Senior Information Systems Security Engineer

ECS

Washington (District of Columbia)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

ECS is seeking a Senior Information Systems Security Engineer in Washington, D.C., to support a crucial federal cybersecurity program. This role involves leading the Security Assessment and Authorization program and working on various risk management activities.

The ideal candidate will need a Top Secret clearance and extensive experience in cybersecurity practices. Strong verbal and written communication skills are essential to work effectively with diverse stakeholders.

Qualifications

  • 8+ years of experience in secure information systems.
  • Experience with security controls and risk management.
  • Strong understanding of federal cybersecurity policies.

Responsibilities

  • Lead Security Assessment and Authorization program.
  • Support Risk Management Framework activities.
  • Advise on security controls implementation.

Skills

Active Top Secret clearance with SCI eligibility
U.S. citizenship
Secure design, analysis, and testing of information security systems
Application of cybersecurity methods and standards
Creating or updating security test plans
Experience with RMF and Security Assessment
Understanding of NIST SP 800-53 and FISMA
Assessing technical security evidence
Written and verbal communication skills
Coordination with stakeholders
CISSP or CEH certification

Tools

Tenable Nessus
Splunk
AWS
Azure
Google Cloud

Job description

Job Description

ECS is seeking an experienced Senior Information Systems Security Engineer to support a mission‑critical federal cybersecurity program in the National Capital Region or Huntsville, Alabama. This role provides senior‑level cybersecurity engineering support for Security Assessment and Authorization, Risk Management Framework execution, technical control implementation, security assessment, continuous monitoring, vulnerability remediation, audit readiness, and risk management for federal information systems.

Please note: This position is contingent upon contract award.

The selected candidate will coordinate with system owners, ISSOs, ISSMs, engineering teams, program leadership, and authorization stakeholders to strengthen authorization package quality, reduce technical control gaps, improve evidence completeness, and support timely, defensible risk‑based decisions. Depending on assignment, the ISSE3 may support division‑level security engineering, resource and project coordination, or new cloud technology security activities.

Key Responsibilities
  • Lead and support implementation of the Security Assessment and Authorization program for assigned federal information systems.
  • Support RMF activities across the Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor phases.
  • Guide system categorization based on mission impact, classification, FIPS 199 categorization, hosting environment, technical complexity, data sensitivity, and applicable federal cybersecurity requirements.
  • Advise on the selection, tailoring, implementation, testing, and documentation of security controls aligned to system risk posture and authorization needs.
  • Develop, review, and improve RMF and SAA artifacts, including System Security Plans, control implementation descriptions, security assessment plans, security test plans, risk assessments, POA&Ms, continuous monitoring artifacts, inventories, network diagrams, data flow diagrams, and authorization packages.
  • Support security control assessments by reviewing technical and procedural controls, validating evidence, identifying gaps, documenting findings, and supporting risk‑based recommendations.
  • Identify technical control gaps, assess risk, recommend remediation strategies, and coordinate corrective actions with system owners, engineers, ISSOs and ISSMs.
  • Support vulnerability remediation activities, including scan result analysis, POA&M development, remediation tracking, control impact analysis, and response to vulnerability reporting requirements.
  • Support FISMA audit preparation, documentation quality reviews, evidence validation, audit response packages, and corrective action planning.
  • Review proposed technical changes for security impact, compliance implications, architecture alignment, vulnerability exposure, and required mitigation.
  • Support cloud‑hosted, hybrid, or newly introduced technologies, including review of cloud control implementation, architecture, inherited controls, and authorization evidence, as assigned.
  • Develop or improve templates, checklists, SOPs, evidence standards, control implementation guidance, dashboards, and repeatable processes to improve quality, consistency, and efficiency.
  • Track and communicate risks, findings, remediation status, assessment progress, documentation quality, schedule concerns, and improvement opportunities to program leadership and stakeholders.
  • Mentor cybersecurity personnel and help drive complex security engineering activities to closure.
Required Skills
  • Active Top Secret clearance with SCI eligibility.
  • U.S. citizenship.
  • Minimum of 8 years of experience in secure design, analysis, and testing of information security systems and products.
  • Minimum of 8 years of experience applying cybersecurity methods, standards, and approaches to ensure baseline security safeguards are properly implemented and documented.
  • Minimum of 8 years of experience creating or updating security test plans for detecting, assessing, and mitigating risk to information systems.
  • Experience supporting RMF, Security Assessment and Authorization, ATO, continuous monitoring, security control implementation, security assessment, POA&M management, and authorization package development.
  • Strong understanding of NIST SP 800‑53, NIST SP 800‑53A, FIPS 199, FIPS 200, CNSS requirements, FISMA, vulnerability management, and federal cybersecurity policy.
  • Experience assessing technical security evidence and developing risk‑based recommendations for decision makers.
  • Strong written and verbal communication skills, including the ability to explain technical risks, evidence gaps, remediation options, and authorization impacts to technical and non‑technical stakeholders.
  • Ability to coordinate across system owners, engineering teams, ISSOs, ISSMs, program leadership, and authorization stakeholders.
  • CISSP or CEH certification required.
Desired Skills
  • Cloud certification preferred.
  • Experience with AWS, Azure, Google Cloud, hybrid cloud environments, cloud authorization, cloud‑native security services, control inheritance, and cloud security documentation.
  • Experience supporting classified federal environments, federal law enforcement systems, national security systems, intelligence systems, or high‑impact mission systems.
  • Experience with GRC platforms, control inheritance, evidence reuse, dashboard reporting, workflow automation, and security documentation repositories.
  • Experience with tools such as Tenable Nessus, Security Center, Splunk, IBM Guardium, WebInspect, Nmap, or similar cybersecurity platforms.
  • Experience leading or mentoring cybersecurity teams in a high‑accountability federal mission environment.
  • Experience developing reusable templates, checklists, SOPs, evidence standards, and process improvements that improve authorization quality and reduce rework.
Equal Opportunity Statement

ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis of any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Systems Security Engineer SME
Information Systems Security Engineer SME

ECS • Stafford (VA)

On-site
USD 120,000 - 150,000
Senior Information Systems Security Engineer
Senior Information Systems Security Engineer

ECS • Huntsville (AL)

On-site
USD 90,000 - 130,000
Information System Security Engineer SME
Information System Security Engineer SME

ECS • Washington

On-site
USD 175,000 - 190,000
Information System Security Officer Sr. (Cloud)
Information System Security Officer Sr. (Cloud)

ECS • Washington

On-site
USD 120,000 - 150,000
Information System Security Engineer
Information System Security Engineer

Navstar Inc. • Columbia (MD)

On-site
USD 140,000 - 190,000
Cyber Security Systems Engineer
Cyber Security Systems Engineer

VTG Defense • Chantilly (VA)

On-site
USD 120,000 - 160,000
Cyber Security Systems Engineer
Cyber Security Systems Engineer

VT Group (VTG) • Chantilly (VA)

On-site
USD 100,000 - 140,000
Cleared On Site Sr. Information Systems Security Engineer (ISSE) (5363)
Cleared On Site Sr. Information Systems Security Engineer (ISSE) (5363)

SMX • United States

On-site
USD 126,000 - 212,000
Health insurance
Paid leave
Retirement
Information Systems Security Engineer
Information Systems Security Engineer

VTG Defense • Huntsville (AL)

On-site
USD 100,000 - 130,000
Information Systems Security Engineer
Information Systems Security Engineer

VT Group (VTG) • Huntsville (AL)

On-site
USD 100,000 - 130,000