Information Systems Security Engineer

Jobtailor

Boston (MA)

On-site

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Merlin seeks a systems security engineer to apply security engineering methods across architecture, design, evaluation, and integration of defense programs, partnering with engineering teams to embed security requirements early rather than retrofitting them after development.

Responsibilities include supporting RMF accreditation and authorization activities—categorization, controls selection and implementation, security assessment, and body of evidence development—while engaging government

Qualifications

  • Bachelor's degree with 5 years of cybersecurity experience on DoD or government programs
  • Direct experience with RMF accreditation and authorization, including body of evidence package development and working with government ISSOs, SCAs, or authorizing official representatives through the authorization lifecycle
  • Hands-on experience applying DISA SRGs and STIGs and conducting vulnerability assessments with tools such as Tenable NESSUS, ACAS, or SCC
  • Active clearance. TS preferred.

Responsibilities

  • Apply systems security engineering methods across the architecture, design, evaluation, and integration of Merlin's defense programs and products, working alongside engineering teams to embed security requirements early rather than retrofitting them once a system is built.
  • Support RMF accreditation and authorization activities for supported programs, including categorization, controls selection and implementation, security assessment, and body of evidence package development through all required RMF steps.
  • Engage with government customers and their security representatives to define, document, and implement security protection requirements with the technical rigor and fidelity that DoD authorization demands.
  • Apply and verify DISA SRGs and STIGs across program environments, and maintain the configuration management processes that keep systems compliant as they evolve through their operational lifecycle.
  • Conduct vulnerability assessments using tools such as Tenable NESSUS and ACAS, coordinate remediation with engineering teams, and manage the ongoing security posture of supported systems.
  • Evaluate and advise on the selection of COTS, GOTS, and open-source tools entering the program environment, following DoD-approved software approval processes and ensuring security implications are understood before adoption.
  • Support DevSecOps security integration by bringing defense-grade practices into our CI/CD pipeline, including static application security testing and security-gated build processes for government-facing deliverables.

Skills

RMF Accreditation and Authorization
Vulnerability Assessment
DISA SRGs and STIGs
DevSecOps Security Integration
Active Security Clearance
Collaboration with Engineering Teams
Government Customer Engagement

Education

Bachelor's degree

Tools

Tenable NESSUS
ACAS
SCC

Job description

• Apply systems security engineering methods across the architecture, design, evaluation, and integration of Merlin's defense programs and products, working alongside engineering teams to embed security requirements early rather than retrofitting them once a system is built.
• Support RMF accreditation and authorization activities for supported programs, including categorization, controls selection and implementation, security assessment, and body of evidence package development through all required RMF steps.
• Engage with government customers and their security representatives to define, document, and implement security protection requirements with the technical rigor and fidelity that DoD authorization demands.
• Apply and verify DISA SRGs and STIGs across program environments, and maintain the configuration management processes that keep systems compliant as they evolve through their operational lifecycle.
• Conduct vulnerability assessments using tools such as Tenable NESSUS and ACAS, coordinate remediation with engineering teams, and manage the ongoing security posture of supported systems.
• Evaluate and advise on the selection of COTS, GOTS, and open-source tools entering the program environment, following DoD-approved software approval processes and ensuring security implications are understood before adoption.
• Support DevSecOps security integration by bringing defense-grade practices into our CI/CD pipeline, including static application security testing and security-gated build processes for government-facing deliverables.

Requirements

  • Bachelor's degree with 5 years of cybersecurity experience on DoD or government programs
  • Direct experience with RMF accreditation and authorization, including body of evidence package development and working with government ISSOs, SCAs, or authorizing official representatives through the authorization lifecycle
  • Hands-on experience applying DISA SRGs and STIGs and conducting vulnerability assessments with tools such as Tenable NESSUS, ACAS, or SCC
  • Active clearance. TS preferred.

Core Competencies

Demonstrates expertise in systems security engineering, RMF accreditation, and vulnerability assessments, with a strong focus on integrating security requirements early in the development lifecycle. Proficient in applying DISA SRGs and STIGs while maintaining compliance and security posture in DoD environments.

Highest-signal resume keywords

  • RMF Accreditation and Authorization
  • Vulnerability Assessment with Tenable NESSUS
  • DISA SRGs and STIGs Application
  • DevSecOps Security Integration
  • Active Security Clearance

ATS Optimization Keywords

Hard Skills

  • Cybersecurity Experience
  • Body of Evidence Package Development
  • Security Assessment
  • Configuration Management
  • Security Controls Selection
  • COTS and GOTS Evaluation
  • Static Application Security Testing
  • Security-Gated Build Processes

Soft Skills

  • Collaboration with Engineering Teams
  • Engagement with Government Customers

Industry Keywords

  • DoD Authorization
  • Security Protection Requirements
  • Operational Lifecycle Compliance
  • Defense Programs

Tools & Technologies

  • Tenable NESSUS
  • ACAS
  • SCC
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Manager – ISSM
Information System Security Manager – ISSM

Jobtailor • Ventura (CA)

On-site
USD 110,000 - 150,000
Advisory Information Security Manager – ISSM
Advisory Information Security Manager – ISSM

Jobtailor • Huntsville (AL)

On-site
USD 110,000 - 170,000
Information Systems Security Engineer
Information Systems Security Engineer

Jobtailor • King of Prussia (PA)

On-site
USD 120,000 - 170,000
Senior Information Systems Security Engineer – ISSE
Senior Information Systems Security Engineer – ISSE

Jobtailor • Maryland

On-site
USD 140,000 - 180,000
Senior Information Systems Security Officer
Senior Information Systems Security Officer

Jobtailor • Washington

On-site
USD 120,000 - 180,000
Information Assurance Engineer
Information Assurance Engineer

Agile IT Synergy, LLC • Tampa (FL)

On-site
USD 90,000 - 130,000
Cybersecurity Engineer, TS/SCI
Cybersecurity Engineer, TS/SCI

Jobtailor • Frederick (MD)

On-site
USD 120,000 - 160,000
Cloud-Native Security Engineer – RMF & DevSecOps
Cloud-Native Security Engineer – RMF & DevSecOps

Jobtailor • Colorado

On-site
USD 120,000 - 170,000
Systems Security Engineer
Systems Security Engineer

Modern Technology Solutions, Inc. (MTSI) • Bath Township (OH)

On-site
USD 120,000 - 180,000
Information Assurance / Security Specialist
Information Assurance / Security Specialist

Diverse Systems Group, LLC • Bethesda (MD)

On-site
USD 110,000 - 150,000