Cybersecurity Engineer

Nortex Cyber

Fort Meade, Northern (MD, KY)

Hybrid

USD 140,000 - 185,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Company-paid medical insurance
Dental and vision insurance
Competitive salary
Generous 401k with immediate vesting
Generous PTO & parental leave
Flexible work hours

Job summary

Nortex Cyber Solutions is seeking an experienced Cybersecurity Engineer / ISSE to support RMF authorization, assessment, and continuous monitoring of mission-critical information systems.

The role requires strong RMF, NIST 800-53, and STIGs expertise, vulnerability assessments with ACAS/Nessus, and development of authorization packages in eMASS/Xacta within NSA environments.

Qualifications

  • Bachelor's degree in a related technical field preferred.
  • 10+ years of cybersecurity, information assurance, RMF, or systems security engineering experience.
  • Active TS/SCI clearance with CI polygraph at time of hire.

Responsibilities

  • Support RMF lifecycle for information systems seeking or maintaining authorization.
  • Develop, review, maintain, and update system security authorization packages and evidence.
  • Apply security controls per NIST SP 800-53 and DoDI 8510.01 RMF for DoD IT.
  • Use MASS and Xacta to develop, maintain, track, and manage authorization documentation.
  • Scope security assessments and conduct assessments for accreditation/authorization.
  • Coordinate Interim Authorizations to Test (IATTs) for testing prior to full authorization.
  • Evaluate configurations against DISA STIGs, CIS Benchmarks, and other standards.
  • Conduct vulnerability assessments using ACAS/SecurityCenter and Nessus.
  • Review vulnerability findings, track remediation, and support POA&Ms.
  • Collaborate with engineers to implement and validate security controls.
  • Support automated continuous monitoring of controls, vulnerabilities, and configurations.
  • Identify automation opportunities to improve RMF and monitoring processes.
  • Leverage AI-enabled tools when beneficial while ensuring proper RMF expertise.
  • Maintain traceable documentation linking requirements, controls, results, and evidence.
  • Participate in SAFe Agile processes and communicate risks to stakeholders.

Skills

RMF knowledge
Vulnerability assessment
Communication skills
Automation
SAFe Agile
Documentation
Security controls
NSA/DoD environment
Security package automation

Education

Bachelor's degree in Cybersecurity/CS/IT/Engineering

Tools

eMASS
XACTA
ACAS/SecurityCenter
Nessus

Job description

CLEARANCE REQUIRED FOR START:Yes

CLEARANCE TYPE:Top Secret/SCI with CI Polygraph

LOCATION:Fort Meade, MD

Job Summary

Nortex Cyber Solutions is seeking an experiencedCybersecurity Engineer / Information Systems Security Engineer (ISSE)to support the security authorization, assessment, and continuous monitoring of mission-critical information systems.

This position requires a strong technical understanding of the Risk Management Framework (RMF), security controls, system hardening, vulnerability management, and the development and maintenance of authorization packages. The ideal candidate can independently evaluate system security, identify and document risk, maintain traceable bodies of evidence, and work with engineering teams to implement practical security solutions throughout the system lifecycle.

The individual must be comfortable working within classified environments and accessing and maintaining security packages within NSA environments.

Duties/Responsibilities
  • Support the fullRisk Management Framework (RMF)lifecycle for information systems seeking or maintaining authorization.
  • Develop, review, maintain, and update system security authorization packages and supporting bodies of evidence.
  • Apply and interpret security controls and requirements in accordance withNIST SP 800-53andDoD Instruction 8510.01 (RMF for DoD IT).
  • Use security package management and governance tools such aseMASSandXactato develop, maintain, track, and manage system authorization documentation.
  • Scope security assessments and conduct assessments of information systems undergoing accreditation/authorization or maintaining an existing authorization.
  • Support the preparation, coordination, and approval ofInterim Authorizations to Test (IATTs)for systems requiring testing prior to full authorization.
  • Evaluate system configurations against applicableDISA Security Technical Implementation Guides (STIGs),CIS Benchmarks, and other security configuration standards.
  • Conduct and analyze vulnerability assessments using tools such asACAS/SecurityCenter and Nessus.
  • Review vulnerability scan results, determine applicability and risk, track remediation activities, and support the development and maintenance of Plans of Action and Milestones (POA&Ms), as applicable.
  • Work closely with system engineers, developers, and other technical stakeholders to implement and validate security controls.
  • Support the implementation of automated solutions forcontinuous monitoring of security controls, vulnerabilities, configurations, and other security requirements.
  • Identify opportunities to improve RMF, assessment, evidence collection, and continuous monitoring processes through automation.
  • Appropriately leverage AI-enabled tools when beneficial while maintaining sufficient cybersecurity and RMF expertise to independently understand, validate, and take responsibility for the intended outcome.
  • Maintain organized, accurate, and traceable documentation demonstrating the relationship between security requirements, implemented controls, assessment results, findings, remediation activities, and supporting evidence.
  • Participate in Agile development and engineering environments and work effectively withinSAFe Agileprocesses.
  • Communicate security risks, findings, and requirements clearly to both cybersecurity and engineering stakeholders.
Require Qualifications
  • ActiveTS/SCI clearance with CI Polygraphrequired at time of hire.
  • Ability to access required classified environments and security packages within NSA systems.
  • Strong working knowledge of theDoD Risk Management Framework (RMF)and the complete authorization lifecycle.
  • Strong knowledge ofNIST SP 800-53security and privacy controls andDoDI 8510.01.
  • Experience developing, reviewing, and maintaining RMF authorization packages and supporting bodies of evidence.
  • Hands-on experience witheMASS and/or Xactafor security package and authorization management.
  • Strong understanding ofDISA STIGs, CIS Benchmarks, system hardening, and security configuration requirements.
  • Experience usingACAS/SecurityCenter and Nessusfor vulnerability scanning, analysis, and remediation support.
  • Experience scoping and conducting security assessments for information systems undergoing or maintaining authorization.
  • Knowledge of theIATT processand experience supporting systems requiring authorization for testing.
  • Understanding of continuous monitoring requirements and approaches for validating security controls throughout the system lifecycle.
  • Ability to work with technical teams to develop or implement automation supporting cybersecurity and continuous monitoring activities.
  • Familiarity withSAFe Agileor similar Agile development environments.
  • Strong written and verbal communication skills.
  • Exceptional attention to detail, organization, documentation, and configuration management.
  • Ability to maintain clear traceability across security requirements, implementation details, assessment procedures, findings, and supporting evidence.
Preferred Qualifcations
  • Experience supporting NSA, DoD, or Intelligence Community information systems.
  • Experience working directly with system owners, ISSMs, ISSOs, security control assessors, and Authorizing Official representatives.
  • Experience with continuous monitoring and automated security control validation.
  • Experience integrating security activities into CI/CD or DevSecOps environments.
  • Experience developing scripts, workflows, or other automation to improve security assessment, evidence collection, vulnerability management, or compliance processes.
  • Familiarity with AI-assisted cybersecurity or compliance workflows, with the technical expertise necessary to independently verify AI-generated outputs.
  • Relevant cybersecurity certifications such as Security+, CISSP, CAP/CGRC, CASP+/SecurityX, or equivalent.
Education & Experience
  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field preferred.
  • 10+ years of relevant cybersecurity, information assurance, RMF, or systems security engineering experience.
  • Equivalent combinations of education, certifications, and directly relevant experience may be considered.
Physical Requirements
  • Ability to remain seated and work at a computer for extended periods.
  • Ability to occasionally lift up to 15 pounds.
  • Ability to communicate effectively in person and through virtual collaboration tools.
Benefits & Perks

As an Employee First company, we offer a comprehensive and competitive total rewards package:

  • 100% Company-paid medical insurance for employees
  • 100% Company-paid dental and vision insurance
  • Competitive salary
  • Generous 401k employer contribution to your 401k with no required personal contribution with immediate vesting
  • Generous PTO and parental leave
  • Flexible work hours

This role requires use of technical data subject to U.S. Government contract restrictions; therefore, this posting is only for U.S. Citizens.

Nortex Cyber Solutions is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, disability status, genetic information, protected veteran status, or any other characteristic protected by law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer
Cybersecurity Engineer

Nortex Cyber Solutions • Fort Meade (MD)

On-site
USD 120,000 - 180,000
Medical, dental, vision insurance
401k with employer contributions
Generous PTO and parental leave
+1
Information/Cybersecurity Engineer (Clearance Required)
Information/Cybersecurity Engineer (Clearance Required)

Nexxis Solutions • Maryland

On-site
USD 90,000 - 230,000
Competitive salary
Limited telework
Comprehensive benefits package
Information Cybersecurity Engineer Clearance Required
Information Cybersecurity Engineer Clearance Required

Nexxis Solutions • Corridor North (MD)

On-site
USD 90,000 - 250,000
Paid time off
Medical/dental/vision insurance
401k and more
Cyber Security Analyst
Cyber Security Analyst

Scientific Research Corporation • San Diego (CA)

On-site
USD 97,000 - 161,000
401(k) match
Medical, dental, vision plans
Tuition reimbursement
+1
Cybersecurity Engineer
Cybersecurity Engineer

Precise Systems • San Diego (CA)

On-site
USD 78,000 - 129,000
Health insurance
Retirement plans
Disability insurance
+2
Cybersecurity Systems Analyst, Intermediate
Cybersecurity Systems Analyst, Intermediate

TJ Consulting Group • Tampa (FL)

On-site
USD 90,000 - 130,000
PTO
Holiday Pay
401K Match
+11
Information Systems Security Engineer (ISSE) - FULLY CLEARED with POLYGRAPH REQUIRED
Information Systems Security Engineer (ISSE) - FULLY CLEARED with POLYGRAPH REQUIRED

Constellation Technologies, Inc • Maryland

On-site
USD 120,000 - 190,000
Healthcare options
Dental package
Vision with employer paid premium
+6
Cyber Security Analyst II
Cyber Security Analyst II

Scientific Research Corporation • San Diego (CA)

On-site
USD 84,000 - 140,000
Medical, dental, and vision plans
401(k) with company match
Paid time off & holidays
+1
Cybersecurity Systems Analyst, Associate
Cybersecurity Systems Analyst, Associate

TJ Consulting Group • Tampa (FL)

On-site
USD 70,000 - 100,000
PTO
Holiday Pay
401K with a 4% Match
+13
Cybersecurity and Vulnerability Management Systems Administrator
Cybersecurity and Vulnerability Management Systems Administrator

NexGen Data Systems • Columbus (OH)

On-site
USD 120,000 - 160,000
Premium health insurance for employee
401(k) match
Training & development program
+1