CompQsoft, Inc.

Information Systems Security Engineer (Active DOD Secret Clearance required)

CompQsoft, Inc. Kittery, Maine, United States · $80K–$90K/yr

IT Services and IT Consulting · 501-1,000 employees

2 h ago
Remote security Senior (5-10 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The contractor will oversee the development and maintenance of system cybersecurity solutions and lead security control implementation and testing efforts. They are responsible for managing eMASS records, performing risk assessments, and ensuring compliance throughout the system lifecycle.

What they look for

Cyber Security RMF eMASS Security Control Assessment Vulnerability Assessment Risk Assessment System Categorization Security Plan Development Continuous Monitoring Test Planning Interoperability Testing Hardware Testing Software Testing DOD Secret Clearance CompTIA Security+

Requirements

Candidates must possess an active DOD Secret clearance and a CompTIA Security+ certification. Experience as an ISSE on Navy eMass projects is preferred, along with the ability to travel to the Portsmouth Naval Shipyard.

Full description

Description

Title: Information Systems Security Engineer (ISSE)

Location: Remote Work (Portsmouth Naval Shipyard, NH)

Duration: Full time

Clearance: Active DOD Secret

Client: Naval Sea Systems Command

Certification: CompTIA SEC+ CE or Equivalent

NOTE: Must willing to travel 2nd week of onboarding to Portsmouth Naval Shipyard (PNSY)

  • The contractor shall provide Cyber Security (CS) support. In performance of this task the contractor shall:
  • Oversee the development and maintenance of a system’s CS solutions.
  • Identify Authorizing Official (AO) and SCA cognizance (i.e. Functional Authoring Official or Navy Authorizing Official, and Functional Security Control Assessor or Security Control Assessor) of the system as well as any specific authorization requirements such as reciprocity, cross domain, and applicable overlays to support System Categorization.
  • Identify and tailor the security control baseline with applicable overlays.
  • Assist with development, maintenance, and tracking of the Security Plan.
  • Lead the security control implementation and testing efforts.
  • Perform vulnerability-level risk assessment on the POA&M/RISK Assessment Worksheet.
  • Assist with any security testing required as part of Assessment and Authorization (A&A) or annual reviews.
  • Assist in the mitigation and closure of open vulnerabilities under the system’s change control process.
  • Oversee CS testing to assess security controls and recording security control compliance status during the continuous monitoring phase of the lifecycle.
  • Make data entries into the eMASS record and POA&M consistent with implementation results.
  • Utilize the Collaboration Board in the eMASS workflow for all formal coordination during the RMF process. Detailed findings will be posted in the Artifacts tab (if necessary).
  • Rework shall be documented and provided to the Package Submitting Officer/Project Management Office for review.
  • Analyze the results of software, hardware, or interoperability testing.
  • Determine level of assurance of developed capabilities based on test results.
  • Develop test plans to address specifications and requirements.
  • Validate specifications and requirements for testability.
  • Make recommendations based on test results.
  • Perform developmental testing on systems under development.
  • Perform interoperability testing on systems exchanging electronic information with other systems.
  • Perform operational testing.
  • Test, evaluate, and verify hardware and/or software to determine compliance with defined specifications and requirements.
  • Record and manage test data.
  • Determine scope, infrastructure, resources, and data sample size to ensure system requirements are adequately demonstrated.
  • Address security implications in the software acceptance phase including completion criteria, risk acceptance and documentation, common criteria, and methods of independent testing.

Requirements

Candidates must have CompTIA Security+, active clearance, good communication, consistent engagement, and be willing to travel 2nd week of onboarding to Portsmouth Naval Shipyard (PNSY).

Past experience as an ISSE on Navy eMass Projects is a plus.

CompQsoft provides equal opportunity in all aspects of employment and in the working environment to all employees and applicants. CompQsoft does not take any non-merit factors like race, color, religion, sex (gender), mental/physical disability, and age into account for purposes of recruitment, hiring and development.

Similar roles