Search jobs > Washington, DC > Information system security

Information System Security Engineer (ISSE) - Security Clearance Required

Envisioneering
Washington, District of Columbia
Full-time

Envisioneering, Inc. is seeking an Information Systems Security Engineer (ISSE) to support an active government contract.

This position will be responsible for the following :

Summary ISSE Responsibilities :

  • Oversee the development and maintenance of a system’s cybersecurity solutions.
  • Identify AO and SCA cognizance (i.e. FAO or NAO, and FSCA or SCA) of the system as well as any specific authorization requirements such as reciprocity, cross domain, and applicable overlays to support System Categorization.
  • Identify mission criticality.
  • Identify and tailor the security control baseline with applicable overlays.
  • Assist with development, maintenance, and tracking of the SP.
  • Lead the security control implementation and testing efforts.
  • Perform vulnerability-level risk assessment on the POA&M / RISK Assessment Worksheet.
  • Assist with any security testing required as part of A&A or annual reviews.
  • Assist in the mitigation and closure of open vulnerabilities under the system’s change control process.
  • Oversee cybersecurity testing to assess security controls and recording security control compliance status during the continuous monitoring phase of the lifecycle.
  • Make data entries into the eMASS record and POA&M consistent with implementation results.
  • Utilize the Collaboration Board in the eMASS workflow for all formal coordination during the RMF process. Detailed findings will be posted in the Artifacts tab (if necessary).
  • Rework shall be documented and provided to the PSO / PMO for review.

Assist the ISSM / ISSO with the following responsibilities :

  • Lead the RMF process for assigned programs, organizations, systems, or enclaves.
  • Maintain and report system’s A&A status and events.
  • Manage the SP for assigned systems throughout their lifecycle.
  • Perform annual security reviews, annual testing of security controls, and annual testing of the contingency plan, in line with FISMA requirements.
  • Manage POA&M entries and ensuring vulnerabilities are properly tracked, mitigated, and resolved.
  • Assist with identification of the security control baseline set and any applicable overlays.
  • Supervise the validation of security controls with the PM / ISO, SCA Liaison, PSO, and AO CSA.
  • Assemble the Security Authorization Package and submit for adjudication.
  • Register and maintain the system in eMASS.
  • Assess the quality of security control implementation against all requirements in accordance with the approved SLCM strategy.
  • Plan and perform cybersecurity testing to assess security controls and recording security control compliance status during sustainment.
  • Report changes in the security posture of systems to the AO.
  • Utilize the Collaboration Board in eMASS workflow for all formal coordination during the RMF process. Detailed findings will be posted in the Artifacts tab (if necessary).
  • Assist the ISSMs in executing their duties and responsibilities.
  • Ensure compliance with all USN, DON, and DoD cybersecurity policies.
  • Ensure all users possess the requisite security clearances and awareness of their responsibilities for systems under their purview prior to being granted access.
  • Ensure an incident response, business continuity, disaster recovery, as well as vulnerability and threat reporting plans and channels are in place and that team members are trained accordingly.
  • Ensure relevant policy and procedural documentation is current and accessible to properly authorized individuals
  • Utilize the Collaboration Board in the eMASS workflow for all formal coordination during the RMF process. Detailed findings will be posted in the Artifacts tab (if necessary).

PHYSICAL DEMANDS :

Sedentary / 10 lbs. maximum. Occasional life / carry of small articles. Some occasional walking or standing may be required.

MINIMUM SKILLS / QUALIFICATIONS :

  • Must have and maintain a DoD Top Secret Clearance.
  • CompTIA Security+ or other DOD 8570.01 IAT Level 2 or 3 certification.
  • 6-10 years of system administration and / or cybersecurity experience.
  • Working knowledge of system administration fundamentals which may include, but is not limited to, administration of desktop / workstations, dedicated and virtual servers, Microsoft Active Directory.
  • Self-motivated and the ability to multi-task and balance multiple goals and priorities.
  • Must be familiar with DOD Risk Management Framework (RMF) policies, standards, procedures and have relevant experience with associated tools (e.

g., eMASS, XACTA 360, Assured Compliance Assessment Solution (ACAS), Anchore, DISA Security Technical Implementation Guides (STIGs), SCAP Compliance Checker (SCC), STIG Viewer, eMASSter, Eval STIG).

EDUCATION :

  • High School diploma or GED equivalent.
  • Security+ or other DOD 8570.01 IAT Level 2 or 3 certification.
  • BENEFITS : Envisioneering, Inc. offers a stable work environment, a competitive salary, and a comprehensive benefits package effective date of hire;

including 401k, Medical / Dental / Vision, FSA, Short Term, Long Term, AD&D and Life insurance, (employer paid), voluntary life, Tuition Reimbursement, Paid Leave, Holidays and much more.

AS A CONDITION OF EMPLOYMENT : You must pass a drug and pre-employment drug screening. U.S. Citizenship Required. Candidate must follow all company and non-DOT Drug and Alcohol Testing.

A Department of Defense (DoD) Top Secret security clearance is required at time of hire. Applicants selected will be subject to a U.

S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.

S. citizenship is required. Please confirm in your cover letter or resume.

IT-SECURITY

30+ days ago
Related jobs
Promoted
AKIMA
Washington, District of Columbia

Bachelor of Science degree in Computer Engineering, Computer Information Systems, Telecommunications, or Management Information Systems preferred. Monitor and maintain McAfee's Host-Based Security System (HBSS), ensuring virus definitions, patch versions, and Department of Defense (DoD) Security Tec...

Promoted
ASRC Federal
Washington, District of Columbia

The COOP Project Engineer shall be proficient in war fighting reporting systems that focus on military functions, such as, equipping the force, causalities, planning, logistics, COOP, and requirements, while working at a minimum at the CMMI Maturity Level 3 for Development and Level 2 for services. ...

Promoted
AKIMA
Washington, District of Columbia

RiverTech provides innovative solutions to complex engineering and operational challenges and delivers wide-ranging services for mission support, systems engineering, and IT. Current active TS/SCI security clearance. While data sharing has occurred through collaborative means, the process is marred ...

Promoted
V2X
Washington, District of Columbia

Clearance must have an current, adjudicated, and active TS/SCI security clearance with Poly. Clearance must have an current, adjudicated, and active TS/SCI security clearance with Poly. Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for ...

Promoted
OneZero Solutions
Washington, District of Columbia

In-depth understanding of information security principles and best practices, including network security, system security, encryption, incident response, and risk management. OneZero Solutions is on contract to provide division-wide support for Federal Information Security Modernization Act (FISMA) ...

Promoted
BTI
Washington, District of Columbia

Demonstrated experience managing systems security assessments, reviewing system security documentation for successful security authorization of such systems. Manage Information System Security Officers (ISSO) to support information technology (IT) security goals and objectives and reduce overall org...

H2 Performance Consulting Corporation
Washington, District of Columbia

H2 Performance Consulting (H2) is seeking a Cloud Information Systems Security Engineer (ISSE). BS in Computer Science/Information Systems/Engineering, or a strong grasp of Computer Science/Information Systems with relevant experience. Work closely with engineers to perform security impact analysis ...

RedTrace Technologies Inc
Washington, District of Columbia

Develop Plan of Action and Milestones (POAMs) in response to reported security vulnerabilities Manage the risks to ISs and other agency assets by coordinating appropriate correction or mitigation actions, and oversee and track the timely completion of (POAMs) Coordinate system owner concurrence for ...

Ark Solutions
Washington, District of Columbia

Current and maintained certification in one or more of the following IT Security disciplines: Certified in Risk and Information Systems Control (CRISC), Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP) or equivalent certification required. ...

ST2 ManTech Advanced Systems Intl
Washington, District of Columbia

Provides recommendations on information assurance engineering standards, implementation dependencies, and changing information assurance related technologies. Knowledge and experience with information network security equipment. Tests and operates firewalls, intrusion detection systems, enterprise a...