Information Systems Security Engineer with Security Clearance

BOAB Ventures

Washington (District of Columbia)

On-site

USD 140,000 - 220,000

Full time

29 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

BOAB Ventures is seeking an experienced Information Systems Security Engineer (ISSE) to support mission-critical systems in a highly secure DoD/IC environment. This hands-on role designs, implements, hardens, and validates security controls within complex classified systems, collaborating with system administrators, engineers, and government stakeholders to align mission needs with compliance requirements.

The ideal candidate translates RMF, NIST SP 800-53, ICD 503, and CNSSI 1253 into testable

Qualifications

  • Active TS/SCI security clearance required.
  • Ability and willingness to obtain a polygraph.
  • Hands-on experience implementing cybersecurity controls within DoD/IC environments.
  • Strong understanding of RMF, NIST SP 800-53, ICD 503, CNSSI 1253.
  • Experience engineering or supporting systems through ATO.
  • Hands-on experience with DISA STIG implementation and system hardening.
  • Experience with vulnerability-management and compliance tools such as ACAS, Nessus, SCAP.
  • Experience securing Windows and/or Linux environments.
  • Ability to translate cybersecurity requirements into actionable technical solutions.
  • DoD 8570/8140 IASAE Level II certification or equivalent.
  • IASAE Level III qualification preferred.
  • Experience with JWICS, SAP, or similar highly classified environments.
  • Experience with secure cloud environments (AWS GovCloud, Azure Government).
  • Experience with DevSecOps, CI/CD pipelines, containers, Kubernetes, or IaC.
  • Automation experience with PowerShell, Bash, Python, Ansible.

Responsibilities

  • Engineer and integrate cybersecurity controls throughout the system development lifecycle.
  • Translate RMF, ICD 503, CNSSI 1253, and NIST SP 800-53 requirements into implemented controls.
  • Support ATO lifecycle development and validation of technical security evidence.
  • Implement and validate DISA STIGs and IC baselines across Windows, Linux, network, and infrastructure.
  • Conduct vulnerability assessment and remediation using ACAS, Nessus, SCAP, and related tools.
  • Collaborate with engineering teams to embed security into architecture, deployment, and operations.
  • Integrate cybersecurity requirements into DevSecOps and CI/CD environments.
  • Engineer and validate security monitoring, logging, auditing, and continuous-monitoring capabilities.
  • Assess security impact of proposed system changes and recommend controls.
  • Support secure cloud, on-premises, containerized, and classified computing environments.
  • Assist with incident response, vulnerability remediation, configuration management, and investigations.

Skills

TS/SCI clearance
polygraph
security engineering
RMF
NIST SP 800-53
ICD 503
CNSSI 1253
ATO lifecycle
DISA STIG
vulnerability tools
DevSecOps
CI/CD
Cloud security
Infrastructure as Code
PowerShell
Python
Ansible
Kubernetes
JWICS/SAP

Tools

ACAS
Nessus
SCAP

Job description

Job Description BOAB Ventures is seeking an experienced Information Systems Security Engineer (ISSE) to support mission-critical systems within a highly secure Department of Defense and Intelligence Community environment. This is a hands-on security engineering position for someone who can go beyond documenting compliance requirements and actively design, implement, integrate, harden, and validate security controls within complex classified systems. The ideal candidate understands the intent behind cybersecurity requirements and can work directly with system administrators, software engineers, infrastructure teams, and government stakeholders to develop secure technical solutions that satisfy both mission and compliance objectives.

What You'll Do * Engineer and integrate cybersecurity controls throughout the system development lifecycle.

  • Translate RMF, ICD 503, CNSSI 1253, and NIST SP 800-53 requirements into implemented and testable technical controls.
  • Support systems through the ATO lifecycle, including development and validation of technical security evidence.
  • Implement and validate DISA STIGs and Intelligence Community security baselines across Windows, Linux, network, and infrastructure environments.
  • Conduct vulnerability assessment and remediation using tools such as ACAS, Nessus, SCAP, and related security technologies.
  • Analyze STIG and security-control requirements to understand the underlying vulnerability and develop appropriate technical solutions, alternative implementations, or compensating controls when standard configurations conflict with mission requirements.
  • Work directly with engineering and development teams to incorporate security into system architecture, infrastructure, applications, and deployment processes.
  • Integrate cybersecurity requirements into DevSecOps and CI/CD environments where applicable.
  • Engineer and validate security monitoring, logging, auditing, and continuous-monitoring capabilities.
  • Assess proposed system changes for security impact and recommend appropriate technical controls or remediation.
  • Support secure cloud, on-premises, containerized, and classified computing environments.
  • Assist with incident response, vulnerability remediation, configuration management, and technical security investigations.
  • Collaborate with ISSMs, ISSOs, system owners, engineers, developers, and government stakeholders throughout authorization and operational activities.
  • Required Skills * Active TS/SCI security clearance.
  • Ability and willingness to obtain a polygraph.
  • Demonstrated hands-on experience implementing cybersecurity controls within classified DoD or Intelligence Community environments.
  • Strong understanding of RMF, NIST SP 800-53, ICD 503, and CNSSI 1253.
  • Experience engineering or supporting systems through ATO.
  • Hands-on experience with DISA STIG implementation and system hardening.
  • Experience with vulnerability-management and compliance tools such as ACAS, Nessus, SCAP, or equivalent technologies.
  • Experience securing and troubleshooting Windows and/or Linux environments.
  • Ability to translate cybersecurity requirements into actionable technical solutions.
  • Strong understanding of vulnerability, risk, compensating controls, and security-control implementation.
  • Ability to communicate effectively with both technical engineering teams and government/customer stakeholders.
  • DoD 8570/8140 IASAE Level II certification or equivalent qualification.
  • Desired Skills * IASAE Level III qualification.
  • Experience supporting JWICS, SAP, or similar highly classified environments.
  • Experience with AWS GovCloud, Azure Government, or other secure cloud environments.
  • Experience with DevSecOps, CI/CD pipelines, containers, Kubernetes, or Infrastructure as Code.
  • Experience automating security or system-hardening activities using PowerShell, Bash, Python, Ansible, or similar technologies.
  • Experience with cross-domain solutions or complex classified network architectures.
  • Experience securing AI/ML platforms, data pipelines, or emerging technologies.
  • Prior Military Intelligence, DoD, or Intelligence Community experience.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Engineer
Information Systems Security Engineer

VT Group (VTG) • Chantilly (VA)

On-site
USD 90,000 - 120,000
Information Security System Engineer
Information Security System Engineer

Elevate Technology Group • Fairfax Station (VA)

On-site
USD 150,000 - 220,000
Employer-funded 401(k) contribution
Flexible benefits allowance
Medical, Dental & Vision coverage
+1
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

VT Group (VTG) • Chantilly (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

VTG Defense • Chantilly (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

TechIcon, Inc. • Aberdeen (MD)

On-site
USD 130,000 - 180,000
Information Systems Security Engineer (INFOSEC Engineer, ISSE)
Information Systems Security Engineer (INFOSEC Engineer, ISSE)

M2 Solutions Inc. • Herndon (VA)

On-site
USD 140,000 - 190,000
Information Systems Security Engineer (INFOSEC Engineer, ISSE)
Information Systems Security Engineer (INFOSEC Engineer, ISSE)

M2 Solutions • Herndon (VA)

On-site
USD 100,000 - 130,000
Senior ISSE (TS/SCI) - DoD/IC Secure Systems Engineer
Senior ISSE (TS/SCI) - DoD/IC Secure Systems Engineer

BOAB Ventures • Washington

On-site
USD 140,000 - 220,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Evans & Chambers Technology • Arlington (VA)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Evans & Chambers • Arlington (VA)

On-site
USD 100,000 - 130,000