Information Systems Security Engineer - Entry to Mid Level

Cybersecurity Jobs

Fort Meade (MD)

On-site

USD 87,000 - 153,000

Full time

11 days ago
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

NSA seeks Information Systems Security Professionals for an onsite role in Fort Meade, MD. You will design and operate secure IT systems supporting SIGINT and cybersecurity missions, applying RMF and NIST standards in hybrid/cloud environments.

Responsibilities include vulnerability remediation, system hardening, and continuous monitoring. The position requires security clearances and extensive experience in cyber defense, architectures, and risk management.

Qualifications

  • Experience in computer or information systems design/development or cybersecurity fields.
  • The role requires knowledge of DoD-style security documentation such as SSPs and risk assessment reports.
  • Entry/Developmental: Associate’s degree + 2 years of relevant experience, or a Bachelor’s degree with no experience.
  • Full Performance: advanced degrees with years of relevant experience; higher education is valued.
  • A degree in Computer Science or related field is required.
  • Commitment to public service and upholding the Constitution is expected.

Responsibilities

  • Design system and network architectures to enforce confidentiality, integrity, and availability.
  • Apply systems engineering principles and methodology.
  • Define and manage remediation plans across applications, infrastructure, and cloud environments.
  • Ensure compliance with cybersecurity standards and regulatory requirements (e.g., NIST).
  • Assess and mitigate risks in legacy systems, misconfigurations, and vulnerabilities.
  • Lead and provide oversight for patching and hardening of infrastructure systems.
  • Define information system security requirements and functionality.
  • Review cloud service security configurations and recommend secure options.
  • Use cryptography knowledge and programming capability (Python and Java).
  • Assess the effectiveness of security solutions against frameworks such as MITRE ATT&CK.
  • Monitor cybersecurity hygiene and direct remediation of findings to reduce risk.
  • Apply concepts to design, implement, monitor, and secure OS, networks, apps, and controls.
  • Operate within teams implementing security settings for cloud environments.
  • Hardening of latest OS for mission needs.
  • Implement automation and AI across RMF lifecycle into continuous monitoring.

Skills

Python
Java
cryptography
risk assessment
security engineering
cloud security
secure coding
vulnerability analysis
automation
AI

Education

Associate’s degree + 2 years experience or Bachelor’s degree with no experience
Bachelor’s degree with relevant field or higher
Master’s degree + 1 year of experience
Doctoral degree with no experience

Tools

Docker
Kubernetes
AWS
Azure
Oracle
Google Cloud
CI/CD pipelines

Job description

At the U.S. National Security Agency/Central Security Service (NSA), Information Systems Security Professionals help architect, design, operate, defend, and maintain secure IT systems that support NSA SIGINT and Cybersecurity missions. This onsite role at Fort Meade, Maryland applies full life-cycle security engineering to manage risk, remediate vulnerabilities, and maintain compliance with relevant standards.

Working within security engineering teams, you will contribute to securing hybrid environments, including cloud services, while supporting authorization and continuous monitoring activities. The position is a permanent, full-time appointment in the Excepted Service, with eligibility for benefits based on the type of appointment.

Responsibilities
  • Design system and network architectures to enforce confidentiality, integrity, and availability.
  • Apply systems engineering principles and methodology.
  • Define and manage remediation plans across applications, infrastructure, and cloud environments.
  • Ensure compliance with cybersecurity standards and regulatory requirements (for example NIST).
  • Assess and mitigate risks in legacy systems, misconfigurations, and vulnerabilities.
  • Analyze and prioritize vulnerabilities in collaboration with cross-functional teams.
  • Lead and provide oversight for patching and hardening of infrastructure systems.
  • Define information system security requirements and functionality.
  • Review cloud service security configuration options and recommend secure configurations.
  • Use knowledge of cryptography and programming capability (including Python and Java).
  • Assess the effectiveness of security solutions against cybersecurity frameworks such as MITRE ATT&CK.
  • Monitor cybersecurity hygiene for a family of IT systems and direct remediation of configuration and vulnerability findings to reduce adversary risk.
  • Apply concepts, principles, structure, and standards to design, implement, monitor, and secure operating systems, equipment, networks, applications, and controls.
  • Operate within teams implementing and evolving procedures and security settings for protecting data and applications in cloud environments.
  • Conduct security engineering and hardening of the latest operating systems, tailoring them for specific mission needs.
  • Implement automation and artificial intelligence across the RMF authorization life cycle into continuous monitoring.
Requirements
  • All applicants and employees are subject to random drug testing in accordance with Executive Order 12564.
  • Relevant experience must be in one or more areas such as computer or information systems design/development; programming; information/cyber/network security; system or network administration; vulnerability analysis; penetration testing; computer forensics; systems engineering; computer systems research; reverse engineering; or updating information assurance documentation (for example System Security Plans, Risk Assessment Reports, Certification and Accreditation packages, and System R…).
  • Completion of military training in relevant areas (such as JCAC, UCT, NWBC/INWT, or Cyber Defense Operations) may count toward the relevant experience requirement, based on course duration.
  • Cybersecurity certifications (for example NET+, Security+, CISSP, and CAP) may count as a total of 1 year of experience.
  • Entry/Developmental: Associate’s degree plus 2 years of relevant experience, or a Bachelor’s degree with no experience.
  • Full Performance: Associate’s degree plus 5 years of relevant experience; Bachelor’s degree plus 3 years of relevant experience; Master’s degree plus 1 year of relevant experience; or Doctoral degree with no experience.
  • Degree must be in Computer Science or a related field (examples include Engineering, Mathematics, Data Science, Artificial Intelligence, Computer Forensics, Cybersecurity, Information Technology, Information Assurance, Information Security, Information Systems, Informatics, Cyber Operations, and Cyber Defense).
  • Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of the American republic, and committed to upholding the rule of law and the U.S. Constitution.
Technologies
  • Commercial cloud fabrics, artificial intelligence, and high performance computing
  • Advanced cryptographic systems
  • Python, Java
  • NIST, MITRE ATT&CK, RMF authorization life cycle
  • Amazon Web Services, Microsoft Azure, Oracle, and Google cloud environments
  • NET+, Security+, CISSP, CAP
  • NIST 800-53, ISO 27001, CI/CD pipelines, DevSecOps
  • Container security, Kubernetes, Docker
Evaluation and Selection
  • Understanding of security frameworks (for example NIST 800-53, ISO 27001, and CIS)
  • Ability to prioritize and remediate vulnerabilities across hybrid network environments
  • Cloud security knowledge across AWS, Microsoft Azure, Oracle, and Google cloud environments
  • Familiarity with secure coding, DevSecOps, and CI/CD pipelines
  • Capability to translate complex security issues into actionable guidance
  • Understanding of vulnerability scanning tools
  • Understanding of container security, including Kubernetes, Docker, and container hardening practices
  • Understanding of threat modeling and mitigation design strategies
  • Critical thinking and problem decomposition skills
How the Role Is Structured
  • Location: Fort Meade, MD (onsite)
  • Telework: No; Remote: No
  • Relocation expenses reimbursed: Yes (in accordance with agency policy)
  • Salary: $87,362 - $153,082 per year
  • Pay scale & grade: GG 7 - 12; Work schedule: Full-time
  • Travel: Occasional
  • Appointment type: Permanent
  • Occupations and job series: 0132 Intelligence; Supervisory status: No
  • Federal service type: Excepted Service
  • Drug test: Yes
  • Security clearance: Top Secret
  • Position sensitivity and risk: Critical-Sensitive (CS)/High Risk
  • Background check type: National security
  • Financial disclosure required: Yes
Open To
  • The public: U.S. Citizens, Nationals, or those who owe allegiance to the U.S.
  • Federal employees in the Excepted Service: current federal employees whose agencies have their own hiring rules, pay scales, and evaluation criteria
  • Veterans, and eligible spouses, widows, widowers, or parents of veterans for derived preference
  • Military spouses
  • Individuals with disabilities eligible under Schedule A
Required Documents
  • NSA positions are part of the DoD Intelligence Community Defense Civilian Intelligence Personnel System (DCIPS).
  • All NSA positions are in the Excepted Services under 10 U.S.C. 1601 appointment authority.
  • Veterans' Preference may apply to eligible candidates for DoD Components with DCIPS positions, as defined by Section 2108 of Title 5 U.S.C., following DoD Instruction 1400.25, Volume 2005.
  • If claiming veterans' preference, you may be asked to submit documents verifying eligibility.
  • If relying on education to meet qualification requirements, the education must be accredited by an accrediting institution recognized by the U.S. Department of Education.
  • Failure to provide all required information as stated in the vacancy announcement may result in an ineligible rating or may affect the overall rating.
Agency Contact
  • Phone: 1-844-424-4737
  • Email: intelcareers@nsa.gov
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Software Engineer
Software Engineer

National Security Agency • Fort Meade (MD)

On-site
USD 105,000 - 193,000
Computer Systems Architect
Computer Systems Architect

Intelligence Careers • Fort Meade (MD)

On-site
USD 105,000 - 193,000
Engineering and Physical Sciences Researcher
Engineering and Physical Sciences Researcher

Intelligence Careers • Northern (KY)

Hybrid
USD 133,000 - 197,000
Software Engineer - Mid to Experienced Level (MD, TX)
Software Engineer - Mid to Experienced Level (MD, TX)

National Security Agency • Fort Meade (MD)

On-site
USD 120,000 - 193,000
Engineer/Developer - Software, Hardware, Research (Capabilities Development Specialist) - Mid to Experienced Level (MD, TX, CO)
Engineer/Developer - Software, Hardware, Research (Capabilities Development Specialist) - Mid to Experienced Level (MD, TX, CO)

National Security Agency • Fort Meade (MD)

On-site
USD 105,000 - 193,000
Target Systems Analyst
Target Systems Analyst

Intelligence Careers • Fort Meade (MD)

On-site
USD 105,000 - 193,000
Benefits package
DCIPS trial period
Flexible work schedule
Digital Network Exploitation Analyst - Mid Level (Maryland)
Digital Network Exploitation Analyst - Mid Level (Maryland)

National Security Agency • Fort Meade (MD)

On-site
USD 105,000 - 153,000
Forensic Analyst
Forensic Analyst

Intelligence Careers • Fort Meade (MD)

On-site
USD 87,000 - 153,000
Comprehensive benefits package
Cryptanalysis Development Program (CADP)
Cryptanalysis Development Program (CADP)

Intelligence Careers • Fort Meade (MD)

On-site
USD 87,000 - 173,000
Comprehensive benefits package
Engineer/Developer - Software, Hardware, Research (Capabilities Development Specialist)
Engineer/Developer - Software, Hardware, Research (Capabilities Development Specialist)

National Security Agency • Fort Meade (MD)

On-site
USD 105,000 - 193,000
Comprehensive benefits