View all jobs

Information Systems Security Engineer

  • McLean, Virginia

Expert ISSE 
$225K to $240K 
McLean, VA 

Position Overview

The Information Systems Security Engineer (ISSE) supports the client and program team in defining, implementing, and maintaining security requirements across the system lifecycle. This role advises on, executes, and oversees cybersecurity and Information Assurance (IA) programs, including Authority to Operate (ATO) processes, Assessment and Authorization (A&A) activities, User Activity Monitoring (UAM), and the development and maintenance of System Security Plans (SSPs). The ISSE works closely with system owners, ISSOs, and government stakeholders to ensure systems meet all applicable federal security requirements.

Key Responsibilities

  • Define, document, and advise on security requirements throughout the system development lifecycle (SDLC)
  • Lead and support Assessment and Authorization (A&A) packages in accordance with NIST Risk Management Framework (RMF)
  • Develop, maintain, and update System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POA&Ms)
  • Support and track systems through the Authority to Operate (ATO) process, coordinating with Authorizing Officials (AOs) and ISSMs
  • Design, implement, and monitor User Activity Monitoring (UAM) capabilities in compliance with insider threat program requirements
  • Conduct risk assessments and vulnerability analyses; recommend and implement mitigations
  • Ensure systems comply with applicable DoD/IC directives (e.g., DoDI 8510.01, ICD 503, NIST SP 800-53, CNSSI 1253)
  • Collaborate with ISSOs, engineers, and program management to integrate security controls into system architecture
  • Support continuous monitoring (ConMon) activities and maintain audit readiness
  • Prepare and present security documentation and briefings to government stakeholders

Required Qualifications

  • Active TS/SCI with Full Scope Polygraph
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field (equivalent experience may be considered)
  • [X]+ years of experience in information systems security engineering, IA, or cybersecurity within a DoD/IC environment
  • Working knowledge of NIST RMF, A&A processes, and ATO lifecycle
  • Experience developing SSPs, SARs, and POA&Ms
  • Familiarity with UAM tools and insider threat monitoring requirements
  • DoD 8570/8140 compliance (e.g., CISSP, CAP, Security+ CE, or equivalent certification)