Senior Information Systems Security Engineer (ISSE)

The Amatriot Group

Maryland

On-site

USD 150,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The Amatriot Group is seeking a Senior Information Systems Security Engineer to design, implement, and maintain enterprise security architecture in line with NIST RMF, DoD STIGs, and CIS benchmarks. You will lead security engineering across the system development lifecycle and support vulnerability management to keep systems secure.

Responsibilities include integrating cybersecurity requirements across Windows, Linux, cloud, virtualization, and containerized environments, and supporting

Qualifications

  • Experience designing and implementing enterprise security architecture.
  • Proven ability to perform security engineering across the SDLC.
  • Hands-on with Nessus, CyberArk, Splunk, and cloud security in DoD contexts.

Responsibilities

  • Design and maintain enterprise security architecture aligned with NIST RMF and DoD STIGs.
  • Lead vulnerability management programs and risk assessments.
  • Collaborate with DoD systems and ensure secure configuration baselines.
  • Provide technical leadership and mentoring to ISSE staff.

Skills

Security architecture
Security engineering
Cloud security
Kubernetes
DevSecOps
Scripting & automation
Project leadership

Tools

Tenable Nessus
ACAS
Qualys
CyberArk
Splunk Enterprise
VMware vSphere
GitLab
Windows Server
Red Hat Enterprise Linux
Ubuntu Linux
PowerShell
Python
Bash
Ansible

Job description

Location: Annapolis Junction, MD

Security Clearance: Active TS/SCI [Required]

Job Type: Full-Time

Target Salary Range*:$150,000 - $210,000

  • This represents the potential salary range for this position depending on education level, years of experience and/or certifications in addition to other position specific requirements which may impact salary
Position Overview

The Senior Information Systems Security Engineer designs, implements, and maintains enterprise security architecture aligned with NIST RMF, DoD STIGs, CIS benchmarks, and organizational cybersecurity policies. This role performs security engineering across the system development lifecycle, supports vulnerability management, integrates cybersecurity requirements across enterprise environments, and ensures development and operational systems are functional and secure.

Key Responsibilities
  • Security Architecture and Engineering
    Design, implement, and maintain enterprise security architecture aligned with NIST RMF, DoD STIGs, CIS benchmarks, and organizational cybersecurity policies.
  • Security Engineering across the system development lifecycle
    Perform security engineering activities across the system development lifecycle, including requirements analysis, system design reviews, security testing, and accreditation support.
  • Integration of cybersecurity requirements
    Integrate cybersecurity requirements into Windows and Linux server environments, cloud infrastructure, virtualization platforms, and containerized applications.
  • DoD IA architectures and systems
    Responsible for the design, development, implementation, and integration of DoD IA architectures, systems, or system components for use within computing, network, and enclave environments.
  • Architecture and design assurance
    Ensure the architecture and design of development and operational systems are functional and secure.
  • Program of record systems and interconnectivity
    Support designs for program of record systems and special purpose processing nodes with platform IT interconnectivity.
Vulnerability Management and Compliance
  • Implement vulnerability management processes using Tenable Nessus, ACAS, and Qualys to identify, assess, and remediate system vulnerabilities.
  • Remediation collaboration
    Collaborate with system administrators, network engineers, ISSOs, and application teams to remediate security findings and implement secure configuration baselines.
  • Security impact analysis
    Perform security impact analysis for system changes, software deployments, and infrastructure upgrades to ensure continued compliance and operational security.
  • Security requirements evaluation
    Determine security requirements by evaluating business strategies and requirements, researching information security standards, conducting system security and vulnerability analyses and risk assessments, studying architecture and platforms, identifying integration issues, and preparing cost estimates.
  • Cyber risk measurement framework
    Establish a framework by which cyber risk can be measured and quantified in the marketplace.
Security Monitoring, Incident Response, and Threat Detection
  • Incident response and forensics
    Support incident response and forensic investigations by analyzing security logs, SIEM alerts, network traffic, and endpoint telemetry using Splunk Enterprise.
  • Cyber event monitoring
    Monitor, analyze, and detect cyber events and incidents within information systems and networks under general supervision.
  • Integrated cyber defense
    Assist with integrated, dynamic cyber defense.
  • Security toolsets and continuous monitoring
    Coordinate and maintain security toolsets to support continuous monitoring and ongoing authorization programs.
  • Evaluate cybersecurity tools
    Evaluate and implement cybersecurity tools and technologies to improve system security posture, continuous monitoring, and threat detection capabilities.
Security Tools, Automation, and Endpoint Protection
  • Automation scripting
    Develop automation scripts using PowerShell, Bash, and Python to streamline vulnerability remediation, account auditing, compliance reporting, and security monitoring tasks.
  • Endpoint protection and hardening
    Engineer endpoint protection and hardening solutions using Trellix ePO On-Prem, host-based firewalls, and application whitelisting technologies.
  • Security systems implementation
    Implement security systems by specifying intrusion detection methodologies and equipment, directing equipment and software installation and calibration, preparing preventive and reactive measures, creating, transmitting, and maintaining keys, providing technical support, and completing documentation.
  • Test scripts and verification
    Verify security systems by developing and implementing test scripts.
  • CyberArk administration
    Administer, configure, and troubleshoot CyberArk core modules, including Enterprise Password Vault, Password Vault Web Access, Central Policy Manager, and Privileged Session Manager.
Documentation, Training, and Technical Leadership
  • Technical security documentation
    Produce technical security documentation, architecture diagrams, standard operating procedures, and executive-level risk assessment reports.
  • Security compliance monitoring
    Maintain security by monitoring and ensuring compliance with standards, policies, and procedures.
  • Incident response analyses
    Conduct incident response analyses.
  • Training program development
    Develop and conduct training programs.
  • Technical briefings to leadership
    Present technical briefings to leadership.
Qualifications
  • Strong background in networking, including TCP/IP, firewalls, and VPNs.
  • Strong background in cloud security, including AWS and Azure.
  • Strong background in Kubernetes and DevSecOps.
  • Deep understanding of NIST SP 800-161, NIST RMF, FedRAMP, Common Criteria, ATO package development, and cybersecurity compliance, including STIGs.
  • Hands-on experience managing and deploying Tenable Nessus, CyberArk, Trellix, Splunk Enterprise, VMware vSphere, GitLab, Microsoft Windows Server, Red Hat Enterprise Linux, and Ubuntu Linux.
  • Experience with scripting and automation using PowerShell, Python, Bash, and Ansible.
  • Proven experience leading projects and mentoring junior ISSEs.
Skills
  • Ability to design, implement, and maintain enterprise security architecture.
  • Ability to perform security engineering across the system development lifecycle.
  • Ability to integrate cybersecurity requirements across server, cloud, virtualization, and containerized environments.
  • Ability to perform security impact analysis for system changes, software deployments, and infrastructure upgrades.
  • Ability to produce technical security documentation, architecture diagrams, standard operating procedures, and executive-level risk assessment reports.
  • Ability to present technical briefings to leadership.

Certifications
  • DoD 8570.1-M / DoD 8140 IAT Level III certification, such as SecurityX, GCIH, CISA, or CISSP. [Required]
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Systems Security Engineer (ISSE)
Senior Information Systems Security Engineer (ISSE)

Amatriot Group, LLC • Glen Burnie (MD)

On-site
USD 150,000 - 210,000
Senior Information Systems Security Engineer (ISSE)
Senior Information Systems Security Engineer (ISSE)

Amatriot Group, LLC • Maryland

On-site
USD 150,000 - 210,000
Information System Security Engineer (ISSE)
Information System Security Engineer (ISSE)

Peraton • Maryland

On-site
USD 120,000 - 180,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

Arena Technical Resources, LLC (ATR) • Maryland

On-site
USD 120,000 - 150,000
Senior Information Systems Security Engineer – ISSE
Senior Information Systems Security Engineer – ISSE

Jobtailor • Maryland

On-site
USD 140,000 - 180,000
Information Systems Security Engineering (ISSE)
Information Systems Security Engineering (ISSE)

HRUCKUS • Maryland

On-site
USD 116,000 - 140,000
Jr Information System Security Engineer (ISSE)
Jr Information System Security Engineer (ISSE)

Peraton • Washington

On-site
USD 85,000 - 115,000
Information System Security Engineer
Information System Security Engineer

Navstar Inc. • Columbia (MD)

On-site
USD 140,000 - 190,000
ISSE 3 - Information Systems Security Engineer
ISSE 3 - Information Systems Security Engineer

InisCore Technologies • Maryland

On-site
USD 180,000 - 280,000
Information System Security Engineer (ISSE)
Information System Security Engineer (ISSE)

Peraton • Corridor North (MD)

On-site
USD 146,000 - 234,000