Information System Security Engineer

ANALYGENCE

San Antonio (TX)

On-site

USD 100,000 - 140,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Tharros is seeking an experienced Information System Security Engineer to support cybersecurity, RMF, and ATO activities for DoD/federal information systems. The ISSE will work with ISSOs, system owners, security teams, engineers, and government stakeholders to prepare, manage, and submit security documentation throughout the RMF/ATO lifecycle.

The ideal candidate is a hands-on cybersecurity professional who can own RMF/ATO activities, develop and maintain an authorization package, work

Qualifications

  • Active TS/SCI clearance required.
  • DoD IAT Level II certification (e.g., Security+ or equivalent) required.
  • Hands-on ISSE/security engineering experience with RMF/ATO lifecycle.
  • Experience with eMASS and RMF artifact development.
  • Knowledge of NIST SP 800-53 controls and DISA STIGs/SRGs.

Responsibilities

  • Support RMF activities and Risk Management Framework implementation.
  • Prepare, coordinate, and support ATO packages and submissions.
  • Develop and maintain SSPs, SARs, POA&Ms, and supporting artifacts.
  • Manage security artifacts in eMASS and coordinate with ISSOs/ISSMs, owners and engineers.
  • Track security findings, vulnerabilities, and POA&Ms through resolution.
  • Provide cybersecurity guidance to engineering and project teams.

Job description

Tharros is seeking an experience Information System Security Engineer to support cybersecurity, Risk Management Framework (RMF), and Authority to Operate (ATO) activities for DoD/federal information systems.

The ISSE will work closely with ISSOs, ISSMs, system owners, security teams, engineers, and government stakeholders to prepare, manage, and submit security documentation and support systems throughout the RMF/ATO lifecycle. The ideal candidate is a hands-on cybersecurity professional who can take ownership of RMF and ATO activities, develop and maintain a complete authorization package, work effectively in eMASS, coordinate with ISSOs/ISSMs and engineering teams, and drive security findings toward resolution.

  • Support the implementation and execution of the NIST Risk Management Framework (RMF).
  • Develop, review, and maintain RMF security documentation and artifacts.
  • Prepare, coordinate, and support Authority to Operate (ATO) packages and submissions.
  • Work within eMASS to create, update, and maintain system security artifacts.
  • Support security control implementation, assessment, validation, and remediation activities.
  • Develop and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and supporting documentation.
  • Collect and maintain security control implementation evidence.
  • Coordinate with ISSOs, ISSMs, system owners, security control assessors, engineers, and government stakeholders.
  • Track security findings, vulnerabilities, and POA&Ms items through resolution.
  • Support DISA STIG/SRG compliance and vulnerability remediation activities.
  • Participate in RMF reviews, security assessments, authorization activities, and ATO decision processes.
  • Ensure security documentation and system security artifacts remain accurate, current, and audit-ready.
  • Provide cybersecurity and RMF guidance to engineering and project teams.
  • Active TS/SCI security clearance required.
  • DoD IAT Level II certification required, such as Security+ or another DoD-approved IAT Level II baseline certification.
  • Demonstrated experience as an ISSE, Security Engineer, ISSO, or similar cybersecurity professional.
  • Hands-on experience with the NIST RMF and ATO lifecycle.
  • Experience preparing and supporting ATO submissions.
  • Hands-on experience with eMASS.
  • Working knowledge of NIST SP 800-53 security controls.
  • Experience developing and maintaining SSPs, SARs, POA&Ms, security control evidence, and other RMF artifacts.
  • Experience with DISA STIGs/SRGs and vulnerability management.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

RMF & ATO Security Engineer - TS/SCI
RMF & ATO Security Engineer - TS/SCI

ANALYGENCE • San Antonio (TX)

On-site
USD 100,000 - 140,000
Junior Information System Security Officer
Junior Information System Security Officer

ANALYGENCE • Washington

On-site
USD 70,000 - 100,000
Information System Security Officer
Information System Security Officer

ANALYGENCE • Washington

On-site
USD 140,000 - 190,000
Senior Information Systems Security Engineer (ISSE)
Senior Information Systems Security Engineer (ISSE)

Smart Synergies • Fort Belvoir (VA)

On-site
USD 120,000 - 160,000
ISSE II – DoD RMF Security Engineer
ISSE II – DoD RMF Security Engineer

Warrant Technologies, LLC • Bloomington (IN)

On-site
USD 110,000 - 150,000
Security Control Assessor
Security Control Assessor

ANALYGENCE • Washington

On-site
USD 120,000 - 180,000
Junior Security Control Assessor
Junior Security Control Assessor

ANALYGENCE • Washington

On-site
USD 65,000 - 90,000
Information Systems Security Manager - Basic (ISSM-Basic)
Information Systems Security Manager - Basic (ISSM-Basic)

ACQCENTRIC INC • Huntsville (AL)

On-site
USD 90,000 - 140,000
Information System Security Engineer (ISSE) 5613
Information System Security Engineer (ISSE) 5613

Tier4 Group • Chambersburg

Hybrid
USD 140,000 - 190,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

VTG Defense • Chantilly (VA)

On-site
USD 100,000 - 130,000