Information Systems Security Engineer (ISSE) (TS/SCI with Poly Required)

GCI Incorporated

Tysons (VA)

On-site

USD 140,000 - 190,000

Full time

40 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

GCI Incorporated seeks an Information Systems Security Engineer (ISSE) at SME level to lead security engineering across infrastructure, platforms, and applications. You will implement RMF within federal environments, design, implement, assess, and secure systems end-to-end, and serve as the technical focal point for security incidents in coordination with security teams.

The ideal candidate is hands-on, with expertise in RMF, NIST controls, SIEM, and cloud environments, capable of bridging

Qualifications

  • Bachelor’s degree or equivalent in a technical discipline.
  • Minimum ten years of applied cybersecurity experience or five years with degree.
  • Hands-on RMF implementation in federal environments.
  • Experience with RMF control implementations and ATO packages.
  • Strong knowledge of NIST SP 800-53/800-37/800-30.
  • Experience with SIEM platforms and incident response.

Responsibilities

  • Serve as SME for cyber security engineering across system layers.
  • Implement and validate security controls per RMF and NIST guidance.
  • Lead RMF lifecycle activities: Categorize, Select, Implement, Assess, Authorize, Monitor.
  • Coordinate incident response and triage security alerts.
  • Collaborate with owners, architects, developers and operations.
  • Prepare SSPs, SCA support, POA&Ms, risk assessments.

Skills

RMF expert
SIEM experience
Security incident response
Networking security
Cloud RMF
DevSecOps
Docker/Kubernetes
RMF artifacts
DoD overlays knowledge

Education

Bachelor’s degree in Cybersecurity or related field

Tools

Splunk
ELK Stack
ArcSight
QRadar

Job description

GCI embodies excellence, integrity and professionalism. The employees supporting our customers deliver unique, high-value mission solutions while effectively leverage the technological expertise of our valued workforce to meet critical mission requirements in the areas of Data Analytics and Software Development, Engineering, Targeting and Analysis, Operations, Training, and Cyber Operations. We maximize opportunities for success by building and maintaining trusted and reliable partnerships with our customers and industry.

Job Description

At GCI, we solve the hard problems. As an Information Systems Security Engineer (ISSE), a typical day will include the following duties: We are seeking a hands-on Cyber Security Engineer at the Subject Matter Expert (SME) level to lead and execute security engineering activities across complex, enterprise-scale environments. This role requires deep technical expertise across infrastructure, platforms, and applications, combined with expert-level, hands-on experience implementing the NIST Risk Management Framework (RMF) within federal government environments. The ideal candidate is a technical practitioner, not just an advisor-someone who can design, implement, assess, and secure systems end-to-ed while directly supporting system authorization, continuous monitoring, and risk-based decision-making. This role also serves as the technical focal point for all security incidents, leading triage, investigation, and resolution efforts in coordination with program and enterprise security teams.

Qualifications
  • Bachelor’s degree in Cybersecurity, IT, or other related technical discipline; or the equivalent combination of education, technical training, or work/military experience
  • Minimum ten (10) years applied experience or relevant degree plus five (5) years of Cybersecurity expertise with demonstrated ability to successfully shepherd IT projects of varying types through the authorization lifecycle
Required Knowledge/Skills

Candidate must demonstrate hands-on experience in all the following areas:

Security & Compliance
  • Expert-level experience with NIST Risk Management Framework (RMF) in federal government environments.
  • Strong knowledge of:
    • NIST SP 800-53
    • NIST SP 800-37
    • NIST SP 800-30
  • Direct involvement in ATO packages, control implementation, and assessments.
  • Hands-on experience with Security Information and Event Management (SIEM) platforms (e.g., Splunk, ELK Stack, ArcSight, Qradar).
  • Demonstrated experience in security incident detection, analysis, and response.
  • Proven ability to triage security alerts and determine criticality and impact.
Infrastructure & Platforms (Hands-On)
  • Networking (e.g., routing, switching, firewalls, load balancers, network security controls)
  • Operating Systems:
    • Windows Server
    • Linux (RHEL, CentOS)
  • Virtualization and storage platforms
  • Databases (SQL and/or NoSQL)
  • Data Platforms (e.g., HPCC, Hadoop/Cloudera)
  • Web services, APIs, and application architectures
  • Software development environments and CI/CD pipelines
  • Security tooling (e.g., vulnerability scanners, endpoint protection, SIEM)
Engineering Experience
  • Security engineering and system hardening
  • Vulnerability discovery and remediation
  • Secure system design and architecture reviews
  • Technical documentation supporting RMF compliance
  • Experience in cloud environments (AWS, Azure, GCP, CI) within federal RMF contexts
  • Experience with DevSecOps practices
Desired Skills
  • Hands-on experience with containerization and orchestration (Docker, Kubernetes)
  • Hands-on experience with infrastructure-as-code
  • Knowledge of federal overlays (e.g., DoD, FISMA High/Moderate)
  • Relevant certifications (preferred, not required):
    • CISSP
    • CAP
    • CISM
    • Security+
    • Cloud Security
    • Certified Ethical Hacker
  • Experience with guiding and directing junior engineers and information systems security officer (ISSO)
  • Experience with security orchestration, automation, and response (SOAR) platforms
  • Background in threat hunting and proactive security monitoring
  • Relevant incident response certifications
Ideal Candidate Profile
  • Proven hands-on Cyber Security Engineer SME, not policy-only or audit-only
  • Comfortable working across network, system, platform, and application layers
  • Deep understanding of how security controls are actually implemented and validated
  • Experience in federal RMF-driven environments
  • Able to bridge security, engineering, and compliance effectively
  • Experienced in managing security incidents from detection through resolution
  • Skilled at balancing immediate incident response needs with long-term security improvements
  • Effective collaborator across organizational boundaries during high-pressure security events
Key Responsibilities
  • Serve as the Cyber Security Engineer SME, providing hands-on security engineering across all system layers (infrastructure, platform, and application).
  • Engineer, implement, and validate security controls in accordance with NIST SP 800-53 and RMF requirements.
  • Lead and support RMF lifecycle activities (Categorize, Select, Implement, Assess, Authorize, Monitor).
  • Perform security engineering for:
    • Network architectures and boundary protections
    • Windows and Linux operation systems
    • Storage and virtualization platforms
    • Databases and data platforms
    • Web services, APIs, and application stacks
    • Custom and COTS/GOTS software solutions
  • Provide technical input to RMF artifacts, including:
    • System Security Plans (SSP)
    • Security Control Assessments (SCA) support
    • POA&Ms
    • Risk assessments and security impact analyses
  • Collaborate with system owners, architects, developers, and operations teams to embed security into system design and implementation.
  • Support ATO, re-authorization, and continuous monitoring activities.
  • Identify security risks and provide practical, technically sound mitigation strategies.
  • Participate in security reviews, technical design reviews, and vulnerability remediation efforts.
  • Serve as technical point of contact for all security incidents affecting the program.
  • Lead triage and analysis of new security alerts from SIEM, IDS/IPS, and other security monitoring tools.
  • Drive remediation efforts for recurring security alerts, identifying root causes and implementing systemic fixes.
  • Coordinate incident response activities between program stakeholders and enterprise security operations.
  • Act as primary liaison between program teams and enterprise security for incident escalation, resolution, and reporting.
  • Perform forensic analysis and technical investigations of security events.
  • Document security incidents, response actions, and lessons learned.
  • Develop and maintain runbooks and playbooks for common security incident types.
Expectation (SME-Leve Role)
  • Operate independently as the technical authority for system security engineering.
  • Demonstrate the ability to provide technical hands-on configuration, validation, an assessment of security controls.
  • Translate RMF and NIST requirements into real-world technical implementations.
  • Communicate complex technical security issues clearly to both technical and non-technical stakeholders.
  • Maintain a strong balance between security compliance and operational practicality.
  • Lead rapid response to security incidents with minimal guidance.
  • Demonstrate strong analytical and troubleshooting skills under pressure during active security events.
  • Effectively communicate incident status, impact, and remediation progress to technical and leadership audiences.
  • A candidate must be a US Citizen and requires an active/current TS/SCI with Polygraph clearance.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Engineer (ISSE) (TS/SCI with Poly Required)
Information Systems Security Engineer (ISSE) (TS/SCI with Poly Required)

GCI, Inc. • Tysons (VA)

On-site
USD 143,000 - 238,000
Information Security System Engineer
Information Security System Engineer

Elevate Technology Group • Fairfax Station (VA)

On-site
USD 150,000 - 220,000
Employer-funded 401(k) contribution
Flexible benefits allowance
Medical, Dental & Vision coverage
+1
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Evans & Chambers Technology • Arlington (VA)

On-site
USD 100,000 - 130,000
Cybersecurity Subject Matter Expert (SME)
Cybersecurity Subject Matter Expert (SME)

Central Strategies, LLC • Washington, Northern (KY)

Hybrid
USD 120,000 - 180,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Evans & Chambers • Arlington (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

VTG Defense • Chantilly (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

D2 Consulting • Springfield (VA)

On-site
USD 130,000 - 140,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Information Systems Security Engineer (ISSE) with Security Clearance
Information Systems Security Engineer (ISSE) with Security Clearance

D2 Consulting • Arnold (MO)

On-site
USD 120,000 - 130,000
Health/Dental/Vision
401(k) match
Paid time off
Cybersecurity / Information Security Engineer
Cybersecurity / Information Security Engineer

Evans & Chambers Technology • Chantilly (VA)

On-site
USD 100,000 - 130,000
Cybersecurity / Information Security Engineer
Cybersecurity / Information Security Engineer

Evans & Chambers Technology • Albuquerque (NM)

On-site
USD 100,000 - 130,000