Information Systems Security Engineer (ISSE)

Mantis Security Corporation

Sarasota (FL)

On-site

USD 120,000 - 180,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Mantis Security Corporation seeks an Information Systems Security Engineer (ISSE) to lead security design integration within information systems and technology components.

You will implement STIG/SCAP controls, conduct risk analysis, and collaborate with admins to mitigate vulnerabilities while contributing to Agile planning and government security reporting.

Qualifications

  • ISSE and CISSP certifications required.
  • US Citizen with ability to obtain TS/SCI clearance.
  • 8 years of relevant experience and a Bachelor's degree; Master’s may substitute 2 years.
  • DoD 8570 IASAE Level 3 compliance required.
  • 3 years of scripting, Linux/RedHat, or networking appliances experience.

Responsibilities

  • Develop security designs ensuring hardware/OS/software address cyber requirements and SCTM.
  • Identify vulnerabilities and non-compliance, recommend mitigations.
  • Implement STIG requirements and SRG assessments for projects.
  • Develop/configure Splunk apps and dashboards.
  • Create Security Test Procedures (STP) and support A&A testing and validation.
  • Conduct risk analysis of ACAS, CVEs, CWEs; coordinate with System Administrators for mitigations.
  • Support RMF processes and CNSSI 1243 compliance in security engineering.

Skills

Information security engineering
RMF / CSO concepts
Cyber security
Vulnerability assessment
Agile planning

Education

Bachelor’s degree in Computer Science or related field
Master’s degree preferred

Tools

Splunk
STIG
SCAP

Job description

Mantis Security is a leading specialty firm of high caliber talent who specialize in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We enable and protect our nation's most important IT assets and invest in the long-term career development of every employee! We are currently looking for the next Information Systems Security Engineer (ISSE) to join our team of experts!

Mantis Security is a leading specialty firm of high caliber talent who specialize in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We enable and protect our nation's most important IT assets and invest in the long-term career development of every employee! We are currently looking for the next Information Systems Security Engineer (ISSE) to join our team of experts!

As an ISSE on the Mantis Security Team, you will define information security requirements and their integration into information systems and its technology component through purposeful security design.

What You'll Be Doing
  • Develops and implements security designs ensure that the hardware, operating systems and software applications adequately address cyber security requirements and Security Controls Traceability Matrix (SCTM).
  • Identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations and recommend mitigation strategies.

Implement, validate Security Technical Implementation Guide (STIG) requirements and/or perform SRG assessments for all development and implementation projects.

  • Develop, customize, and configure Splunk applications and dashboards.
  • Develop Security Test Procedure (STP), conducts self-assessments to verify compliance with required configuration guidance and support A&A testing and validation of security designs.
  • Conducting risk analysis reviewing ACAS, CVEs, plugins, CWEs, research, collaborate with System Administrators to mitigate identified vulnerabilities and/or author Plans of Actions and Milestones (PO&AM) as needed.
  • Execution of continuous monitoring efforts responds to data calls, scan requests, and various weekly and monthly security metrics reporting requirements.
  • Validate control implementations provide enforcement of the require data access and network flow restrictions align with the continuous monitoring strategy.
  • Participates in Agile Planning Events to provide technical input.
  • Support government activities and reporting to appropriate IC and DoD authorities (i.e., USCYBERCOM, IC-SCC).
  • Support security authorization activities in compliance with the customer Information System Certification and Accreditation Process following the NIST Risk Management Framework (RMF), CNSSI No 1243 and other prescribed business processes for security engineering.
  • Assist architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of Agency security policy and enterprise solutions.
  • Apply system security engineering expertise in one or more of the following to: system security design process; engineering life cycle; information domain; cross domain solutions; commercial off-the-shelf and government off-the-shelf cryptography; identification; authentication; and authorization; system integration; risk management; intrusion detection; contingency planning; incident handling; configuration control; change management; auditing; certification and accreditation process; principles of IA (confidentiality, integrity, non-repudiation, availability, and access control); and security testing.
Requirements

Information Systems Security Engineering Professional (ISSEP) and CISSP Certifications are required.

Must Haves
  • Must be a US Citizen
  • 8 years of relevant experience and a Bachelor's degree in Computer Science, Information Assurance, Information Security System Engineering, or related discipline from an accredited college or university is required. A Master's degree in Computer Science, Information Assurance, Information Security System Engineering, or related discipline may be substituted for two (2) years of additional experience. Four (4) years of additional ISSE experience may be substituted for a bachelor's degree.
  • DoD 8570 compliance with IASAE Level 3 is required
  • Three (3) years of experience in scripting languages, Linux/RedHat, and/or Networking Appliances
  • Active TS/SCI security clearance with the ability to obtain polygraph is required
Nice To Haves
  • Skilled in implementing mitigation strategies and how to resolve problems, and to re-test/ re-evaluate systems
  • Demonstrated experience with DISA Security Technical Implementation Guide (STIG) implementation and Security Content Automation Protocol (SCAP) tool usage
  • Possess a working knowledge of administrating servers, system and application security threats and vulnerabilities
  • Experience extending existing applications in areas such as security, monitoring, task automation, continuous integration, deployment, and performance optimization
  • Demonstrate writing of your own project in scripting/programming (use of Shell scripting, Python, JavaScript, PowerShell) in a Linux or Windows environment to support the various Cyber Security tools and applications required
  • Provide guidance on vulnerability and malware remediation.
  • Experience analyzing vulnerabilities, establishing cause and impact, and identifying the corrective action needed to eliminate and prevent the event from happening in the future.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Mantis Security Corporation • Reston (VA)

On-site
USD 130,000 - 180,000
Information Systems Security Engineer (INFOSEC Engineer, ISSE)
Information Systems Security Engineer (INFOSEC Engineer, ISSE)

M2 Solutions • Herndon (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (INFOSEC Engineer, ISSE)
Information Systems Security Engineer (INFOSEC Engineer, ISSE)

M2 Solutions Inc. • Herndon (VA)

On-site
USD 120,000 - 150,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

VTG Defense • Chantilly (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Modern Technology Solutions, Inc. (MTSI) • Washington

On-site
USD 120,000 - 150,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

VT Group (VTG) • Chantilly (VA)

On-site
USD 100,000 - 130,000
Information System Security Engineer (ISSE)
Information System Security Engineer (ISSE)

Peraton • Maryland

On-site
USD 120,000 - 180,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Vosper Thornycroft Group • Chantilly (VA)

On-site
USD 90,000 - 130,000
Information Systems Security Engineer
Information Systems Security Engineer

VT Group (VTG) • Chantilly (VA)

On-site
USD 90,000 - 120,000
Senior Information Security Engineer (ISSE) – TS/SCI
Senior Information Security Engineer (ISSE) – TS/SCI

Mantis Security Corporation • Reston (VA)

On-site
USD 130,000 - 180,000