Senior Information Systems Security Engineer

ECS Corporate Services

Huntsville (AL)

On-site

USD 170,000 - 190,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Everforth ECS Federal in Huntsville, AL is seeking a Senior Information Systems Security Engineer to support RMF activities across federal information systems. The role requires eight or more years of experience in secure design, analysis, and testing, plus active Top Secret clearance with SCI eligibility.

You will mentor junior staff, coordinate with stakeholders, and ensure continuous monitoring, audit readiness, and secure architecture in a government contracting environment.

Qualifications

  • Eight or more years of experience in secure design, analysis, and testing of information security systems and products.
  • Eight or more years of experience applying security methods, standards, and approaches to ensure baseline security safeguards are implemented and documented.
  • Eight or more years of experience creating or updating security test plans to detect and mitigate risk to information systems.

Responsibilities

  • Serve as a senior security engineering advisor for federal information systems across the RMF lifecycle.
  • Provide support for RMF activities, including Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor.
  • Advise on secure architecture, control implementation, vulnerability remediation, least privilege, and data flows.
  • Maintain artifacts like System Security Plans, POA&Ms, risk assessments, and network diagrams.
  • Track authorization schedules, control gaps, and remediation activities to maintain compliant authorizations.
  • Develop and update security test plans and assessment approaches to detect and mitigate risk.
  • Coordinate vulnerability management, patching, and audit readiness activities.
  • Provide input for compliance, emergency directives, vulnerability reporting, and continuous monitoring.
  • Coordinate with stakeholders to resolve security issues and improve authorization quality.
  • Mentor junior staff in RMF and security engineering best practices; build team capability.
  • Identify recurring risks and recommend practical improvements to strengthen security processes.

Skills

RMF
NIST SP 800-53
Vulnerability assessment
Security testing
System Security Plans
Security authorization
Briefing stakeholders

Job description

Everforth ECS Federal is seeking a Senior Information Systems Security Engineer to work in our Huntsville, AL office. Please Note: This position is contingent upon contract award. Salary Range: $170,000 - $190,000

Responsibilities
  • Serve as a senior security engineering advisor for assigned federal information systems throughout the Security Assessment and Authorization lifecycle.
  • Provide technical security engineering support for Risk Management Framework activities, including Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor.
  • Advise system owners, security officers, security managers, and technical teams on secure architecture, control implementation, vulnerability remediation, least privilege, least functionality, system boundaries, data flows, and interconnections.
  • Support development, review, and maintenance of security authorization artifacts, including System Security Plans, control implementation descriptions, Plans of Action and Milestones, risk assessments, network diagrams, data flow diagrams, hardware/software inventories, and assessment evidence.
  • Help ensure assigned systems maintain compliant authorizations by proactively tracking authorization schedules, documentation status, control gaps, and remediation activities.
  • Develop and update security test plans and assessment approaches to detect, document, and mitigate risk to information systems.
  • Support vulnerability and patch management activities by tracking technical findings, coordinating remediation approaches, and helping ensure remediation actions are managed to closure.
  • Provide technical input for federal cybersecurity compliance, emergency directive, vulnerability reporting, audit readiness, and continuous monitoring activities.
  • Coordinate with cybersecurity, engineering, infrastructure, and mission stakeholders to resolve technical security issues and improve security authorization execution quality.
  • Mentor junior and mid-level cybersecurity personnel by providing technical guidance, reviewing work products, sharing RMF and security engineering best practices, and helping build team capability across assigned systems and portfolios.
  • Contribute to portfolio and program improvements by identifying recurring risks, documentation gaps, process inefficiencies, automation opportunities, and lessons learned, then recommending practical improvements to strengthen security authorization quality, timeliness, and consistency.
  • Track, report, and communicate security risks, remediation status, documentation quality issues, and improvement opportunities to program leadership and government stakeholders.

Maintain current knowledge of NIST RMF, NIST SP800-53 Rev.5, NIST SP800-53A, FISMA, CNSS, DOJ, IC, and other applicable federal cybersecurity guidance.

Active Top Secret clearance with SCI eligibility. Ability to meet federal law enforcement and national security suitability, access, and polygraph requirements. U.S. citizenship required; no dual citizenship.

Requirements
  • Eight or more years of experience in secure design, analysis, and testing of information security systems and products.
  • Eight or more years of experience applying security methods, standards, and approaches to ensure baseline security safeguards are implemented and documented.
  • Eight or more years of experience creating or updating security test plans to detect and mitigate risk to information systems.
  • Experience supporting RMF, Security Assessment and Authorization, ATO, POA&M, vulnerability management, audit readiness, and security control implementation activities.
  • Experience working with technical teams to translate security requirements into practical system, network, cloud, or infrastructure configurations.
  • Strong written and verbal communication skills, including the ability to brief risks, findings, recommendations, and remediation plans to technical and non-technical stakeholders.
  • CISSP or CEH certification required.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Systems Security Engineer
Senior Information Systems Security Engineer

ECS • Huntsville (AL)

On-site
USD 90,000 - 130,000
Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS Corporate Services • Huntsville (AL)

On-site
USD 155,000 - 168,000
Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS Corporate Services • Washington

On-site
USD 155,000 - 170,000
Top Secret clearance eligibility
US citizenship
Senior Information Systems Security Engineer
Senior Information Systems Security Engineer

ECS • Washington

On-site
USD 120,000 - 150,000
Senior RMF Cybersecurity Engineer | ATO & Risk Expert
Senior RMF Cybersecurity Engineer | ATO & Risk Expert

ECS Corporate Services • Huntsville (AL)

On-site
USD 170,000 - 190,000
Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS • Stafford (VA)

On-site
USD 120,000 - 150,000
Senior Information Systems Security Engineer
Senior Information Systems Security Engineer

MANTECH • Huntsville (AL)

On-site
USD 110,000 - 160,000
Senior Information Systems Security Engineer
Senior Information Systems Security Engineer

ECS Corporate Services • Washington

On-site
USD 120,000 - 170,000
Senior Cybersecurity Professional
Senior Cybersecurity Professional

Modern Technology Solutions, Inc. • Huntsville (AL)

On-site
USD 120,000 - 150,000
Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS Corporate Services • Clarksburg (WV)

On-site
USD 150,000 - 164,000