Information Systems Security Engineer SME

ECS

Stafford (VA)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ECS is seeking an experienced Information Systems Security Engineer SME to support mission-critical federal cybersecurity programs. This senior role involves leading security engineering efforts, advising stakeholders, and translating complex risks into actionable recommendations.

Responsibilities include supporting RMF and Security Assessment activities, providing guidance on security controls, and developing improvement templates. The ideal candidate has a Top Secret clearance and over 10 years of relevant experience in cybersecurity.

Qualifications

  • Active Top Secret clearance with SCI eligibility.
  • 10+ years of experience in secure design and testing.
  • Ability to assess technical security evidence.

Responsibilities

  • Lead RMF and Security Assessment and Authorization activities.
  • Provide technical guidance to stakeholders.
  • Develop templates and improve processes.

Skills

Secure design
Cybersecurity methods
Security test plans
NIST SP 800-53 knowledge
Written and verbal communication
Team leadership

Education

CISSP or CEH certification
Cloud security certification preferred

Tools

Tenable Nessus
Splunk
Nmap

Job description

Overview

ECS is seeking an experienced Information Systems Security Engineer SME to support mission-critical federal cybersecurity programs. The selected candidate will serve as a senior cybersecurity engineering expert supporting Security Assessment and Authorization, Risk Management Framework execution, cloud security, technical control implementation, assessment readiness, continuous monitoring, vulnerability remediation, audit support, and risk-informed authorization activities. This role is ideal for a senior cybersecurity professional who can operate at both the strategic and technical levels and who is passionate in leading security engineering efforts, mentoring cybersecurity personnel, advising stakeholders, improving authorization quality, and translating complex technical risks into clear, actionable recommendations.

Responsibilities
  • Lead and support full lifecycle RMF and Security Assessment and Authorization activities for federal information systems.
  • Provide senior technical guidance to system owners, ISSOs, ISSMs, engineering teams, program leadership, and authorization stakeholders.
  • Advise on system categorization, security control selection and tailoring, control implementation, assessment readiness, risk analysis, and authorization package quality.
  • Review and strengthen RMF documentation, including System Security Plans, control implementation descriptions, risk assessments, security test plans, assessment results, POA&Ms, inventories, network diagrams, data flow diagrams, and continuous monitoring artifacts.
  • Evaluate technical, operational, and management controls to determine whether safeguards are implemented correctly, operating as intended, and supported by complete evidence.
  • Identify technical control gaps and develop remediation recommendations that are practical, risk-informed, and aligned to federal cybersecurity standards.
  • Support cloud security engineering activities for systems using AWS, Azure, Google Cloud, or hybrid environments.
  • Provide technical input for vulnerability remediation, patch compliance, POA&M tracking, emergency directive response, audit readiness, and corrective action planning.
  • Support security impact analysis for proposed technical changes, including architecture updates, system integrations, cloud services, network changes, and control modifications.
  • Develop or improve templates, checklists, SOPs, evidence standards, dashboards, and repeatable processes that improve quality, consistency, and efficiency.
  • Track and communicate risks, findings, action items, assessment status, remediation progress, and improvement opportunities to stakeholders and leadership.
  • Maintain current knowledge of RMF, NIST, CNSS, FISMA, cloud security, and federal cybersecurity best practices.
Required Skills
  • Active Top Secret clearance with SCI eligibility.
  • U.S. citizenship.
  • 10+ years of experience in secure design, analysis, and testing of information security systems and products.
  • 10+ years of experience applying cybersecurity methods, standards, and approaches to ensure baseline security safeguards are properly implemented and documented.
  • 10+ years of experience creating or updating security test plans to detect, assess, and mitigate risk to information systems.
  • CISSP or CEH required.
  • Experience supporting RMF, ATO, SAA, continuous monitoring, POA&M management, vulnerability remediation, security assessment, and audit readiness activities.
  • Experience developing, reviewing, or improving federal cybersecurity documentation and authorization artifacts.
  • Knowledge of NIST SP 800-53, NIST SP 800-53A, FIPS 199, FIPS 200, CNSS guidance, FISMA, and federal information security requirements.
  • Ability to assess technical security evidence and provide risk-based recommendations to technical and non-technical stakeholders.
  • Strong written and verbal communication skills.
  • Ability to lead teams, mentor personnel, coordinate across multiple stakeholders, and manage complex cybersecurity tasks in a high-accountability environment.
Desired Skills
  • Cloud security certification preferred, such as CCSP, AWS Certified Security - Specialty, AWS Certified Solutions Architect, Microsoft Azure Security Engineer Associate, or Google Professional Cloud Security Engineer.
  • Experience securing AWS, Azure, Google Cloud, or hybrid cloud environments.
  • Experience with GRC tools, control inheritance, evidence reuse, dashboard reporting, and workflow automation.
  • Experience with tools such as Tenable Nessus, Security Center, Splunk, IBM Guardium, WebInspect, Nmap, or similar security platforms.
  • Experience supporting classified federal environments, national security systems, law enforcement systems, intelligence systems, or high-impact mission systems.

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis of any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Everforth ECS is the federal segment of Everforth, a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies.

Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow.

We Value
  • Attracting and developing top talent and high-performing teams
  • Fostering a culture that is engaging, accountable, and mission-driven
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Systems Security Engineer
Senior Information Systems Security Engineer

ECS • Washington

On-site
USD 120,000 - 150,000
Senior Information Systems Security Engineer
Senior Information Systems Security Engineer

ECS • Huntsville (AL)

On-site
USD 90,000 - 130,000
Security Controls Assessor
Security Controls Assessor

ECS • Washington

Hybrid
USD 150,000 - 168,000
Information System Security Engineer SME
Information System Security Engineer SME

ECS • Washington

On-site
USD 175,000 - 190,000
Senior Security Engineer
Senior Security Engineer

ECS • Washington

On-site
USD 145,000 - 165,000
General Description of Benefits
Authorizing Official Designated Representative (AODR) Support Analyst
Authorizing Official Designated Representative (AODR) Support Analyst

ECS • Washington

Hybrid
USD 170,000 - 190,000
Information System Security Officer Sr. (Cloud)
Information System Security Officer Sr. (Cloud)

ECS • Washington

On-site
USD 120,000 - 150,000
Senior Cyber Incident Analyst
Senior Cyber Incident Analyst

ECS • Arlington (VA)

On-site
USD 170,000 - 180,000
AWS Cloud / Security Engineer
AWS Cloud / Security Engineer

ECS • Stafford (VA)

Hybrid
USD 100,000 - 120,000
Cyber Assessment & Authorization / Technical Writer
Cyber Assessment & Authorization / Technical Writer

ECS • Falls Church (VA)

On-site
USD 130,000 - 150,000