Astrion

Information Systems Security Engineer (ISSE)

Astrion · Colombia

Defense and Space Manufacturing · 5,001-10,000 employees

17 h ago
Principal (10+ yrs) Full-time Colombia
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Information Systems Security Engineer will design, integrate, and implement security controls for classified information systems throughout their lifecycle. They are responsible for vulnerability management, continuous monitoring, and developing technical documentation to support system authorization.

What they look for

Information Systems Security Systems Engineering Linux Administration Windows Administration Security Architecture Vulnerability Assessment Configuration Management Risk Analysis Technical Writing Secure Software Development Assessment and Authorization Continuous Monitoring Nispm Rule Emass Daag Security Controls

Requirements

Candidates must hold a Bachelor's degree with 8-10 years of experience, including at least 5 years in Linux and Windows administration. A CAP, CISM, or CISSP certification is required, along with active TS/SCI eligibility.

Full description

Overview

Information Systems Security Engineer (ISSE)

LOCATION: Columbia, MD

JOB STATUS: Full-time

CLEARANCE: Ability to obtain TS/SCI

CERTIFICATION: CAP, CISSM, or CISSP

TRAVEL: Less than 5%

SALARY RANGE: $114K - $171K

Astrion has an exciting opportunity for an experienced Information Systems Security Engineer (ISSE) to securely engineer classified information systems throughout their lifecycle. The ISSE serves as the primary architect for the technical design, integration, and implementation of security controls in support of classified information management systems under 32 CFR Part 117 (NISPOM Rule). Further, the ISSE will design the secure networks based on instructions, manuals and policies as outlined in guidance from the DoW, Navy, and MDA; this position is located in Columbia Maryland.

REQUIRED QUALIFICATIONS / SKILLS

  • Bachelor’s degree with 8-10 years of experience.
  • Minimum of 5 years of experience in Linux and Windows administration.
  • Experience in supporting U.S. Government clients.
  • Be able to apply systems engineering knowledge to develop, implement and maintain a secure network environment.
  • A CAP, CISM, or CISSP certification is required.
  • U.S. citizenship with active TS/SCI eligibility and the ability to maintain such eligibility.

PREFERRED QUALIFICATIONS / SKILLS

  • Proficiency with Secure Internet Protocol Network establishment and maintenance.
  • Configuration management.
  • Vulnerability assessment and remediation.
  • Secure software development principles.
  • Risk analysis and technical writing.
  • Proficiency with various compute applications and testing tools (Word, Excel, PowerPoint, WASSP, MBSA).
  • Strong understanding of DCSA eMASS and DAAG processes.

RESPONSIBILITES:

  • Security Architecture and System Design – Integrate security requirements into system architecture during the planning and design phases.
  • Ensure system designs meet 32 CFR Part 117 (NISPOM Rule); and guidance as outlined in the DCSA Assessment and Authorization Guide (DAAG).
  • Research and recommend secure technologies and architectures to reduce risk.
  • Incorporate security engineering principles throughout the system development life cycle (SDLC).
  • Develop engineering artifacts required for Assessment & Authorization (A&A).
  • Assist with security control inheritance and control tailoring.
  • Support the development of Plans of Action and Milestones (POA&Ms).
  • Security Control Implementation - Design and implement technical security controls; ensure controls are implemented correctly and function as intended; validate implemented controls; work closely with system administrators to configure systems securely.
  • Vulnerability Management – Analyze vulnerabilities identified through tools such as; ACAS, SCAP, STIG Viewer Nessus, Security Assessments.
  • Recommend engineering solutions to mitigate identified risks.
  • Evaluate security impacts of hardware, software, and configuration changes.
  • Continuous Monitoring (ConMon) – Review security posture and system health.
  • Authorization Support – Develop technical documentation supporting system authorization.
  • Provide Engineering input for Security Plans, POA&Ms, and Configuration Management Plans.
  • Configuration and Change Management - Evaluate proposed system changes for security impact; Participate in Configuration Control Boards (CCBs).
  • Technical Advising - Advise program managers, system owners, and administrators on security implications of design decisions.
  • Collaboration – Work closely with ISSM, ISSO, Systems Administrators, DCSA Information System Security Professional (ISSP)