Information Systems Security Engineer III

ARMADA, Ltd.

Philadelphia (Philadelphia County)

On-site

USD 90,000 - 110,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ARMADA, Ltd. is seeking a dedicated Information Systems Security Engineer III in Philadelphia, PA, responsible for developing and maintaining Risk Management Framework (RMF) security plans. This full-time role requires collaboration with teams to ensure compliance and perform risk assessments. The ideal candidate will have over seven years of experience and relevant certifications.

We offer a competitive salary, benefits, and a supportive work environment. Candidates must pass background checks and pre-employment drug testing.

Qualifications

  • 7 years of experience in information security operations and security requirements.
  • IAT Level III certification (CASP+ CE, CCNP Security, CISA, CISSP, GCED, GCIH, CCSP) is required.

Responsibilities

  • Develop and maintain RMF system security plans.
  • Perform vulnerability assessments and security testing.
  • Ensure compliance with STIG and configuration management.

Skills

Teamwork
Communication
Customer focus
Information assurance guidance

Education

Bachelor's degree in computer science, information technology, or equivalent

Tools

Assured Compliance Assessment Solution (ACAS)
Security Content Automation Protocol (SCAP)
STIG compliance tools

Job description

Type: Full Time

Location: Philadelphia, PA (Travel - CONUS locations, less than 5%)

Overtime Exempt: Yes

Reports To: ARMADA HQ

Security Clearance Required: Active Secret

CONTINGENT UPON AWARD***************

Duties & Responsibilities
  • The Information Systems Security Engineer III (ISSE III) shall assist with the developing, maintaining, and tracking Risk Management Framework (RMF) system security plans which include System Categorization Forms, Platform Information Technology (PIT) Determination Checklists, Assess Only (AO) Determination Checklists, Implementation Plans, System Level Continuous Monitoring (SLCM) Strategies, System Level Policies, Hardware Lists, Software List, System Diagrams, Privacy Impact Assessments (PIA), and Plans of Action and Milestones (POA&M).
  • The Information Systems Security Engineer III shall execute the RMF process in support of obtaining and maintaining Interim Authority to Test (IATT), AO approval, Authorization to Operate (ATO), and Denial of Authorization to Operate (DATO).
  • The Information Systems Security Engineer III shall identify and tailor IT and CS security control baselines based on RMF guidelines and categorization of the RMF boundary.
  • The ISSE III shall perform Ports, Protocols, and Services Management (PPSM).
  • The ISSE III shall perform IT and CS vulnerability-level risk assessments.
  • The ISSE III shall execute security control testing as required by a risk assessment or annual security review (ASR).
  • The ISSE III shall mitigate and remediate IT and CS system level vulnerabilities for all assets withing the boundary per STIG requirements.
  • The ISSE III shall develop and maintain Plans of Actions and Milestones (POA&M) in Enterprise Mission Assurance Support Service (eMASS).
  • The ISSE III shall develop and maintain system level IT and CS policies and procedures for respective RMF boundaries and/or guidance provided by the command ISSMs.
  • The ISSE III shall implement and assess STIG and SRGs.
  • The ISSE III shall perform and develop vulnerability assessments with automated tools such as Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP) Compliance Check (SCC) and Evaluate STIG.
  • The ISSE III shall deploy security updates to Information System components.
  • The ISSE III shall perform routine audits of IT system hardware and software components.
  • The ISSE III shall maintain inventory of Information System components.
  • The ISSE III shall participate in IT change control and configuration management processes.
  • The ISSE III shall upload vulnerability data in Vulnerability Remediation Asset Manager (VRAM).
  • The ISSE III shall image or re-image assets that are part of the assigned RMF boundary.
  • The ISSE III shall install software and troubleshoot software issues as necessary to support compliance of the RMF boundaries' assets.
  • The ISSE III shall assist with removal of SSD, HDD or other critical components of assets before destruction and removal from the RMF boundary.
  • The ISSE III shall provide cybersecurity patching of assets in times of DoD and DoN TASKORDs, FRAGORDs, or even designated by Command ISSM, ACIO, and/or Code 104 management.
  • The ISSE III shall support configuration change documentation and control processes and maintaining DOD STIG Compliance.
  • The ISSE III shall support cyber compliance of assets that are part of an enterprise IT network to include Windows server and CISCO networking hardware. This includes assessing vulnerabilities, patching and meeting requirements of the STIG for the hardware.
  • The ISSE III shall report compliance issues of network hardware to management.
  • Other duties as assigned.
Knowledge, Skills, And Abilities (KSAs)
  • Ability to work as a team member, communicate, perform office functions and use office tools, customer focused and deliver exceptional performance.
  • Ability to develop and implement information assurance guidance and execute ISS functions with little to no supervision.
Certifications
  • Minimum Certification Requirements: IAT Level III certification (CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH and CCSP).
Minimum/General Experience
  • Seven (7) years professional experience capturing and refining information security operational and security requirements, and ensuring those requirements are properly addressed through purposeful architecting, design, development, and configuration; and implementing security controls, configuration changes, software/hardware updates/patches, vulnerability scanning, and securing configurations.
Minimum Education
  • Bachelor's degree in computer science, information technology, or an equivalent technical degree from an accredited college or university.

ARMADA provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. ARMADA complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including, but not limited to, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

Must be able to successfully pass a background check, and pre-employment drug testing. Job offers are contingent upon results of background check and drug testing.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Engineer II
Information Systems Security Engineer II

ARMADA, Ltd. • Philadelphia

On-site
USD 80,000 - 100,000
Information Systems Security Engineer II
Information Systems Security Engineer II

Armada LTD • Philadelphia

On-site
USD 90,000 - 120,000
Information System Security Engineer III
Information System Security Engineer III

Centuria • Philadelphia

On-site
USD 90,000 - 130,000
Information System Security Engineer (ISSE) III
Information System Security Engineer (ISSE) III

StratasCorp Technologies • Philadelphia

On-site
USD 90,000 - 120,000
Information System Security Engineer (ISSE) II - Hybrid
Information System Security Engineer (ISSE) II - Hybrid

Ishpi Information Technologies, Inc. (ISHPI) • Philadelphia

On-site
USD 70,000 - 100,000
Information Systems Security Manager
Information Systems Security Manager

ARMADA, Ltd. • Washington

On-site
USD 100,000 - 120,000
Information System Security Engineer (ISSE) II (on-site)
Information System Security Engineer (ISSE) II (on-site)

Ishpi Information Technologies, Inc. (ISHPI) • Philadelphia

On-site
USD 90,000 - 120,000
Cyber Security Analyst III (ISSE)
Cyber Security Analyst III (ISSE)

Scientific Research Corporation • Virginia Beach (VA)

On-site
USD 119,100 - 198,450
Medical, dental, and vision plans
401(k) with company match
Life insurance
+2
Information Systems Security Manager
Information Systems Security Manager

Armada LTD • Washington

On-site
USD 130,000 - 190,000
Information System Security Engineer II Required Security Clearance Secret Philadelphia, PA ID [...]
Information System Security Engineer II Required Security Clearance Secret Philadelphia, PA ID [...]

Athena Technology Group • Philadelphia

On-site
USD 100,000 - 140,000
Performance bonuses
Health, dental, and vision insurance
Short-Term Disability
+5