Information System Security Engineer III

Centuria

Philadelphia (Philadelphia County)

On-site

USD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A Service-Disabled Veteran-Owned Small Business is seeking an Information System Security Engineer (ISSE) III in Philadelphia, PA. The ideal candidate has extensive experience with cybersecurity, risk management, and security compliance. Applicants should hold a bachelor's degree in a relevant field and have at least seven years of professional experience in information security. Relevant certifications are also required.

Qualifications

  • Bachelor's degree in computer science or equivalent STEM degree from an accredited institution.
  • Seven years of experience in information security and implementing security controls.
  • Certifications such as CASP+ CE, CCNP Security, CISA, or CISSP (or Associate).

Responsibilities

  • Develop and maintain RMF system security plans and assessment checklists.
  • Execute RMF process for obtaining and maintaining authority to operate.
  • Perform risk assessments and manage cybersecurity vulnerabilities.
  • Maintain system security policies and implement STIG compliance.
  • Support cyber compliance for assets within the IT network.

Skills

Information Security
Risk Management Framework (RMF)
Cybersecurity Compliance
Vulnerability Assessments
System Security Policies

Education

Bachelor’s degree in computer science or equivalent STEM degree

Tools

Assured Compliance Assessment Solution (ACAS)
Security Content Automation Protocol (SCAP)
Enterprise Mission Assurance Support Service (eMASS)

Job description

Job Title: Information System Security Engineer (ISSE) III
Location: Philadelphia, PA
Clearance: Secret
Company/ Program Description

Centuria, a Service-Disabled Veteran-Owned Small Business (SDVOSB), has been delivering IT, Engineering, and Scientific solutions to the Federal Government since 2002. During our two decades of service, we have earned the trust and respect of our government clients for the simple reason that we have great people who are experts in their fields and take pride and ownership in everything they do.

Job Responsibilities
  • Assist with the developing, maintaining, and tracking Risk Management Framework (RMF) system security plans, which include System Categorization Forms, Platform Information Technology (PIT) Determina Checklists, Assess Only (AO) Determination Checklists, Implementation Plans, System Level Continuous Monitoring (SLCM) Strategies, System Level Policies, Hardware Lists, Software List, System Diagram Privacy Impact Assessments (PIA), and Plans of Action and Milestones (POA&M).
  • Execute the RMF process in support of obtaining and maintaining Interim Authority to Test (IATT), AO approval, Authorization to Operate (ATO), and Denial of Authorization to Operate (DATO). Identify and tailor IT and Cyber Security (CS) control baselines based on RMF guidelines and categorization of the RMF boundary.
  • Perform Ports, Protocols, and Services Management (PPSM). Perform IT and CS vulnerability-level risk assessments.
  • Execute security control testing as required by a risk assessment or annual security review (ASR). Mitigate and remediate IT and CS system level vulnerabilities for all assets within the boundary per STIG requirements. Develop and maintain Plans of Actions and Milestones (POA&M) in Enterprise Mission Assurance Support Service (eMASS).
  • Develop and maintain system level IT and CS policies and procedures for respective RMF boundaries in accordance with guidance provided by the command ISSMs. Implement and assess STIG and SRGs.
  • Perform and develop vulnerability assessments with automated tools such as Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP) Compliance Check (SCC) and Ev STIG.
  • Deploy security updates to Information System components.
  • Perform routine audits of IT system hardware and software components. Maintain inventory of Information System components.
  • Participate in IT change control and configuration management processes.
  • Upload vulnerability data in Vulnerability Remediation Asset Manager (VRAM). Image or re-image assets that are part of the assigned RMF boundary.
  • Install software and troubleshoot software issues as necessary to support compliance of the RMF boundaries’ assets.
  • Assist with removal of Solid‑State Drive (SSD), Hard Disk Drive (HDD) or other critical components of assets before destruction and removal from the RMF boundary.
  • Provide cybersecurity patching of assets in response to DoD and DoN TASKORDs, FRAGORDs, or as required by Command ISSM, ACIO, and/or Code 104 management.
  • Support configuration change documentation and control processes and maintaining DOD STIG Compliance.
  • Support cyber compliance of assets that are part of an enterprise IT network to include Windows server and CISCO networking hardware. This includes assessing vulnerabilities, patching and meeting requirements the STIG for the hardware.
  • Report compliance issues of network hardware to management to avoid operational loss of the network.
Job Requirements
  • Education: Bachelor’s degree in computer science, information technology, or an equivalent STEM degree from an accredited college or university.
  • Experience: Seven (7) years professional experience capturing and refining information security operational and security requirements and ensuring those requirements are properly addressed through purposeful development, configuration, and implementing security controls, configuration changes, software/hardware updates/patches, vulnerability scanning, and securing configurations.
  • Minimum Certification Requirement: IAT‑III (CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH, CCSP)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Engineer (ISSE) III
Information System Security Engineer (ISSE) III

StratasCorp Technologies • Philadelphia

On-site
USD 90,000 - 120,000
Information Systems Security Engineer III
Information Systems Security Engineer III

ARMADA, Ltd. • Philadelphia

On-site
USD 90,000 - 110,000
Information System Security Engineer (ISSE) II - Hybrid
Information System Security Engineer (ISSE) II - Hybrid

Ishpi Information Technologies, Inc. (ISHPI) • Philadelphia

On-site
USD 70,000 - 100,000
Information System Security Engineer (ISSE) II (on-site)
Information System Security Engineer (ISSE) II (on-site)

Ishpi Information Technologies, Inc. (ISHPI) • Philadelphia

On-site
USD 90,000 - 120,000
Information Systems Security Engineer
Information Systems Security Engineer

VT Group (VTG) • Chantilly (VA)

On-site
USD 90,000 - 120,000
Information Systems Security Engineer (INFOSEC Engineer, ISSE)
Information Systems Security Engineer (INFOSEC Engineer, ISSE)

M2 Solutions Inc. • Herndon (VA)

On-site
USD 120,000 - 150,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Vosper Thornycroft Group • Chantilly (VA)

On-site
USD 90,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

VTG Defense • Chantilly (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

VT Group (VTG) • Chantilly (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (ISSE) Level 2
Information Systems Security Engineer (ISSE) Level 2

Synergy ECP • Maryland

On-site
USD 120,000 - 160,000