This on-site Information Systems Security Engineer (ISSE) role supports DoD and NIST-aligned security architecture, vulnerability management, incident response, and accreditation across the system development lifecycle.
Responsibilities
- Design, implement, and sustain an enterprise security architecture aligned with NIST RMF, DoD STIGs, CIS benchmarks, and internal cybersecurity policies.
- Lead security engineering activities throughout the SDLC, including requirements analysis, design reviews, security testing, and accreditation support.
- Operate vulnerability management programs using Tenable Nessus, ACAS, and Qualys to identify, evaluate, and remediate weaknesses.
- Incorporate cybersecurity requirements into Windows and Linux servers, cloud environments, virtualization platforms, and containerized apps.
- Assist incident response and forensic investigations by evaluating security logs, SIEM alerts, network traffic, and endpoint telemetry with Splunk Enterprise.
- Develop automation scripts in PowerShell, Bash, and Python to streamline remediation, auditing, compliance reporting, and monitoring tasks.
- Collaborate with system administrators, network engineers, ISSOs, and application teams to address findings and establish secure baselines.
- Conduct security impact analyses for system changes, software deployments, and infrastructure upgrades to maintain compliance and security.
- Engineer endpoint protection and hardening using Trellix ePO on-premises, host-based firewalls, and application whitelisting.
- Assess and implement cybersecurity tools to enhance posture, continuous monitoring, and threat detection capabilities.
- Produce technical security documentation, architecture diagrams, SOPs, and executive risk assessment reports.
- Experience with administering and troubleshooting CyberArk core modules including EPV, PVWA, CPM, and PSM.
- Monitor, analyze, and detect cyber events within information systems and networks under general supervision.
- Support integrated cyber defense initiatives and maintain security toolsets for continuous monitoring and ongoing authorization programs.
- Establish a framework for measuring and quantifying cyber risk in practical terms.
- Determine security requirements by evaluating business needs, researching standards, performing risk assessments, and assessing architecture and integration issues.
- Specify intrusion detection methodologies and oversee equipment installation, calibration, documentation, and key management; verify systems with test scripts.
- Maintain security by ensuring adherence to standards, policies, and procedures, conducting incident analyses, and delivering training.
- Contribute to the design, development, implementation, and integration of DoD information assurance architectures for computing, network, and enclave environments.
- Ensure development and operational systems are secure and functional, including program of record systems and special purpose processing nodes with IT interconnectivity.
Requirements
- 5 years of professional experience with a bachelorβs degree; 3 years with a masterβs degree; 0 years with a PhD, with 4+ years of experience in lieu of a degree.
- Active Top Secret clearance with SCI eligibility.
- DoD 8570.1-M / 8140 IAT Level III certification (SecurityX CASP, GCIH, CISA, or CISSP) compliant.
- Strong background in networking (TCP/IP, firewalls, VPNs), cloud security (AWS/Azure), Kubernetes, and DevSecOps.
- Solid understanding of NIST SP 800-161, NIST RMF, FedRAMP, Common Criteria, ATO package development, and STIG compliance.
- Hands-on experience deploying and managing Nessus, CyberArk, Trellix, Splunk, VMware vSphere, GitLab, Windows Server, Red Hat Enterprise Linux, and Ubuntu.
- Proficiency in scripting and automation with PowerShell, Python, Bash, and Ansible.
- Proven ability to lead projects and mentor junior ISSEs, with experience delivering technical briefings to leadership.
Technologies
- Tenable Nessus, ACAS, Qualys
- Splunk Enterprise
- PowerShell, Bash, Python
- Trellix ePO
- CyberArk, EPV, PVWA, CPM, PSM
- VMware vSphere
- Microsoft Windows Server
- Red Hat Enterprise Linux, Ubuntu Linux
- GitLab
- Kubernetes
- Ansible
- AWS, Azure
Benefits
- Medical
- Dental
- Vision
- Life
- Health Savings Account
- Short-term disability
- Long-term disability
- EAP
- Parental leave
- 401(k)
- Paid time off for vacation
- Company paid holidays
About the Role
The position encompasses designing, implementing, and maintaining an enterprise security architecture in line with NIST RMF, DoD STIGs, and CIS benchmarks, while supporting the secure SDLC through requirements analysis, design reviews, testing, and accreditation. It involves managing vulnerability programs with Nessus, ACAS, and Qualys, integrating security controls across Windows, Linux, cloud, virtualization, and container environments, and aiding incident response with Splunk Enterprise. The role also includes developing automation in PowerShell, Bash, and Python to improve remediation and compliance reporting, collaborating across IT teams to remediate findings, performing security impact analyses for changes, engineering endpoint protection with Trellix ePO, evaluating new cybersecurity tools, and producing security documentation and risk assessments. Experience with CyberArk core modules is required, along with ongoing monitoring and defense activities to support continuous monitoring and authorization programs and to quantify cyber risk for the organization.
Qualifications
In addition to the requirements above, the role demands demonstrated leadership in projects and mentoring of junior ISSEs, and the ability to present technical concepts to leadership. Candidates should exhibit a comprehensive understanding of cybersecurity standards and a track record of implementing secure, compliant architectures within DoD contexts.
Details
- Target Salary Range: USD 135,000 - 216,000 per year. Salary is determined by scope, experience, education, and location, with potential for additional overtime or discretionary bonuses depending on role and contract terms.
- Benefits Statement: Eligible employees receive medical, dental, vision, life, health savings account, short and long term disability, EAP, parental leave, 401(k), paid time off for vacation, and company paid holidays. Full benefits details are available at the employer's careers site.
- Application Statements: The posting is open for an estimated 30 days from the date of posting, subject to change. Applicants may be invited to participate in on-camera interviews and identity verification during the process.
- EEO: This is an equal opportunity employer, including protections for disability and protected veterans, among other legally safeguarded characteristics.