Information System Security Engineer

Navstar Inc.

Columbia (MD)

On-site

USD 140,000 - 190,000

Full time

9 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Navstar Inc. in Maryland seeks a Senior ISSE to lead threat-informed cybersecurity activities, including risk assessments, architecture reviews, and engineering guidance for mission partners.

You will support real-time threat detection capabilities, analyze architectures for security gaps, research emerging technologies, and assist stakeholders with security planning, validation, and policy alignment.

Qualifications

  • Active TS/SCI with Polygraph required.
  • Bachelor of Science in CS/IA or related field with extensive ISSE/Systems Engineer experience.

Responsibilities

  • Lead threat-informed cybersecurity products including risk assessments and architecture reviews.
  • Support design, implementation, and operation of real-time capabilities to discover, detect, analyze, and mitigate threats.
  • Evaluate candidate architectures against security requirements to identify gaps and propose mitigations.
  • Research emerging technologies to determine cybersecurity effectiveness.
  • Assist stakeholders in developing and implementing innovative security solutions.

Skills

Active TS/SCI with Poly
CISSP or CASP
RMF expertise
Cybersecurity risk assessments
Security engineering
NIST 800-series knowledge
DoD 8500 knowledge
Brief DoD officials
Independent work
Emerging tech: Zero Trust/Cloud
Threat-informed approach

Education

Bachelor of Science in Computer Science or Information Assurance or related field

Job description

The Senior ISSE shall deliver and lead threat-informed cybersecurity products - cybersecurity risk assessments, architecture reviews, and engineering guidance that bring sound, accurate, timely, and actionable service to mission partners. This includes:

  • Conduct cybersecurity risk assessments and provide prioritized risk mitigation recommendations in support of the customer’s mission.
  • Support the design, implementation, and operation of real-time capabilities to discover, detect, analyze, and mitigate threats and vulnerabilities.
  • Analyze candidate architectures by evaluating against defined security requirements to identify security gaps, and provide recommended mitigation strategy.
  • Research and evaluate candidate emerging technologies to determine cybersecurity effectiveness.
  • Aid stakeholders through the development, refinement, delivery, and implementation of innovative solutions and capabilities.
  • Engage stakeholders to ensure security objectives, protection needs, security requirements and associated validation methods are defined.
  • Validates and verifies system security requirements definitions and analysis and establishes system security design.
  • Designs, develops, implements and/or integrates IA and security systems and system components including those for networking, computing and enclave environment to include those with multiple enclaves and with differing data protection/classification requirements.
  • Assist architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of Agency security policy and enterprise solutions.
  • Contributes to the security planning, assessment, risk analysis, risk management, certification and awareness activities for system and networking operations.
  • Reviews C&A documentation, providing feedback on completeness and compliance of its content.
Required Skills and Qualifications:
  • To be eligible for this position you must hold an active TS/SCI clearance with Polygraph.
  • Bachelor of Science degree from an accredited university ideally in Computer Science, Information Assurance, Information Security System Engineering or related field with a minimum of 14 years of experience as an Information Systems Security Engineer (ISSE) or System Engineer.
  • CISSP OR CASP certification required.
  • Confidence and ability to present briefing to senior level DoD officials in both prepared briefings and/or in ad hoc discussions.
  • Expertise in the Risk Management Framework (RMF) and conducting cybersecurity risk assessments.
  • Expertise in network technology and systems security engineering. Experience in identifying, researching, characterizing, and documenting security weaknesses related to operating systems, software applications, firmware, network hardware components, as well as network architecture design to identify protection needs and documented policies and procedures.
  • Experience developing and documenting system security requirements and conducting requirements gap analysis.
  • Experience with security monitoring and incident response capabilities.
  • Experience with emerging technologies such as Zero Trust, Cloud Computing, etc.
  • Knowledge of, and practical experience with the NIST Special Publications 800 Series, CNSSI 1253, and DoD 8500.
  • Ability to work independently within a schedule and with little direction.
Desired Skills and Qualifications:
  • Experience with the following: JEE (EJB, JPA, JTA, JAX-B, JAX-RS, JAX-WS), SQL, application servers (Tomcat, WebLogic, JBoss), scripting.
  • Experience with high level requirements management including requirements decomposition, secure systems engineering and development, trade-off analysis, interface control, and testing and continuous integration.
  • Experience in software development on Agile teams using Agile Developer practices such as Pair Programming, TDD, Refactoring, and ATDD.
  • Experience with FITNesse, Mockito, Cucumber, Unified Functional Tester (UFT), Selenium.
  • Experience with Behavior Driven Development (BDD).
  • Experience with the Scaled Agile Framework (SAFe) methodology, SAFe Agilest Certification, or experience as a member of an agile team.
  • Additional experience in J2EE, Python, C/C++, SQL, SOAP, WSDL, Postgres, Oracle, Mongo, PowerShell a plus.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Engineer
Information Systems Security Engineer

VT Group (VTG) • Chantilly (VA)

On-site
USD 90,000 - 120,000
Information Systems Security Engineer (INFOSEC Engineer, ISSE)
Information Systems Security Engineer (INFOSEC Engineer, ISSE)

M2 Solutions Inc. • Herndon (VA)

On-site
USD 120,000 - 150,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Vosper Thornycroft Group • Chantilly (VA)

On-site
USD 90,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

VT Group (VTG) • Chantilly (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

VTG Defense • Chantilly (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (INFOSEC Engineer, ISSE)
Information Systems Security Engineer (INFOSEC Engineer, ISSE)

M2 Solutions • Herndon (VA)

On-site
USD 100,000 - 130,000
Information Security System Engineer
Information Security System Engineer

Elevate Technology Group • Fairfax Station (VA)

On-site
USD 150,000 - 220,000
Employer-funded 401(k) contribution
Flexible benefits allowance
Medical, Dental & Vision coverage
+1
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Evans & Chambers • Arlington (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (ISSE) Level 2
Information Systems Security Engineer (ISSE) Level 2

Synergy ECP • Maryland

On-site
USD 120,000 - 160,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Evans & Chambers Technology • Arlington (VA)

On-site
USD 100,000 - 130,000