Information System Security Engineer (ISSE)

Tier4 Group

Chambersburg (Franklin County)

Hybrid

USD 130,000 - 160,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Tier4 Group is seeking an Information System Security Engineer (ISSE) to serve as a customer-facing cybersecurity engineering consultant across DoD-inspired environments. The role requires RMF/NIST expertise, DoD policy interpretation, and strong risk-focused design capabilities, with hybrid onsite work in Chambersburg, PA or Fort Meade, MD.

As an ISSE you will guide engineering teams, translate requirements into actionable controls, and mentor staff while ensuring secure SDLC practices and

Qualifications

  • Bachelor's degree or equivalent professional experience.
  • 10+ years of related experience.
  • DoD 8140 Work Role 652 Security Architect Certification requirement.
  • Current DoD Top Secret clearance.
  • Must reside within commutable distance of Fort Meade, MD or Chambersburg, PA for hybrid onsite schedule.
  • Expert-level RMF/NIST SP 800-37 knowledge.
  • Expert-level NIST SP 800-53 controls knowledge.
  • Hands-on engineering/configuration with enterprise security technologies.

Responsibilities

  • Embed as security engineering expert for Mission Partners and system owners.
  • Provide security engineering support through SDLC including design reviews and modernization.
  • Translate RMF and DoD policy into actionable, threat-informed solutions.
  • Conduct security architecture and design reviews for new/existing systems.
  • Analyze architectures, cloud/native setups, apps, APIs, containers and data flows for weaknesses.
  • Collaborate with architects/developers to implement achievable controls and reduce friction.
  • Develop vulnerability mitigation strategies and support POA&M actions.
  • Create solutions to reduce attack surface without compromising mission.
  • Translate requirements into MFA, encryption, secure zoning and related controls.
  • Apply DoD STIGs, SRGs, PPSM to system engineering.
  • Use SIEM/vuln/EDR findings to drive improvements.
  • Mentor ISSMs, ISSOs, developers, and owners.
  • Present risks and mitigations to tech staff and leadership.
  • Document customer interactions and recommendations.

Skills

RMF expertise
Security architecture
Threat modeling
Leadership
Communication

Education

Bachelor's degree
DoD 8140 Certification

Tools

Splunk
Elastic
ACAS/Nessus
EDR

Job description

Maximum Conversion Salary: $130k-$160k
Position Location: Customer Site - Chambersburg, PA, Customer Site - Fort Meade, MD
Location Type (Remote, Hybrid, Onsite): Hybrid (4 days onsite)

The Information System Security Engineer (ISSE) serves as a dedicated, customer-facing cybersecurity engineering consultant supporting organizational ISSMs, ISSOs, Mission Partners, system owners, architects, and development teams. The ISSE provides expert security architecture and Risk Management Framework (RMF) guidance for on-premises, cloud-hosted, legacy, and modernizing systems throughout the System Development Lifecycle (SDLC). The ISSE helps customers understand cybersecurity requirements and develop actionable technical solutions that implement controls, remediate vulnerabilities, and improve system security before or following formal assessment.

Essential Duties and Responsibilities:
  • Serve as the embedded security engineering expert for Mission Partners, ISSMs, ISSOs, system owners, architects, and development teams.
  • Provide security engineering support throughout the SDLC, including requirements gathering, design reviews, sprint planning, modernization, implementation, and production.
  • Translate RMF, NIST SP 800-53, DoD cybersecurity policy, and other governance requirements into actionable, threat-informed engineering solutions.
  • Conduct in-depth security architecture and design reviews for new and existing systems.
  • Analyze network architectures, cloud-native architectures, applications, APIs, microservices, containers, serverless functions, interfaces, and data flows to identify security weaknesses.
  • Collaborate with architects and developers to identify achievable security controls and reduce compliance friction before formal assessment.
  • Engineer and document vulnerability mitigation strategies and provide technical consultation supporting POA&M corrective actions.
  • Develop solutions that reduce system attack surface and improve resiliency without unnecessarily compromising mission capability.
  • Translate security requirements into specific technical implementation activities such as MFA, database encryption, secure network zoning, and related controls.
  • Apply DoD STIGs, SRGs, and PPSM guidance to system engineering activities.
  • Use security telemetry and findings from SIEM, vulnerability scanning, and EDR technologies to recommend architectural and engineering improvements.
  • Provide technical mentorship and guidance to ISSMs, ISSOs, developers, and system owners.
  • Present cybersecurity risks, architectural findings, mitigation strategies, and recommendations to technical personnel and Government leadership.
  • Document customer interactions, systems supported, issues addressed, and technical recommendations as required.
Required Skills, Qualifications and Experience:
  • Bachelors degree or equivalent professional experience.
  • 10+ years of related experience.
  • DoD 8140 Work Role 652 Security Architect Certification requirement (must have at least one of the following): Security X/CASP+CE, CCSP, Cloud+, CISSP, CSSLP, CISM, CISSP-ISSAP, CISSP-ISSIP, CSSLP, and GSEC.
  • Must have and maintain a current DoD Top Secret clearance.
  • Must reside within a commutable distance of Fort Meade, MD or Chambersburg, PA in order to work a hybrid onsite schedule (4 days onsite weekly).
  • Expert-level knowledge of RMF and NIST SP 800-37.
  • Expert-level knowledge of NIST SP 800-53 security and privacy controls.
  • Strong security architecture and systems-security engineering experience.
  • Practical experience applying DoD STIGs, SRGs, and PPSM requirements.
  • Experience converting compliance requirements into practical engineering solutions.
  • Hands-on engineering/configuration experience with enterprise security technologies, including:

o SIEM platforms such as Splunk or Elastic.
o Vulnerability scanners such as ACAS/Nessus.
o Endpoint Detection and Response (EDR) technologies.
Knowledge of traditional and cloud-native architectures.
Ability to support multiple concurrent systems, projects, and development efforts.
Strong written, verbal, consulting, and presentation skills.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Systems Security Engineer (ISSE) Architect
Information Systems Security Engineer (ISSE) Architect

Saic • Newington (VA)

On-site
USD 80,000 - 120,000
Information System Security Engineer (ISSE)
Information System Security Engineer (ISSE)

Navstar Inc. • Maryland

On-site
USD 150,000 - 190,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

VTG Defense • Chantilly (VA)

On-site
USD 100,000 - 130,000
Information System Security Engineer (ISSE)
Information System Security Engineer (ISSE)

Peraton • Maryland

On-site
USD 120,000 - 180,000
Information Security System Engineer
Information Security System Engineer

Elevate Technology Group • Fairfax Station (VA)

On-site
USD 150,000 - 220,000
Employer-funded 401(k) contribution
Flexible benefits allowance
Medical, Dental & Vision coverage
+1
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Evans & Chambers Technology • Arlington (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Evans & Chambers • Arlington (VA)

On-site
USD 100,000 - 130,000
Information System Security Engineer (ISSE)
Information System Security Engineer (ISSE)

IDS International • Maryland

On-site
USD 90,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Cape Fox Shared Services • Reston (VA)

On-site
USD 190,000 - 220,000
Health insurance
Dental insurance
Vision insurance
+3
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Dobbs Defense Solutions • Landover (MD)

On-site
USD 120,000 - 170,000