Information Systems Security Engineer
Spear AI Washington, District of Columbia, United States
Defense and Space Manufacturing · 51-200 employees
About the role
The Information Systems Security Engineer will design and integrate security architectures for classified information systems while ensuring compliance with RMF and IC directives. They will also manage the body of evidence for ATO packages and provide technical security guidance for AI/ML pipelines and development environments.
What they look for
Requirements
Candidates must possess an active TS/SCI clearance and meet DoW 8570/8140 IASAE Level II compliance. Strong hands-on expertise in NIST RMF, system hardening, and vulnerability management within classified environments is required.
Benefits
Full description
We are seeking an Information Systems Security Engineer (ISSE) to design, build, and integrate security into all information systems supporting the program, serving as the hands-on technical expert who translates Intelligence Community security requirements into engineered, implemented, and validated solutions.
Spear AI is a growing defense contracting company dedicated to delivering cutting-edge solutions that support our nation's security. As we expand, we're building a culture where innovation meets mission-critical work. We operate with a flat organizational structure that empowers every team member to make an impact, collaborate directly with leadership, and contribute to projects that matter. Whether you're joining our Hardware, Software, or Services division, you'll work alongside talented professionals who are committed to excellence and advancing the capabilities that keep our nation safe and secure.
Spear AI builds sonobuoy sensors that are deployed into the water and collect edge data. We also work with the U.S. Navy to collect and process their SONAR data. You'll have an opportunity to work on real-world projects that directly impact warfighter capabilities and mission success.
What you'll do
We're a small team wearing many hats, and you'd have a wide variety of responsibilities that include:
- Design and engineer security architectures for program information systems, ensuring security is built in from the ground up rather than bolted on
- Translate RMF, ICD 503, CNSSI 1253, and NIST SP 800-53 requirements into implemented, testable technical controls across multiple classified systems
- Develop and maintain the body of evidence supporting ATO packages — system security plans, control implementation details, test results, and supporting artifacts — in partnership with the ISSM and ISSOs
- Harden systems to DISA STIG and IC baselines; run and remediate vulnerability scans (ACAS/Nessus, SCAP) across the environment
- Integrate security into the development pipeline (DevSecOps), advising engineers on secure design, secure coding, and control implementation early in the lifecycle
- Engineer and tune continuous monitoring, auditing, and logging capabilities for classified systems
- Assess security impacts of proposed system changes and support configuration management boards
- Engineer security for AI/ML pipelines and data platforms, addressing emerging threats unique to model training, data ingestion, and edge deployment
- Support incident response with technical analysis, containment engineering, and remediation
- Coordinate with ISSM/ISSO staff, system owners, and government security stakeholders to keep engineering decisions aligned with mission requirements and applicable directives
Important Skills
- Active TS/SCI required; must be able to obtain a Polygraph.
- Hands-on expertise implementing NIST RMF, ICD 503, CNSSI 1253, and NIST SP 800-53 controls in classified environments
- Demonstrated experience engineering systems through ATO — building the technical body of evidence, not just documenting it
- Strong background in system hardening, vulnerability management, and security tooling (STIGs, SCAP, ACAS/Nessus) on JWICS or similar classified networks
- Experience with secure architecture design across cloud, on-prem, and cross-domain environments
- DoW 8570/8140 IASAE Level II compliance required (Level III preferred)
Nice to have
- Experience securing AI/ML systems and data pipelines
- AWS GovCloud or Azure Government security engineering experience
- DevSecOps tooling experience (container security, pipeline scanning, IaC security)
- Cross Domain Solution (CDS) integration experience
- Military Intelligence or IC experience
Why work with us
- We ship — We don't work on 18-month projects that are irrelevant before they're even finished.
- Our work has impact — We build products that are deployed to U.S. submarines and integrate with the sonobuoys we manufacture.
- We're growing responsibly — We have the resources to hire a lot more people, but we don't want to build a massive team of people who don't share our values.
- We're profitable — We aren't burning through cash trying to make the business work. But we also have investors who believe in us and are committed to our success.
- We care about doing great work — You don't need permission to sweat the details here.
- We don't take ourselves too seriously — We're building products that make the world safer. But we don't let that get to our heads.
What we offer
- Unlimited PTO — Take the time you need to recharge and maintain work-life balance.
- Dedicated Sick Time — Your health and well-being come first.
- Comprehensive Health & Benefits – Medical, dental, and vision coverage to keep you and your family protected.
- 11 Paid Holidays — Enjoy time off throughout the year to celebrate and spend time with loved ones.
- Professional Development — Educational opportunities and resources to help you grow your skills and advance your career.
- Collaborative Environment — Work directly with leadership in our flat organizational structure, where your ideas and contributions matter.
- Mission-Driven Work — Contribute to projects that directly support national security and make a real-world impact.
- Growth Opportunities — Join us during an exciting expansion phase where you can help shape our future.
Additional benefit opportunities when you choose Spear AI
- 401(k) with company match.
- Onsite / Remote / Flexible work arrangements or hybrid options (position dependent).
- Relocation assistance (position dependent).
- Referral bonuses.
- Performance bonuses.
- Life insurance and disability coverage.
- Technology home office setup stipend.
- Professional certification reimbursement (position dependent).
Compensation
We offer competitive compensation tailored to your experience, location, and the impact you'll make. We're committed to equitable pay and will share a range aligned to your level and geography during the hiring process. In accordance with state law, candidates in jurisdictions such as CA, CO, WA, NY, and others, where applicable, will be provided a good-faith salary range upon request and throughout the hiring process. This is a full-time, exempt position under the Fair Labor Standards Act (FLSA) and is not eligible for overtime pay.
Compensation for this position is provided on a salaried basis and is not subject to reduction based on hours worked. At Spear AI, you'll find more than just a job; you'll join a mission-driven team where your work directly contributes to national security. Our flat organizational structure means your voice matters, your ideas reach leadership, and your impact is visible. As we grow, we're committed to building robust processes and infrastructure that support both our mission and our people. We value collaboration, continuous improvement, and the expertise each team member brings to the table. If you're looking for a place to grow professionally while working on projects that truly matter, we'd love to hear from you.
Similar roles
-
Security Engineer
Applied Network Solutions Inc Linthicum, Maryland, United States · $100K–$200K/yr
-
Security Engineer with Akamai WAF
Syncreon Consulting New York, New York, United States
-
Cyber Security Engineer
UL Solutions Northbrook, Illinois, United States · $96K–$130K/yr
-
OT Network & Security Engineer
Vulcan Elements Research Triangle Park, North Carolina, United States
-
Senior Security Engineer, Access Security
Google New York, New York, United States · $174K–$252K/yr
-
Senior Security Engineer
Zepz United Kingdom