Enable job alerts via email!
Boost your interview chances
Create a job specific, tailored resume for higher success rate.
A leading company in the defense sector is looking for a Senior Information Systems Security Engineer to support critical missions in cybersecurity. The ideal candidate will have extensive experience in information security, technical certifications, and a proven track record in managing cybersecurity projects. Key responsibilities include designing secure architectures, ensuring compliance with standards, and supporting cross-functional teams.
Location: Fairfax, VA (Situational telework eligible)
Clearance: TS Clearance SCI Eligible / SAP Eligible
Education: MA/MS in Cybersecurity, Computer Science or related field (or BS in a related field plus an additional 4 years of related work experience)
Certifications: A DoD 8570.01-M IAT Level III technical certification (such as CISSP, CASP, or other level 3 technical certification) is required.; and a Cloud Service Provider Associate Certification (AWS, Azure, Oracle, or Google) is required.
Outcomes:
The successful candidate is expected to accomplish the following outcomes during the first year in the position:
· Formally track all tasks, to include assigned by, suspense, status, and comments on all assigned tasks through completion and be prepared to brief upon request.
· Develop digital continuity folders and files that include standard operating procedures, workflows and POC lists to accomplish all tasks.
· Create 2-3 products beyond the client’s requirements that positively impact the client to either increase efficiency, effectiveness, or innovation.
· Master position tasks within 60 days and exceed requirements within 90 days.
Responsibilities:
The Senior Information Systems Security Engineer (ISSE) (SME) will directly support the Secretary of the Air Force (SAF) / Office of Competition (OC) Mission Partner Capabilities Office (MPCO) also known as SAF/CDMX Directorate. The Mission Partner Capabilities Office provides design, configuration, accreditation and implementation of mission and R&D information management systems and cloud-based solutions that support defense and intelligence priorities as well as internal business processes and mission functions, network communications, database management, security accreditation, and workflow management.
The ISSE will design and implement secure system architectures to protect SAF/OC information systems from cyber threats. The ISSE will work closely with ISSMs, ISSOs, and IT teams to integrate security controls and ensure compliance with RMF, NIST 800-53, and DoD security standards.
The ISSE SME is responsible for designing, implementing, and maintaining security controls to protect the organization's information systems in accordance with Department of Defense (DoD) requirements. This role involves collaborating with various stakeholders to ensure that security measures are effectively integrated into the system development lifecycle (SDLC) and that compliance with relevant regulations is achieved. This is a unique hands-on technical role in such that the ISSE is responsible for compliance-based cybersecurity engineering to include but not limited to cybersecurity engineering and generation of body of evidence requirements per DoD Risk Management Framework (RMF). Additionally, the ISSE shall provide management and professional support, assistance, advice, to support the efficient and effective management and operation of the organization, activities, or systems specifically related to cybersecurity in all phases of RMF. This role will be the technical component supporting the ISSM. Per PWS section 1.3.9, Cybersecurity Support, specific tasks and responsibilities include but are not limited to:
Specific responsibilities include but are not limited to:
Qualifications:
The candidate must have the following qualifications:
· A minimum of fifteen (15) years of related work experience in information security, and of those years, at least ten (10) years of experience supporting a component of the Department of Defense (DoD) or Intelligence Community (IC).
Cloud Service Provider Associate Certification (AWS, Azure, Oracle, or Google)
Excellent oral, written, and interpersonal communication skills.
Expertise in building bodies of evidence and assessment and authorization packages/activities within DoD and IC environments, specifically Special Access Programs.
The ability to work under pressure and meet deadlines in a rapidly changing and demanding environment.
Strong attention to detail, flexibility, and the ability to context switch.
Expert in multiple domains of Information Technology, including cloud, cybersecurity, networking, and others.
Expert in two or more of the following domains: vulnerability analysis and vulnerability management, SIEM operations and defensive cyber operations, system hardening and cyber tool engineering.
Cybersecurity engineering is related to the RMF lifecycle, security control enforcement, body of evidence creation, and continuous monitoring, assessment, and authorization processes.
Operating in overlapping security control and overlay environments (CNSSI 1253, Executive Order 12333, Intelligence, JSIG, etc.).
Experience in overlapping domains at multiple classifications, including vulnerability analysis, SIEM operations, cyber network defense, cyber operations, malware analysis, information systems security management, or engineering.
Proficiency with Xacta or eMASS.
Experience with DoD Joint Special Access Program Implementation Guide (JSIG), AF Cyber policies, NIST SP 800 Series, and CNSSI 1253 security controls and overlays.
Experience operating in cloud cybersecurity and shared responsibility models, networking, and/or data experience is required.
Certifications:
DoD 8570.01-M IAT Level III technical certification (such as CISSP, CASP, or other level 3 technical certification) is required; and a Cloud Service Provider Associate Certification (AWS, Azure, Oracle, or Google) is required.
The following qualifications are desired:
Travel: Some local travel may be expected.