Senior Cybersecurity Engineer - RMF/ISSE Lead
Job Description
The Senior Cybersecurity Engineer - RMF/ISSE Lead will support a division focused on safeguarding Electronic Warfare systems by guiding security posture across the system lifecycle. This onsite role in Sterling, VA includes leading Risk Management Framework (RMF) execution, supervising Security Engineers, and ensuring Assessment & Authorization (A&A) documentation and continuous monitoring requirements are met.
Key Responsibilities
- Lead, mentor, and manage a team of 3-5 Security Engineers, including oversight of project timelines, delivery of high-quality security solutions, performance evaluations, and professional development opportunities.
- Direct design and documentation of secure system architectures spanning web applications, application stacks, Web Application Firewalls (WAFs), Intrusion Detection/Prevention Sensors (IDS/IPS), antimalware technologies, and Advanced Persistent Threat (APT) prevention.
- Define security requirements and integrate security capabilities across all SDLC phases, including initiation, acquisition/development, implementation, operations/maintenance, and disposition, aligned to NIST 800-64 Rev. 2 guidance.
- Manage and execute RMF activities (Steps 1-6), performing ISSO/ISSE functions to support system progress from initial categorization through Authorization to Operate (ATO).
- Support DoD or IC acquisition programs, contributing to outcomes such as IATT and/or ATO.
- Develop, maintain, and review Assessment & Authorization (A&A) documentation using Xacta, eMASS, or equivalent tools, including artifacts such as SSP, SCTM, and BoE.
- Ensure compliance of hardware and software with Government Security Certification Officer (SCO) requirements and standards including NIST SP 800-53, ICD 503, and CNSSI 1253.
- Implement continuous monitoring (ConMon) and lead security audits using IC and DoD approved scanning tools such as Nessus/ACAS, SCAP/SCC, STIG Viewer, Nmap, and additional vulnerability assessment platforms.
- Direct incident response activities and participate in an on-call rotation for security incidents.
Required Qualifications
- Bachelor’s degree in computer science, cybersecurity, engineering, information technology, or a related field (or equivalent experience).
- 10+ years of experience with demonstrated ISSE/ISSO responsibilities, preferably in the Intelligence Community or DoD environment.
- Experience achieving IATT and/or ATO on DoD or IC acquisition programs.
- People management or team leadership experience.
- Current active TS/SCI eligibility.
- DoD 8570/8140 IASAE Level III (e.g., CISSP).
- Knowledge of RMF processes and NIST SP 800-53 and NIST 800-64 Rev. 2.
- Experience integrating security across the SDLC phases: initiation, acquisition/development, implementation, operations/maintenance, and disposition.
- Working knowledge of network protocols (TCP/IP, DNS, HTTP/HTTPS), VPNs, IDS/IPS, firewalls, and DMZ configurations.
- Hands-on Linux/Unix experience.
- Experience with web applications, application stacks, WAFs, and application-layer security controls.
- Experience with A&A tracking tools such as Xacta or eMASS, plus SCAP/SCC and vulnerability assessment tools including Nessus and ACAS.
Technology Stack
- Risk Management Framework (RMF)
- NIST 800-64 Rev. 2
- NIST SP 800-53
- ICD 503
- CNSSI 1253
- ISSO/ISSE
- IATT and Authorization to Operate (ATO)
- Xacta, eMASS, SSP, SCTM, BoE
- Nessus/ACAS, SCAP/SCC, STIG Viewer, Nmap
- Linux/Unix
- TCP/IP, DNS, HTTP/HTTPS, VPNs, IDS/IPS, firewalls, DMZ configurations
- Web Application Firewalls (WAFs), Web applications, antimalware technologies, APT prevention
Travel Requirements
- Percentage of Travel Required: Up to 10%
- Type of Travel: Local
Clearance & Certifications
- Current active TS/SCI eligibility
- DoD 8570/8140 IASAE Level III (e.g., CISSP)
Compensation
The proposed salary range for this position is $103,800 - $218,100 per year.
Benefits
- Flexible time off benefit
- Robust learning resources
- Healthcare
- Wellness
- Financial benefits
- Retirement
- Family support
- Continuing education
- Time off benefits