Information Systems Security Engineer (Hybrid)
Northstrat
- Fort Belvoir, VA
- Permanent
- Full-time
- Candidates must be able to thoroughly understand how a system works from a technical perspective, rather than just a compliance-oriented one.
- They should be able to clearly relay this technical understanding to a less technical audience (e.g., other traditional RMF roles).
- We are not looking for compliance-only ISSEs for our current roles.
- Reduce our reliance on these highly technical personnel for routine tasks.
- Utilize them more effectively for their intended purpose: Subject Matter Expert (SME) support.
- Will create, review and edit authorization documentation for completeness and accuracy in accordance with federal and DoD policy.
- Thoroughly understand and be able to implement DoD RMF system accreditation processes.
- Assess use case and operational risk of integrated open source, and GOTS/COTS software components.
- Will use vulnerability management systems, automated security scanning tools, and system accreditation record systems.
- Must be able to grasp new concepts, facilitate information exchanges for data gathering, and collaborate with diverse audiences.
- Will follow established processes where applicable and establish and execute defensible processes where none are prescribed.
- Provide security planning, assessment, risk analysis, and risk management support.
- Recommend system-level solutions to resolve security requirements and guide the development team in meeting the security posture requirements.
- Support the Government in the enforcement of the design and implementation of trusted relationships among external systems and architectures.
- Must apply existing knowledge of IA policy, procedures, and workforce structure to design, develop, and implement secure networking, computing, and enclave environments.
- Must be able to interact well with others to complete work.
- Technical proficiency across technologies is paramount.
- Must have a current TS/SCI level U.S. Government clearance is required and therefore all candidates must be a U.S. Citizen.
- At least 9+ years of experience as an ISSE with large multi-tiered programs and Bachelors in related field; OR 7 years relevant experience with Masters in related field; OR High School Diploma or equivalent and 13 years relevant experience.
- Experience implementing DoD system accreditation processes (DIACAP acceptable and RMF preferred).
- A working knowledge of TCP/IP suite of protocols and services, computer architectures, and network topologies is required.
- A DoD 8570 compliance with IAT Level II (SSCP, Security+, CCNA-Security, or GSEC certification) is required
- Experience with DISA STIGs and SRGs, vulnerability management systems, mitigation and compliance processes, and reviewing results from automated security scanning tools.
- The ability to work independently and as part of a team is needed.
- Flexibility is essential to adapt to schedule changes as needed.
- CISSP-ISSEP is highly desired