
Information System Security Engineer
- Washington DC
- Permanent
- Full-time
- Achieve ATOs for our client’s software across multiple government customers with minimal oversight.
- Partner with engineers to analyze software, interpret security requirements, and plan effective control implementations.
- Provide outstanding customer service, policy expertise, and high-quality documentation.
- Serve as the primary in-person point of contact for one or more U.S. Government customers on cybersecurity and compliance requirements and questions.
- Independently interpret the findings of vulnerability scanning utilities such as ACAS (Tenable Nessus) and SCAP (STIG benchmark) and manage a Plan of Actions and Milestones (POA&M) for remediation of findings.
- Active U.S. DoD Top Secret clearance with SCI eligibility.
- Active DOD 8140 or 8570 Certification (e.g. CISSP or Security+).
- Active IAT II certification.
- Specific experience working in on-premises environments using security tools such as ACAS, SIEMs, and STIG related software.
- Minimum 2 years experience directly supporting a customer’s ATO/RMF process.
- Be at customer site 5 days per week.
- Proficiency in interpreting and communicating government policy to a diverse audience.
- Ability to multitask under pressure, using time management and organizational skills.
- Specific experience working in both traditional on premises environments and cloud environments such as Amazon Web Services (AWS).
- Experience accrediting IT systems against U.S. Government standards including NIST SP 800-53, CNSSI 1253, and the DISA STIGs, using frameworks like DOD RMF, ICD 503, or DIACAP.
- Initiative in proactively identifying problems before they arise and creativity in proposing solutions.