Information Systems Security Engineer

Systems Planning & Analysis

Lorton (VA)

On-site

USD 180,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Systems Planning and Analysis, Inc. (SPA) is seeking an IT Modernization Information Systems Security Engineer (SCISSE) to join the Sea, Land, Air Analysis Group.

The role focuses on integrating cybersecurity requirements into system architecture from concept through deployment and across the full system lifecycle. You will develop security artifacts, perform threat modeling and vulnerability assessments, implement controls per NIST and CNSSI guidance, and collaborate with ISSOs, developers, and

Qualifications

  • Onsite in Lorton, VA, up to full-time, based on client needs.
  • Master’s degree in engineering, computer science, cybersecurity, networking, or programming.
  • Experience with SAPs and cloud architecture with strong security elements.
  • 12+ years in cybersecurity, IT, or systems engineering; TS/SCI with CI Polygraph.
  • ISSEP/CCSP/CISSP/CASP/GCLD certifications are desirable.

Responsibilities

  • Integrate cybersecurity requirements into system architecture from concept to deployment.
  • Develop security artifacts—Security Plans, SATCMs, diagrams, and docs.
  • Perform threat modeling, vulnerability assessments, and security impact analyses.
  • Select, tailor, and implement controls per NIST SP 800-53, CNSSI 1253, and related guides.
  • Communicate risk-based recommendations and support changes with ISSOs and teams.
  • Monitor security compliance and maintain SOPs, POA&Ms, and governance artifacts.

Skills

Threat modeling
Security architecture
System hardening
Java
Python
Ruby
C++
Linux
Cloud security
Risk assessment

Education

Master’s degree in engineering, computer science, cybersecurity, networking, or programming

Tools

OPSWAT
OWASP ZAP
BurpSuite
Fortify
Tenable
Azure Defender
AWS Inspector
Nessus
SIEM

Job description

Overview

Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing Results that Matter . Come work with the best! We offer opportunity, unique challenges, and clear-sighted commitment to the mission. SPA: Objective. Responsive. Trusted.

Overview

Systems Planning and Analysis, Inc. (SPA) delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and consistent growth, we are known for continuous innovation for our government customers, in both the US and abroad. Our exceptionally talented team is highly collaborative in spirit and practice, producing Results that Matter . Come work with the best! We offer opportunity, unique challenges, and clear-sighted commitment to the mission. SPA: Objective. Responsive. Trusted.

The Sea, Land, Air Analysis Group’s mission is to deliver objective analyses, plans and strategies to US Navy, US Marine Corps, US Air Force, other DoD, and Australian Defence Force clients to support technology development, acquisition, delivery and sustainment decisions.

The group provides the core of SPA thought leadership on Undersea Strategy, Software Development and Cost Estimating, with additional benchmark capabilities in AI/ML & Decision Analytics, Modeling and Simulation, and Future Force Assessments.

SPA has an immediate need for an IT Modernization Information Systems Security Engineer.

Responsibilities

The Senior Cloud Information Systems Security Engineer (SCISSE) will support the Government Program Manager by integrating cybersecurity requirements into system architecture, design, and engineering activities from concept through deployment. Working across the system lifecycle, the SCISSE will develop and maintain security artifacts, including Security Plans, Security Controls Traceability Matrices, architectural diagrams, and engineering documentation.

Responsibilities include performing security engineering analyses such as threat modeling, vulnerability assessments, and security impact analyses for proposed system changes. The SCISSE will select, tailor, and implement security controls in accordance with NIST SP 800-53, CNSSI 1253, the Joint SAP Implementation Guide, and other applicable cybersecurity frameworks.

To support informed decision-making, the SCISSE will communicate engineering risk assessments, including mitigation strategies, residual risks, and risk-benefit recommendations. The role also encompasses requirements analysis, system design, and integration for complex software applications and collaboration infrastructures.

As part of the configuration management process, the SCISSE will submit and review Change Requests while assessing the security implications of proposed modifications. Additional responsibilities include creating and maintaining information system security documentation, developing Standard Operating Procedures, and providing guidance on active Plans of Action and Milestones (POA&Ms).

The SCISSE will conduct continuous and periodic monitoring of systems, documentation, and operational procedures to ensure ongoing compliance with authorization requirements. Close collaboration with ISSOs, system administrators, and development teams will be essential to remediate vulnerabilities, maintain secure system configurations, and support secure engineering practices.

Working with multiple system owners, the SCISSE will address security-related design and integration requirements for hybrid environments while evaluating cloud technologies in areas such as encryption, identity and access management, boundary protection, logging, and monitoring. The position also supports incident response and forensic activities in coordination with cybersecurity teams and contributes to the development and execution of governance frameworks for managing and authorizing national security systems.

Qualifications

Required Qualifications:

  • Ability to support onsite in Lorton Virginia, up to full-time, based upon the needs of the client
  • Master’s degree in engineering, computer science, cybersecurity, networking, or programming
  • Requires experience working with Special Access Programs (SAPs), along with strong proficiency in cloud architecture and associated security elements
  • Must possess excellent analytical skills with the ability to quantify risk to enterprise systems and assess compliance with security policy, backed by 12+ years of technical experience in cybersecurity, information technology, or systems engineering
  • TS/SCI with CI Polygraph, and the ability to maintain this throughout employment

Advanced knowledge in one or more of the following areas:

  • Secure systems engineering practices, including threat modeling, security architecture design, and/or system hardening
  • Software Development in Java, Python, Ruby and/or C++
  • Linux Expertise
  • Dynamic & Static Application Security Scanning (e.g., OPSWAT, OWASP ZAP, BurpSuite, Fortify
  • Experience with vulnerability management tools (e.g., Tenable, Defender), SIEM technologies, and secure configuration baselines
  • Infrastructure Security Scanning, Vulnerability Scanning (NMAP, Azure Defender, AWS Inspector, ACAS/Nessus)
Certification Requirements In One Or More Of The Following
  • Information Systems Security Engineering Professional (ISSEP)
  • Certified Cloud Security Professional (CCSP)
  • Certified Information Systems Security Professional (CISSP)
  • CompTIA Advanced Security Practitioner (CASP)
  • GIAC Cloud Security Essentials Certification (GCLD)
Desired Qualifications
  • Strong oral and written communication Skills.
Pay Range Information

At SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities. SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work. The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc. Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. Virginia, Pay Transparency Salary range: USD $180,000.00/Yr. - USD $210,000.00/Yr.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Officer
Information Systems Security Officer

Arenatechnologies • Lorton (VA)

On-site
USD 180,000 - 210,000
Information Systems Security Engineer
Information Systems Security Engineer

Arenatechnologies • Colorado Springs (CO), Northern (KY)

Hybrid
USD 85,000 - 100,000
Health insurance
Retirement savings plans
Paid time off
Information Systems Security Specialist
Information Systems Security Specialist

Arenatechnologies • Washington

On-site
USD 160,000 - 180,000
Health insurance
Retirement plans
Health savings accounts
+2
Information Systems Security Manager
Information Systems Security Manager

Systems Planning and Analysis, Inc. • Arlington (VA)

On-site
USD 130,000 - 170,000
Information Systems Security Manager
Information Systems Security Manager

Systems Planning & Analysis • Arlington (VA)

On-site
USD 130,000 - 170,000
Health insurance
Flexible spending accounts
Health savings accounts
+3
Information Systems Security Manager
Information Systems Security Manager

Arenatechnologies • Arlington (VA)

On-site
USD 130,000 - 170,000
Health insurance
Retirement plan
Paid time off
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

Arenatechnologies • Lincoln (MA)

On-site
USD 180,000 - 215,000
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

Systems Planning & Analysis • Lincoln (MA)

On-site
USD 180,000 - 215,000
Health insurance
Retirement plans
Paid time off
Principal Cyber Systems Engineer
Principal Cyber Systems Engineer

Arenatechnologies • Washington

On-site
USD 135,000 - 195,000
Health insurance
Retirement plans
Paid time off
Information Systems Security Engineer
Information Systems Security Engineer

CareerArc • Colorado Springs (CO)

On-site
USD 85,000 - 100,000