Enable job alerts via email!

Information Systems Security Engineer III

Armada Ltd

Philadelphia (Philadelphia County)

On-site

USD 80,000 - 110,000

Full time

29 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking an Information Systems Security Engineer III to enhance their cybersecurity posture. In this pivotal role, you will develop and maintain comprehensive security plans, execute risk assessments, and ensure compliance with the Risk Management Framework. You will work collaboratively with a dedicated team to implement security controls and manage vulnerabilities across IT systems. This position offers a unique opportunity to contribute to critical security operations while ensuring the integrity of vital information systems. If you are passionate about cybersecurity and eager to make a significant impact, this role is for you.

Qualifications

  • 7+ years of experience in information security operational requirements.
  • IAT Level III certification required, such as CISSP or CCNP Security.

Responsibilities

  • Develop and maintain RMF system security plans and policies.
  • Execute security control testing and mitigate vulnerabilities.
  • Perform audits and maintain inventory of Information System components.

Skills

Teamwork
Communication
Information Assurance Guidance
Risk Management Framework (RMF)
Vulnerability Assessments

Education

Bachelor's degree in Computer Science

Tools

Assured Compliance Assessment Solution (ACAS)
Security Content Automation Protocol (SCAP)
Vulnerability Remediation Asset Manager (VRAM)
CISCO Networking Hardware

Job description

Information Systems Security Engineer III
  • 5001 S Broad St, Philadelphia, PA 19112, USA

Location: Philadelphia, PA (Travel - CONUS locations, less than 5%)

Overtime Exempt: Yes

Reports To: ARMADA HQ

Security Clearance Required: Active Secret

Duties & Responsibilities:

  • The Information Systems Security Engineer III (ISSE III) shall assist with developing, maintaining, and tracking Risk Management Framework (RMF) system security plans which include System Categorization Forms, Platform Information Technology (PIT) Determination Checklists, Assess Only (AO) Determination Checklists, Implementation Plans, System Level Continuous Monitoring (SLCM) Strategies, System Level Policies, Hardware Lists, Software List, System Diagrams, Privacy Impact Assessments (PIA), and Plans of Action and Milestones (POA&M).
  • The Information Systems Security Engineer III shall execute the RMF process in support of obtaining and maintaining Interim Authority to Test (IATT), AO approval, Authorization to Operate (ATO), and Denial of Authorization to Operate (DATO).
  • The Information Systems Security Engineer III shall identify and tailor IT and CS security control baselines based on RMF guidelines and categorization of the RMF boundary.
  • The ISSE III shall perform Ports, Protocols, and Services Management (PPSM).
  • The ISSE III shall perform IT and CS vulnerability-level risk assessments.
  • The ISSE III shall execute security control testing as required by a risk assessment or annual security review (ASR).
  • The ISSE III shall mitigate and remediate IT and CS system level vulnerabilities for all assets within the boundary per STIG requirements.
  • The ISSE III shall develop and maintain Plans of Actions and Milestones (POA&M) in Enterprise Mission Assurance Support Service (eMASS).
  • The ISSE III shall develop and maintain system level IT and CS policies and procedures for respective RMF boundaries and/or guidance provided by the command ISSMs.
  • The ISSE III shall implement and assess STIG and SRGs.
  • The ISSE III shall perform and develop vulnerability assessments with automated tools such as Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP) Compliance Check (SCC) and Evaluate STIG.
  • The ISSE III shall deploy security updates to Information System components.
  • The ISSE III shall perform routine audits of IT system hardware and software components.
  • The ISSE III shall maintain inventory of Information System components.
  • The ISSE III shall participate in IT change control and configuration management processes.
  • The ISSE III shall upload vulnerability data in Vulnerability Remediation Asset Manager (VRAM).
  • The ISSE III shall image or re-image assets that are part of the assigned RMF boundary.
  • The ISSE III shall install software and troubleshoot software issues as necessary to support compliance of the RMF boundaries' assets.
  • The ISSE III shall assist with removal of SSD, HDD or other critical components of assets before destruction and removal from the RMF boundary.
  • The ISSE III shall provide cybersecurity patching of assets in times of DoD and DoN TASKORDs, FRAGORDs, or even designated by Command ISSM, ACIO, and/or Code 104 management.
  • The ISSE III shall support configuration change documentation and control processes and maintaining DOD STIG Compliance.
  • The ISSE III shall support cyber compliance of assets that are part of an enterprise IT network to include Windows server and CISCO networking hardware. This includes assessing vulnerabilities, patching and meeting requirements of the STIG for the hardware.
  • The ISSE III shall report compliance issues of network hardware to management.
  • Other duties as assigned.

Knowledge, Skills, and Abilities (KSAs):

  • Ability to work as a team member, communicate, perform office functions and use office tools, customer focused and deliver exceptional performance.
  • Ability to develop and implement information assurance guidance and execute ISS functions with little to no supervision.

Certifications:

  • Minimum Certification Requirements: IAT Level III certification (CASP+ CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH and CCSP).

Minimum/General Experience:

  • Seven (7) years professional experience capturing and refining information security operational and security requirements, and ensuring those requirements are properly addressed through purposeful architecting, design, development, and configuration; and implementing security controls, configuration changes, software/hardware updates/patches, vulnerability scanning, and securing configurations.
  • Bachelor's degree in computer science, information technology, or an equivalent technical degree from an accredited college or university.

Disclaimer:

The above information has been designed to indicate the general nature and level of work to be performed. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of the contractor assigned to this position.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Information Systems Security Engineer (ISSE)

Green Expert Technology Inc. (GreenXT)

Philadelphia

On-site

USD 92,000 - 126,000

5 days ago
Be an early applicant

Information Systems Security Engineer III

Alutiiq, LLC

Philadelphia

On-site

USD 100,000 - 120,000

9 days ago

Information Systems Security Engineer III

Armada LTD

Philadelphia

On-site

USD 80,000 - 110,000

9 days ago

Information Systems Security Engineer (IAT Level III)

ISPA Technology, LLC

Philadelphia

On-site

USD 80,000 - 110,000

9 days ago

Information System Security Engineer (ISSE) III - NAVSEA

Diligent Consulting Inc

Philadelphia

On-site

USD 90,000 - 150,000

3 days ago
Be an early applicant

Information System Security Engineer (ISSE) III - NAVSEA

Diligent Consulting Inc

Philadelphia

On-site

USD 90,000 - 140,000

5 days ago
Be an early applicant

Information Systems Security Engineer III

Alutiiq

Philadelphia

On-site

USD 100,000 - 120,000

30+ days ago

Information Systems Security Engineer (IAT Level III)

ISPA Technology, LLC

Philadelphia

On-site

USD 70,000 - 110,000

30+ days ago

Information System Security Engineer III

ISPA Technology, LLC

Philadelphia

On-site

USD 80,000 - 110,000

8 days ago