Information System Security Engineer II

Socket.dev

Bloomington (IN)

On-site

USD 90,000 - 120,000

Full time

9 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

TRISTAR is seeking an Information System Security Engineer II to provide mid-level cybersecurity and systems security engineering in DoD contexts. You will develop RMF documentation, assess controls, and ensure compliance across the system lifecycle.

You will liaise with software, systems and ISSM teams to translate requirements into practical engineering solutions, supporting secure architectures and defense-in-depth implementations.

Qualifications

  • Experience supporting RMF activities and DoD security authorization.
  • Experience with RMF artifacts in eMASS or similar repositories.
  • Proficient in vulnerability assessments and remediation.
  • Understanding of DISA STIGs and SRGs.
  • U.S. citizenship and ability to obtain security clearance.
  • DoD 8570/8140 IASAE II or equivalent.

Responsibilities

  • Develop, update, maintain, and submit RMF security packages (eMASS).
  • Support RMF lifecycle activities: categorization, control implementation, assessment, authorization, monitoring.
  • Create and maintain System Security Plans, SARs, POA&Ms and related artifacts.
  • Conduct control assessments and remediate deficiencies.
  • Implement continuous monitoring strategies for compliance.
  • Analyze vulnerability scanning results and translate to remediation actions.
  • Apply STIGs/SRGs to OS, apps, DBs, networks, containers.

Skills

RMF
Vulnerability assessment
DoD cybersecurity
Security controls
Technical liaison
Windows/Linux security
Communication skills
CompTIA Security+

Education

Bachelor's degree in Computer Science/Info Assurance/Cybersecurity/Systems Engineering

Tools

eMASS
Xacta
ACAS/Nessus
HBSS/ESS
SIEM
IDS/IPS

Job description

Description

We are seeking a skilled Information System Security Engineer II to join our dynamic team. The Information System Security Engineer (ISSE) II provides mid-level cybersecurity and systems security engineering support for Department of Defense (DoD) systems throughout the system development, integration, testing, deployment, and sustainment lifecycle. The ISSE is responsible for implementing secure system architectures and configurations, developing and maintaining Risk Management Framework (RMF) documentation, assessing security controls, identifying and remediating cybersecurity vulnerabilities, and ensuring systems remain compliant with applicable DoD cybersecurity requirements.

The ISSE II serves as a technical liaison between software development, systems engineering, network administration, cybersecurity, and Information System Security Manager (ISSM) personnel. The position requires the ability to translate cybersecurity requirements into practical engineering solutions and work collaboratively with technical teams to resolve security and compliance deficiencies.

Key Responsibilities
  • Develop, update, maintain, and submit RMF security authorization packages within government repositories and tools, including eMASS.
  • Support systems throughout the RMF lifecycle, including categorization, security control implementation, assessment, authorization, and continuous monitoring.
  • Develop and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and other required cybersecurity artifacts.
  • Conduct security control assessments and assist in identifying, documenting, tracking, and remediating security deficiencies.
  • Develop and maintain continuous monitoring strategies to ensure systems remain compliant with established cybersecurity requirements.
  • Perform automated and manual vulnerability assessments using tools such as ACAS/Nessus, SCAP, and other approved vulnerability and compliance assessment tools.
  • Analyze vulnerability scan results and translate findings into actionable remediation requirements.
  • Apply DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) to operating systems, applications, databases, network infrastructure, containers, and other system components as applicable.
  • Troubleshoot and resolve cybersecurity compliance gaps, vulnerabilities, and configuration deficiencies.
  • Support the development and implementation of secure system architectures, security configurations, access controls, boundary protections, and defense-in-depth solutions.
  • Assist with the implementation and integration of security technologies, including ACAS, HBSS/ESS, Security Information and Event Management (SIEM) platforms, intrusion detection/prevention systems (IDS/IPS), firewalls, endpoint security tools, and other cybersecurity capabilities.
  • Serve as a technical liaison between software development and systems engineering teams and the ISSM, ensuring cybersecurity requirements are incorporated throughout the system lifecycle.
  • Participate in engineering change boards, configuration control boards, and technical reviews to evaluate proposed changes for potential cybersecurity impacts.
  • Review system designs, configurations, interfaces, and proposed modifications to ensure changes do not negatively impact the system's security posture or authorization boundary.
  • Provide cybersecurity engineering support during system integration, testing, deployment, and sustainment activities.
  • Analyze security logs and system data to identify anomalous activity, potential vulnerabilities, and indicators of compromise.
  • Provide technical support during cybersecurity incidents, investigations, and forensic activities as required.
  • Assist with security-related troubleshooting and root-cause analysis of system and network issues.
  • Coordinate with system administrators, network engineers, software developers, and other technical personnel to implement and verify security requirements.
  • Maintain technical documentation related to system security configurations, vulnerabilities, assessments, remediation activities, and security controls.
  • Monitor changes to applicable DoD cybersecurity policies, standards, and technical guidance and assist in incorporating new requirements into supported systems.
  • Provide technical recommendations to engineering and cybersecurity leadership regarding system security risks, vulnerabilities, and remediation strategies.
  • Support audits, inspections, assessments, and other cybersecurity compliance activities as required.
  • Perform other cybersecurity engineering and systems security support duties as assigned.

Requirements

  • 5–9 years of professional experience in cybersecurity engineering, systems engineering, network administration, information assurance, or a related technical discipline.
  • Experience supporting DoD Risk Management Framework (RMF) activities and security authorization processes.
  • Experience developing or maintaining RMF documentation and artifacts within eMASS or comparable government cybersecurity repositories.
  • Experience performing vulnerability assessments using ACAS/Nessus, SCAP, or similar cybersecurity assessment tools.
  • Working knowledge of DISA STIGs, SRGs, security controls, vulnerability remediation, and cybersecurity compliance requirements.
  • Experience with security configuration, hardening, and assessment of Windows, Linux, network, application, database, or other enterprise systems.
  • Understanding of system security engineering principles, secure configurations, defense-in-depth, access control, and network boundary protection.
  • Ability to analyze technical security findings and develop practical remediation solutions.
  • Strong written and verbal communication skills, with the ability to communicate technical cybersecurity requirements to both engineering and non-engineering personnel.
  • Ability to work independently while coordinating effectively with government customers, ISSMs, system administrators, software developers, engineers, and other stakeholders.
  • DoD 8570/8140 IASAE Level II or equivalent qualification.
  • Experience supporting systems through the full RMF lifecycle from system development through authorization and sustainment.
  • Experience with eMASS, Xacta, or other RMF/GRC platforms.
  • Experience with ACAS/Nessus, SCAP Compliance Checker, HBSS/ESS, SIEM, IDS/IPS, endpoint security, and vulnerability management platforms.
  • Experience applying DISA STIGs to Windows Server, RHEL/Linux, databases, applications, containers, network devices, and virtualized environments.
  • Experience supporting cybersecurity incident response, security investigations, or digital forensics.
  • Knowledge of DoD cybersecurity policies, including applicable DoD Instructions, DISA guidance, NIST publications, and RMF security control frameworks.
  • Bachelor's degree in Computer Science, Information Assurance, Cybersecurity, Systems Engineering, Information Technology, or a related technical field. Equivalent relevant professional experience may be considered in lieu of the degree on a case-by-case basis.
  • Must have or be able to obtain and present a CompTIA Security Plus certification prior to start date.
  • Ability to obtain and maintain a security clearance.
  • Must be a U.S. Citizen.
About TRISTAR

TRISTAR is an SBA certified Service-Disabled Veteran-Owned professional services company supporting the U.S. Department of Defense programs. Our core competencies include Electronic Warfare, Enterprise Management, Full Spectrum Cybersecurity, Information Technology, Digital Transformation, Software Engineering and Development, Maritime Modernization and Engineering, and Technical Solutions.

TRISTAR was founded in March 1995 and has built an employee-focused collaborative environment which enables our team of professionals to create and deliver customized solutions to meet our customers’ mission critical challenges. TRISTAR’s core capabilities support customers with end-to-end solutions.

For over 30 years, TRISTAR has demonstrated and perfected our ability to successfully manage any task, small or large no matter how difficult or complex.

TRISTAR is proud to serve the Department of Defense and other Federal Agencies.

TRISTAR provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Engineer II
Information System Security Engineer II

TRISTAR INC • Bloomington (IN)

On-site
USD 85,000 - 125,000
Information System Security Engineer II
Information System Security Engineer II

Tri Star Engineering, Inc. • Bloomington (IN)

On-site
USD 90,000 - 140,000
Information System Security Engineer II
Information System Security Engineer II

TRISTAR • Bloomington (IN)

On-site
USD 110,000 - 150,000
Information System Security Engineer III
Information System Security Engineer III

Socket.dev • Bloomington (IN)

On-site
USD 120,000 - 180,000
Information System Security Engineer III
Information System Security Engineer III

TRISTAR INC • Bloomington (IN)

On-site
USD 140,000 - 190,000
Information System Security Engineer III
Information System Security Engineer III

Tri Star Engineering, Inc. • Bloomington (IN)

On-site
USD 135,000 - 180,000
Information System Security Engineer III
Information System Security Engineer III

TRISTAR • Bloomington (IN)

On-site
USD 120,000 - 180,000
Information Systems Security Specialist III
Information Systems Security Specialist III

Star3 • Indiana (PA)

On-site
USD 100,000 - 150,000
Software Integration Engineer
Software Integration Engineer

TRISTAR INC • Bloomington (IN)

On-site
USD 90,000 - 130,000
Software Integration Engineer
Software Integration Engineer

Tri Star Engineering, Inc. • Bloomington (IN)

On-site
USD 90,000 - 135,000