Cambridge International Systems Inc

Information Systems Security Engineer– Top-Secret Clearance|Charleston, SC

Cambridge International Systems Inc Charleston, South Carolina, United States

Technology, Information and Internet · 201-500 employees

20 h ago
security Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The Information Systems Security Engineer integrates cybersecurity into system architectures throughout the lifecycle to ensure compliance with RMF requirements. They collaborate with engineering teams to implement secure solutions, perform vulnerability assessments, and maintain technical cybersecurity documentation.

What they look for

Risk Management Framework Cybersecurity System architecture Vulnerability assessment NIST SP 800-53 DoD guidance eMASS ACAS Security control implementation Zero Trust Network security Cloud security Configuration management Technical documentation Incident response Compliance

Requirements

Candidates must have an active DoD Top-Secret clearance and at least five years of experience with a Bachelor's degree or seven years with a HS/GED. Proficiency in RMF, security assessment tools like ACAS/eMASS, and relevant DoD cybersecurity certifications is required.

Benefits

Medical insurance Dental insurance Vision insurance Life insurance Accident insurance Critical illness insurance 401(k) Paid time off Company holidays Tuition support Training support Relocation assistance Sign-on bonus Performance-based bonus Employee referral program Employee assistance program

Full description

Information Systems Security Engineer– Top-Secret Clearance|Charleston, SC Cambridge International Systems, Inc.

Join a dynamic global team united by shared values: commitment, integrity, and perseverance. At Cambridge, you’ll work alongside top talent worldwide, tackling some of today’s most complex and critical challenges in defense and security.

We are currently seeking an Information Systems Security Engineer to support operations in Charleston, SC. This is a full-time CONUS position requiring an active DoD Top-Secret clearance. 

What You’ll Do As an Information Systems Security Engineer, you will play a critical role in supporting the Naval Information Warfare Center Atlantic (NIWC Atlantic) Expeditionary Enterprise Systems and Services (E2S2) Division. NIWC Atlantic provides design, acquisition, and sustainment services for Marine Corps Systems Command (MCSC) Information Technology (IT) systems). The ISSE is responsible for integrating cybersecurity into system architectures throughout the system lifecycle, ensuring information systems comply with applicable government policies, cybersecurity standards, and Risk Management Framework (RMF) requirements. This role works closely with systems engineers, software developers, architects, ISSM/ISSO personnel, and government stakeholders to engineer secure, resilient solutions that support mission objectives while balancing security, performance, and operational requirements. This role falls under Cyber Security Engineer within our compensation framework. This position reports to Steve Dellinger.  You will:• The ideal candidate will have demonstrated experience supporting large-scale defense or space environments involving space systems, ground infrastructure, mission operations, communications networks, cloud environments, or enterprise information technology capabilities.

  • Integrate cybersecurity requirements into system architecture, engineering designs, interface specifications, and technical documentation throughout the system lifecycle.
  • Engineer, implement, and validate security controls in accordance with NIST RMF, NIST SP 800-53, CNSSI 1253, DoD guidance, and organizational cybersecurity policies.
  • Perform technical security analyses including architecture reviews, vulnerability assessments, threat analysis, risk assessments, attack surface analysis, and mitigation planning.
  • Participate in system architecture reviews, engineering design reviews, technical interchange meetings, and configuration control activities to ensure cybersecurity requirements are incorporated early in system development.
  • Develop and maintain technical cybersecurity documentation including System Security Plan (SSP) content, control implementation statements, security architecture diagrams, data flow diagrams, network diagrams, interface documentation, and engineering analyses.
  • Support development of Security Assessment Plans (SAPs), Security Assessment Reports (SARs), POA&Ms, continuous monitoring documentation, and other RMF artifacts supporting system authorization.
  • Identify cybersecurity gaps, architectural weaknesses, and technical risks, and develop practical engineering solutions to improve the overall security posture.
  • Collaborate with systems engineers, software developers, network engineers, cloud engineers, system administrators, and mission partners to establish and maintain secure configuration baselines.
  • Evaluate proposed system changes, software releases, technology insertions, and architecture modifications for cybersecurity impacts and accreditation implications.
  • Support vulnerability management activities including analysis of vulnerability scan results, prioritization of findings, remediation planning, and validation of corrective actions.
  • Participate in integration, testing, verification, validation, and accreditation activities to ensure implemented security controls function as intended.
  • Support continuous monitoring activities by assessing control effectiveness, monitoring security posture, and recommending improvements to maintain compliance.
  • Ensure secure integration of Commercial Off-the-Shelf (COTS), Government Off-the-Shelf (GOTS), open-source, cloud-based, and custom-developed technologies.
  • Provide technical cybersecurity guidance to engineering teams regarding secure system design, defense-in-depth strategies, Zero Trust principles, and cybersecurity best practices.
  • Prepare technical reports, engineering recommendations, risk assessments, and executive briefings supporting senior leadership and government decision-makers.
  • Plans, develops, and implements proven high-tech solutions to increase security and defend against hacking, malware and ransomware, insider threats, and other types of cybercrimes.
  • Oversees monitoring of computer networks, identifies security issues, and anticipates security breaches.
  • Executes the installation and maintenance of security programs, plans, and software, including firewalls and data encryption programs.

What You’ll Bring Required Qualifications: Must be proficient in using different technologies such as computers and other tools and systems pertinent to the position.• Education & Experience: • Five (5) years with Bachelor’s degree or seven (7) years with HS/GED of practical experience demonstrating competency in Cybersecurity, Engineering, Test & Evaluation (T&E) or Assessment & Authorization (A&A)/ Certification & Accreditation (C&A) related field.

  • Individual shall demonstrate a working knowledge of the Risk Management Framework (RMF) process and/or include prior experience with the
  • Defense Information Assurance & Certification Accreditation Process (DIACAP).
  • Individual shall have experience working with Information Assurance tools such as DISA Enterprise Mission Assurance Support Service (eMASS) or Assured Compliance Assessment Solution (ACAS) and may be required to hold an Interim Security Control Assessor qualification.
  • Individual shall be familiar with security policies & guidance documents to assist with the preparation and maintenance of process artifacts and traceability documents purposed for compliance with Authority to Operate (ATO) requirements. The specialist shall be capable of evaluating security solutions to ensure they meet security requirements for processing up to classified information, and supervise and/or maintain the operational security posture for an information system or program.
  • Individual shall have experience assisting or developing system security policy and ensuring compliance of change management and configuration control processes.
  • Technical Expertise: • Strong Trained in the skills and techniques related to engineering and/or software design/maintenance.
  • Possess Experience supporting Department of Defense, Intelligence Community, U.S. Space Force, or other classified government information systems
  • Demonstrated experience implementing and engineering NIST RMF security controls in accordance with NIST SP 800-37, NIST SP 800-53, CNSSI 1253, and applicable DoD cybersecurity guidance.
  • Strong understanding of secure systems engineering principles, security architecture, defense-in-depth, secure configuration management, and cybersecurity risk management.
  • Experience with operating systems, networking, virtualization, cloud technologies, identity and access management, encryption technologies, and modern cybersecurity solutions.
  • Experience conducting vulnerability assessments using tools such as ACAS, Nessus, SCAP, or comparable vulnerability management platforms.
  • Ability to produce high-quality engineering documentation, technical analyses, architecture recommendations, and RMF artifacts.
  • Security certification meeting DoD 8140 (or legacy DoD 8570) requirements, such as Security+, GSEC, CISSP, CASP+, or IASAE certifications.
  • Proficiency with Microsoft Office Suite, including Word, PowerPoint, Excel, Project, and Outlook.
  • Experience designing and implementing Zero Trust Architecture principles within enterprise or mission systems.
  • Experience supporting cloud security, hybrid cloud environments, containerized applications, Kubernetes, or DevSecOps pipelines.
  • Familiarity with Infrastructure as Code (IaC), automation, scripting, or configuration management tools such as PowerShell, Python, Ansible, or Terraform.
  • Experience performing security architecture reviews for large-scale, distributed, or systems-of-systems environments.
  • Advanced cybersecurity certifications such as CISSP-ISSEP, CCSP, CASP+, GIAC GSEC, or comparable engineering-focused certifications.
  • Experience supporting secure software development, software assurance, DevSecOps, or software factory environments.
  • Familiarity with DoD Enterprise DevSecOps Reference Design, Platform One, or cloud-native security technologies.
  • Excellent written and verbal communication skills with the ability to communicate complex cybersecurity concepts to technical teams, program leadership, and government stakeholders.
  • Clearance:• Must have a current and active DoD Top-Secret security clearance.

Physical & Work Environment Requirements• Periods of prolonged sitting and/or standing, including desk-based computer work.

  • Travel between work locations, including company offices, customer sites, and government installations.
  • Transport and use of work equipment, such as laptops and job-related tools, during site visits.
  • Work is performed in a secure facility where personal electronic devices (including Bluetooth- or Wi-Fi-enabled devices) may be restricted.
  • Work may be performed in industrial or potentially hazardous environments, including around heavy machinery and moving equipment.
  • Regular exposure to outdoor conditions and varying weather.
  • Physical activities may include bending, lifting, carrying, pushing, and pulling materials, consistent with established one-person lift guidelines.
  • Use of tools, equipment, and machinery as required for the role.
  • Work at elevated heights using ladders, scaffolding, boom lifts, or scissor lifts.
  • Communication with team members, customers, and stakeholders through verbal and written methods.
  • Ability to manage competing priorities, work under deadlines, and maintain attention to detail.
  • Interaction with others in dynamic environments, including situations requiring problem-solving and conflict resolution.

Background & Security• Employment is contingent upon successful background investigation

Benefits & Perks We believe in investing in our team—both professionally and personally:• Medical, dental, vision, life, accident, and critical illness insurance

  • 401(k) immediate vesting and match
  • Paid time off and company holidays
  • Generous tuition & training support
  • Relocation assistance
  • Sign-on and performance-based bonuses
  • Employee referral program
  • Access to Tickets at Work, EAP, wellness initiatives, and more

Join Us If you're driven by mission, technology, and teamwork—we want to hear from you. Cambridge is growing, and this position is just one of many opportunities on our global team. Know someone perfect for the role? Referrals are welcome—both employees and non-employees may qualify for a bonus. Apply today and help shape the future of secure cloud computing for national security.

About Cambridge International Systems At Cambridge, we recognize innovation and agility grow through teamwork. By working collaboratively, listening proactively, and engaging across functions we create solutions that build on the best ideas our employees bring to the table. We are committed to one another, to persevere in order to get the job done, and to do so with integrity every time. Learn more at www.cbridgeinc.com.

We are an equal opportunity employer.  Applicants and employees are considered for positions and are evaluated without regard to any protected status under applicable law or other similar factors that are not job-related.  We encourage all qualified individuals to apply for employment.  Selected applicants may be subject to a background investigation and/or education verification.

We provide reasonable accommodation for qualified individuals with disabilities in accordance with federal, state, and local law.  If you require a reasonable accommodation to participate in the application process or to perform the essential functions of the position, please contact our Recruiting Team at recruiting@cbridgeinc.com.

Similar roles