Information Systems Security Engineer with Top Secret Clearance
CALNET Inc. · Guam, United States
IT Services and IT Consulting · 11-50 employees
About the role
The Information Systems Security Engineer will manage the end-to-end Risk Management Framework lifecycle to ensure the security and compliance of Naval Facilities Engineering Systems Command networks. Responsibilities include executing vulnerability assessments, maintaining system authorities to operate, and providing incident response support as part of the cyber emergency response team.
What they look for
Requirements
Candidates must possess an active Top Secret clearance and a minimum of 5 years of experience in RMF and cybersecurity engineering. A bachelor's degree in Computer Science or IT and relevant industry certifications such as Security+ or CISSP are required.
Benefits
Full description
Founded in 1989, CALNET, Inc. has become one of the fastest growing privately held companies in the Technology, Intelligence Analysis, and Language Services consulting arena. Headquartered in Reston, VA, CALNET employees deliver true value to our customers by employing best practices, world-class technologies industry expertise in every project. CALNET is ISO 9001, ISO 20000, and CMMI-Level III certified
CALNET is looking for an Information Systems Security Engineer with a Top Secret Clearance to provide services to the Naval Facilities Engineering Systems Command (NAVFAC) Marianas Command Information Office (CIO), ensuring the confidentiality, integrity, and availability of systems, networks, and data through the planning, analysis, development, implementation, documentation, maintenance, and enhancement of information systems security programs, policies, procedures, and tools.
Job Requirements
- RMF Lifecycle Execution• drive the end-to-end Risk Management Framework (RMF) lifecycle (Steps 1-6) in strict accordance with the latest published Department of the Navy (DoN) and NAVFAC Echelon II guidance.
- This includes rigorously verifying system inventories and artifacts for compliance, completeness, and quality, and ensuring accurate formatting and upload into the Enterprise Mission Assurance Support Service (eMASS).
- Authority to Operate (ATO) Attainment & Maintenance• execute comprehensive ISSE activities to achieve, maintain, and track Authorities to Operate (ATOs) for Facility-Related Control Systems (FRCS).
- This includes facilitating comprehensive annual security reviews and drafting/submitting Memorandums for Record (MFRs) for system baseline changes during RMF Step 6.
- Policy & Procedure Development• develop, author, and maintain comprehensive security policies, standard operating procedures (SOPs), and implementation plans across all applicable NIST SP 800-53 security control families.
- This documentation must be tailored to the FRCS operational environment and ensure strict alignment with DoN and NAVFAC Echelon II cybersecurity directives.
- Vulnerability Management & Compliance Assessments• develop, maintain, and execute a comprehensive Vulnerability Management Strategy.
- execute vulnerability and compliance assessments using approved DoN tools (e.g., ACAS, SCAP, Evaluate STIG).
- perform manual STIG and Security Requirements Guide (SRG) validations (via .ckl/.cklb checklists), generate appropriately formatted Security Center and eMASSter reports for seamless eMASS integration, and ensure all vulnerability scan results are accurately uploaded and maintained within the Vulnerability Remediation Asset Management (VRAM) database.
- Continuous Monitoring • sustain robust System-Level Continuous Monitoring (SLCM) operations.
- Duties include conducting routine vulnerability scans, performing audit log analysis, driving vulnerability remediation/mitigation, and ensuring accurate, quarterly Plan of Action and Milestones (POA&M) updates.
- RMF On-Site Validation• deliver targeted on-site validation and testing support to satisfy RMF Step 4 requirements, actively coordinating with system owners and independent validators to ensure seamless site assessments and accurate technical evidence collection.
- Configuration Management• serve as a dedicated technical representative and/or Configuration Management (CM) Officer on the Configuration Control Board (CCB), providing authoritative security impact analyses and risk assessments for proposed FRCS baseline modifications.
- Incident Response Operations• execute rapid incident response operations in direct support of the NAVFAC CIO.
- serve as an operational member of the MAR Cyber Emergency Response Team (CERT), which mandates participation in designated on-call rotation schedules to guarantee continuous cyber defense coverage.
- Operational Coordination• dynamically prioritize and coordinate technical support across all FRCS environments, regardless of project type or phase.
- provide bi-weekly RMF status reports to the Information Systems Security Manager (ISSM).
- shall create, maintain, and update FRCS RMF project status records within Maximo and/or eProjects on a strict bi-weekly cadence.
Certifications (Required):
- Security+ or CCSP or Cloud+ or GICSP or GISF or GSEC or RCCE Level 1 or CISSO or CISSP-ISSEP or CySA+ or FITSP-O or GCLD or GCSA or GSNA
Typical Educational/Experience Requirements
- Bachelor’s degree in Computer Science, IT, or equivalent experience.
- US Citizen
- Active Top Secret Clearance
- Have a recommended minimum of 5 years of RMF experience and 1 year of specialized experience working on Facility-Related Control Systems (FRCS) performing Risk Management Framework (RMF) and cybersecurity engineering tasks.
- Have demonstrated the ability to operate independently with minimal government supervision.
- Have the ability to communicate in English fluently and effectively in oral and writing.
- Have demonstrated the ability to write comprehensive technical reports, security policies, and procedures, and communicate effectively with other governmental professionals, system owners, and the Information Systems Security Manager (ISSM).
- Be capable of the physical exertion required to perform the necessary services such as long periods of standing; walking over rough, uneven or rocky surfaces; recurring bending, crouching, stooping, and reaching; climbing upon ladders; lifting and moving IT equipment (up to 25 lbs); and other physical activity common to the performance of such duties and have sufficient vision to identify safety concerns.
- Be fully qualified in accordance with DoDM 8140.03 for Cyber Workforce Work Role 461 (Systems Security Analyst) at the intermediate or advanced proficiency level prior to onboarding.
This opportunity is onsite in Guam
CALNET, Inc. offers a competitive salary and a generous benefits package. This package includes medical, dental, vision, life, short- and long-term disability insurances, a 401(k)-retirement savings plan, and generous leave time.
CALNET, Inc. is an Equal Opportunity Employer. EEO/M/F/D/V