats.
- Help ensure secure operations today while strengthening the security posture for tomorrow.
- Collaborate with Xacta, GreenLight, Rapid7 and onsite Information System Security Managers to maintain and renew system security accreditations.
- Prioritize multiple projects and guide applications through the accreditation lifecycle.
- Develop and review security concept of operations.
- Develop and review systems security plans.
- Develop and review security control assessments.
- Develop and review contingency plans.
- Develop and review configuration management plans.
- Develop and review incident response plans.
- Develop and review plan of actions and milestones.
- Develop and review risk management plans.
- Develop and review vulnerability scanning and vulnerability management plans.
- Documented experience with Xacta.
- Documented experience with GreenLight.
- Documented experience with RMF processes (Rev4 and Rev5).
- Cloud security design, requirements analysis, control implementation, and mitigation.
- Experience securing applications in a cloud environment such as Amazon Web Services.
- A&A policy and guidance including ICD-503, FISMA and RMF/A&A processes.
- NIST SP series coverage (800-27, 800-30, 800-37, 800-53, 800-60, 800-137, 800-144, 800-145).
- FIPS publications 199 and 200; CNSSI 1253 technical controls.
- Develop and maintain certification and accreditation documentation for systems.
- Perform security system scans for network, platform, database, and web services.
- Utilize security tools such as Nessus, Rapid7, Weblnspect, and AppDetective.
- Demonstrate strong interpersonal skills and operate effectively as a team member.
- Communicate clearly in writing and verbally; present reports to management; work with developers and engineers to determine mitigations.
- Produce quality deliverables and complete assigned projects on time; provide consistent status updates to keep IT security projects on track.
- Maintain attention to detail; follow standard operating procedures; report anomalies and inconsistencies.
- Persistently and creatively solve problems; troubleshoot thoroughly to identify root causes and present solutions to management.
- Display a professional work ethic; dependable, respectful, and proactive.
Requirements
- Experience developing and reviewing security concept of operations.
- Experience developing and reviewing systems security plans.
- Experience developing and reviewing security control assessments.
- Experience developing and reviewing contingency plans.
- Experience developing and reviewing configuration management plans.
- Experience developing and reviewing incident response plans.
- Experience developing and reviewing plan of actions and milestones.
- Experience developing and reviewing risk management plans.
- Experience developing and reviewing vulnerability scanning.
- Experience developing and reviewing vulnerability management plans.
- Documented experience with Xacta.
- Documented experience with GreenLight.
- Documented experience with RMF processes (Rev4 and Rev5).
- Cloud security design, requirements analysis, control implementation, and mitigation.
- Experience securing applications in a cloud environment such as Amazon Web Services.
- A&A policy and guidance including ICD-503, FISMA and RMF/A&A processes.
- NIST SP series coverage (800-27, 800-30, 800-37, 800-53, 800-60, 800-137, 800-144, 800-145).
- FIPS publications 199 and 200; CNSSI 1253 technical controls.
- Developing and maintaining associated certification and accreditation documentation for systems.
- Performing security system scans for network, platform, database, and web services.
- Using security tools such as Nessus, Rapid7, Weblnspect, and AppDetective.
- Outstanding interpersonal skills and team player.
- Outstanding written and verbal communication; ability to present to management.
- Ability to work with developers and engineers to determine mitigations to vulnerabilities.
- Produce quality deliverables and complete assigned projects on time; provide status updates to keep IT security projects focused.
- Attention to detail and adherence to SOPs; report anomalies and inconsistencies.
- Persistent and creative problem solver with strong troubleshooting; identify root cause and present solutions to management.
- Outstanding work ethic; professional, respectful, dependable, and takes initiative.
Technologies
- Xacta
- GreenLight
- Rapid7
- Nessus
- Weblnspect
- AppDetective
- Amazon Web Services
- JIRA
Benefits
- 401K with company match
- Comprehensive health and wellness package
- Internal mobility team dedicated to helping you own your career
- Professional growth opportunities including paid education and certifications
- Access to cutting edge technology to learn from
- Paid vacation and holidays for rest and recharge
Work Requirements
- Years of Experience: 10+ years of related experience
- Travel: None
- Citizenship: U.S. Citizenship Required
- May vary based on technical training, certification(s), or degree
Salary and Benefits Information
The likely salary range for this position is $178,500 - $241,500. This is not a guarantee of compensation; salary will be set based on experience, geographic location, and contractual requirements and could fall outside of this range.