Senior Principal Cyber Information Systems Security Engineer
Job Description
Lead Risk Management Framework (RMF) authorization efforts across unclassified and classified DoD environments as a senior principal ISSE technical authority.
Responsibilities
- Act as Senior Principal ISSE and subject matter expert, leading development, management, and authorization of RMF packages for unclassified and classified environments supporting DoD enterprise IT and network modernization programs
- Perform end-to-end RMF lifecycle activities in alignment with NIST 800-39, 800-37, 800-53, 800-53A, and 800-137 across multiple simultaneous systems
- Categorize systems and information using FIPS 199 and NIST 800-60; select and tailor initial security control baselines based on FIPS 200 and NIST 800-53
- Implement security controls using NIST Special Publication guidance (including 800-34, 800-64, 800-128); document implemented controls with specific and functional documentation
- Assess security controls using NIST 800-53A to verify correct implementation, intended operation, and achievement of desired outcomes
- Manage and maintain eMASS records for assigned systems; ensure RMF artifacts, POA&Ms, and authorization documentation remain accurate and complete across the system lifecycle
- Drive RMF packages through full authorization workflows following Navy and DoD RMF processes; coordinate with Authorizing Officials (AOs), Information System Owners (ISOs), and Program Managers to achieve and maintain Authority to Operate (ATO)
- Ensure continuous monitoring through NIST 800-137, 800-37, 800-53A, and related special publications; sustain ongoing ATO compliance
- Collaborate with engineering teams to identify, document, and implement security controls across complex DoD enterprise IT and network infrastructure
- Perform internal auditing activities supporting ISO/IEC 9000, 20000, and 27001; coordinate with external auditors to ensure actions align with industry standards
- Conduct policy analysis to author or support enterprise cybersecurity policy aligned with DoD and Navy security requirements
- Provide expert technical guidance and mentorship to junior cybersecurity team members on RMF processes, eMASS management, and ATO authorization workflows
- Serve as organizational spokesperson and prime ISSE technical contact for significant cybersecurity authorization matters across program teams, engineering organizations, and government stakeholders
- Support business development activities, including technical proposal development, capability demonstrations, and customer relationship management for program re-compete and growth opportunities
Requirements
- Bachelor’s degree and 14+ years of related experience; or Master’s degree and 12+ years; or PhD or JD and 9+ years
- 10+ years of hands-on ISSE and RMF experience with demonstrated senior principal-level contributions in complex DoD program authorization environments
- U.S. Citizen
- Active Secret Clearance at start
- Ability to obtain TS/SCI after start
- DoD 8570/8140 IAM Level III or IAT Level III certification required (CISSP, CISM, or equivalent)
- CompTIA Security+ CE required at minimum
- Experience with RMF lifecycle management (NIST 800-37, 800-53, 800-53A, 800-137)
- Experience with eMASS system management and ATO package development
- Experience with FIPS 199 system categorization and security control selection
- Experience with POA&M development, tracking, and remediation management
- Experience with unclassified and classified system authorization workflows
- DoD enterprise IT and network infrastructure security experience
Technologies
- Risk Management Framework (RMF)
- eMASS
- NIST 800-39, NIST 800-37, NIST 800-53, NIST 800-53A, NIST 800-137
- FIPS 199, NIST 800-60, FIPS 200
- NIST 800-34, NIST 800-64, NIST 800-128
- ISO/IEC 9000, ISO/IEC 20000, ISO/IEC 27001
- NIST Special Publication guidance documents
- POA&M