Information System Security Engineer (ISSE) II (on-site)

Ishpi Information Technologies, Inc. (ISHPI)

Philadelphia (Philadelphia County)

On-site

USD 90,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Ishpi Information Technologies, Inc. (DBA ISHPI) is seeking a cybersecurity professional to lead RMF activities, vulnerability management, and compliance for government and enterprise environments.

The role covers A&A, STIG/SRG implementation, IATT/ATO support, and ongoing risk assessments to ensure secure operations and regulatory adherence across assets within the RMF boundary.

Qualifications

  • Bachelor’s degree in Computer science, Information Technology, or an equivalent technical degree from an accredited college or university.
  • Three (3) years professional information security experience capturing and refining operational requirements and implementing security controls.
  • Certifications: CCNA‑Security, CySA+, GICSP, GSEC or Security+ CE.
  • U.S. Citizenship and an active government security clearance required.

Responsibilities

  • Assessment & Authorization (A&A) activities across RMF boundaries.
  • Cybersecurity compliance and audit readiness for DoD/DoN environments.
  • Information Assurance Vulnerability Management (IAVM) and vulnerability remediation.
  • STIGs/SRGs implementation and security control testing.
  • Develop and maintain Plans of Actions and Milestones (POA&M) and RMF documentation.
  • Execute RMF process to obtain and maintain IATT, AO, and ATO.
  • Deploy cyber patches and manage asset configurations within STIG baselines.
  • Use ACAS, SCAP, and related tools to perform vulnerability assessments.

Skills

A&A
RMF
Vulnerability scanning
STIGs SRGs
eMASS
ACAS

Education

Bachelor’s degree in Computer science, Information Technology, or an equivalent technical degree

Tools

ACAS
SCAP
eMASS
PPSM

Job description

Ishpi Information Technologies, Inc. (DBA ISHPI) is passionate about providing our customers with technical solutions that satisfy their business needs. Through collaborative interactions with customers, team members, subject matter experts (SMEs), technical leaders, and partners we design practical solutions that solve real problems for major government and business organizations. As a member of our group, you will work with a team focused on delivering innovative business solutions using emerging technologies through proven successful methods.

Responsibilities
  • Assessment & Authorization (A&A)
  • Cybersecurity Compliance and Audit Readiness
  • Information Assurance Vulnerability Management (IAVM)
  • Vulnerability Scanning and Remediation
  • Application and Implementation of Security Technical Implementation Guides (STIGs) and Security Requirements Guide (SRGs)
  • Assist with the developing, maintaining, and tracking Risk Management Framework (RMF) system security plans which include System Categorization Forms, Platform Information Technology (PIT) Determination Checklists, Assess Only (AO) Determination Checklists, Implementation Plans, System Level Continuous Monitoring (SLCM) Strategies, System Level Policies, Hardware Lists, Software List, System Diagrams, Privacy Impact Assessments (PIA), and Plans of Action and Milestones (POA&M).
  • Execute the RMF process in support of obtaining and maintaining Interim Authority to Test (IATT), AO approval, Authorization to Operate (ATO), and Denial of Authorization to Operate (DATO).
  • Identify and tailor IT and CS security control baselines based on RMF guidelines and categorization of the RMF boundary.
  • Perform Ports, Protocols, and Services Management (PPSM).
  • Perform IT and CS vulnerability-level risk assessments.
  • Execute security control testing as required by a risk assessment or annual security review (ASR).
  • Mitigate and remediate IT and CS system level vulnerabilities for all assets within the boundary per STIG requirements.
  • Develop and maintain Plans of Actions and Milestones (POA&M) in Enterprise Mission Assurance Support Service (eMASS).
  • Develop and maintain system level IT and CS policies and procedures for respective RMF boundaries and/or guidance provided by the command ISSMs.
  • Implement and assess STIG and SRGs.
  • Perform and develop vulnerability assessments with automated tools such as Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP) Compliance Check (SCC) and Evaluate STIG.
  • Deploy security updates to Information System components.
  • Perform routine audits of IT system hardware and software components.
  • Maintain inventory of Information System components.
  • Participate in IT change control and configuration management processes.
  • Upload vulnerability data in Vulnerability Remediation Asset Manager (VRAM).
  • Image or re-image assets that are part of the assigned RMF boundary.
  • Install software and troubleshoot software issues as necessary to support compliance of the RMF boundaries’ assets.
  • Assist with removal of SSD, HDD or other critical components of assets before destruction and removal from the RMF boundary.
  • Provide cybersecurity patching of assets in times of DoD and DoN TASKORDs, FRAGORDs, or even designated by Command ISSM, ACIO, and/or Code 104 management.
  • Support configuration change documentation and control processes and maintaining DOD STIG Compliance.
  • Support cyber compliance of assets that are part of an enterprise IT network including Windows servers and CISCO networking hardware. This includes assessing vulnerabilities, patching, and meeting requirements of the STIG for the hardware.
  • Report compliance issues of network hardware to management so they do not cause an operational impact of the network.
Education

Bachelor’s degree in Computer science, Information Technology, or an equivalent technical degree from an accredited college or university.

Experience

Three (3) years professional experience capturing and refining information security operational and security requirements, and ensuring those requirements are properly addressed through purposeful architecting, design, development, and configuration; and implementing security controls, configuration changes, software/hardware updates/patches, vulnerability scanning, and securing configurations.

Minimum Certification Requirement
  • CCNA‑Security
  • CySA+
  • GICSP
  • GSEC or Security+ CE
Security Clearance

Requires U.S. Citizenship and an active government security clearance.

Equal Opportunity Employer

Ishpi Information Technologies, Inc. is an Equal Opportunity Employer. All qualified candidates will be considered without regard to legally protected characteristics.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Engineer (ISSE) II - Hybrid
Information System Security Engineer (ISSE) II - Hybrid

Ishpi Information Technologies, Inc. (ISHPI) • Philadelphia

On-site
USD 70,000 - 100,000
Information System Security Engineer (ISSE) III
Information System Security Engineer (ISSE) III

StratasCorp Technologies • Philadelphia

On-site
USD 90,000 - 120,000
Information System Security Engineer III
Information System Security Engineer III

Centuria • Philadelphia

On-site
USD 90,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Vosper Thornycroft Group • Chantilly (VA)

On-site
USD 90,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

VT Group (VTG) • Chantilly (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (INFOSEC Engineer, ISSE)
Information Systems Security Engineer (INFOSEC Engineer, ISSE)

M2 Solutions • Herndon (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Evans & Chambers • Arlington (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer II
Information Systems Security Engineer II

ARMADA, Ltd. • Philadelphia

On-site
USD 80,000 - 100,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

VTG Defense • Chantilly (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Modern Technology Solutions, Inc. (MTSI) • Washington

On-site
USD 120,000 - 150,000