Overview
Skills
Job Details
Job Title: Information Systems Security Engineer
Duration: 12 Months
Location: Remote
Summary
We are seeking an experienced Information Systems Security Engineer (ISSE) to support ongoing security engineering, documentation, and accreditation activities. The ideal candidate will have strong multi-tasking skills, the ability to manage multiple Assessment and Authorization (A&A) systems/projects simultaneously, and excellent communication skills for interfacing with both technical staff and senior leadership.
This role requires a deep understanding of complex network environments, Risk Management Framework (RMF), and ICD 503 Security Accreditation processes, as well as hands-on experience supporting cloud and SaaS environments.
Responsibilities
Manage multiple A&A systems and projects simultaneously while effectively communicating across all organizational levels.
Work within complex network environments involving shared networks and multiple security enclaves.
Translate technical engineering concepts into security-focused language that is clear and easy to understand for diverse audiences.
Document security control implementations and collect artifacts to support RMF and ICD 503 Security Accreditation efforts.
Review and document system architectures to develop System Security Plans (SSP) and Concepts of Operations (CONOPS).
Collaborate with system owners, project managers, and engineers to create A&A-related documents, including:
Contingency Plan (CP)
General User Guide (GUG)
Privileged User Guide (PUG)
Standard Operating Procedures (SOPs)
Document and track Plans of Action and Milestones (POA&Ms), including mitigations and evidence gathering.
Coordinate with stakeholders and customer security organizations to navigate the A&A process and achieve:
Authority to Develop (ATD)
Interim Authority to Test (IATT)
Authority to Operate (ATO)
Provide ongoing support for ATO ed systems within the continuous monitoring phase.
Education, Experience & Skills
8+ years of experience in Information Systems Security Engineering or related field.
Bachelor s degree minimum required.
Previous ISSE experience directly supporting enterprise-level projects or customers.
Strong knowledge and experience with SaaS applications and cloud environments (AWS, Microsoft Azure, private and hybrid clouds).
Certifications (at least one required)
Certified Information Systems Security Professional (CISSP)
GIAC Security Leadership Certification (GSLC)