Senior Information System Security Engineer
Redhorse Corporation Chantilly, Virginia, United States · $140K–$160K/yr
IT Services and IT Consulting · 201-500 employees
About the role
The Senior Information System Security Engineer will provide expert technical and programmatic Information Assurance services to secure critical government network systems. Responsibilities include designing security requirements, conducting risk and vulnerability assessments, and managing comprehensive security documentation to ensure compliance.
What they look for
Requirements
Candidates must possess an active TS/SCI with FS Poly security clearance and a bachelor's degree in a relevant field. At least 8 years of experience in information assurance and certification and accreditation frameworks like NIST RMF is required.
Benefits
Full description
About the Organization
Now is a great time to join Redhorse Corporation. We are a solution-driven company delivering data insights and technology solutions to customers with missions critical to U.S. national interests. We’re looking for thoughtful, skilled professionals who thrive as trusted partners building technology-agnostic solutions and want to apply their talents supporting customers with difficult and important mission sets.
About the Role
Redhorse transforms the way government uses data and technology. To support this mission, we are seeking a Senior Information System Security Engineer (ISSE) to provide expert technical and programmatic Information Assurance (IA) services. In this role, you will be the cornerstone of security for our nation's most critical network and information systems. You will bridge the gap between complex technical requirements and business processes, ensuring that as we innovate, we remain compliant, secure, and resilient against evolving threats. Your work will directly impact the security posture of systems that handle vital government data.
\n
Key Responsibilities
- Provide technical and programmatic Information Assurance services to internal and external customers to support network and information security systems.
- Design, develop, and implement security requirements within the organization’s business processes.
- Prepare comprehensive security documentation utilizing accepted guidelines such as DITSCAP, DIACAP, and NIST SP 800-37.
- Develop and execute Security Test and Evaluation (ST&E) plans to verify the efficacy of security controls.
- Conduct complex risk and vulnerability assessments to identify system weaknesses and recommend mitigation strategies.
- Analyze existing policies and procedures against Federal laws and regulations, providing strategic recommendations to close compliance gaps.
- Develop, test, and integrate computer and network security tools to enhance system defense.
- Manage and complete System Security Plans (SSP) and Contingency Plans to ensure operational continuity.
- Perform vulnerability assessments and develop risk mitigation strategies to address identified deficiencies.
- Secure system configurations, install security tools, and scan systems to determine and report compliance results.
- Conduct security program audits and develop solutions to lessen identified risks.
- Provide IA support for the development and implementation of security architectures to meet new and evolving requirements.
- Assist in computer incident investigations and perform root cause analysis.
- Develop strategies to comply with privacy, risk management, and e-authentication requirements.
Required Experience/Clearance
- Must have an active TS/SCI with FS Poly security clearance
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- 8+ years of related experience performing information assurance and information systems security engineering duties.
- Demonstrated experience in the certification and accreditation (C&A) of information systems.
- Direct experience with NIST SP 800-37 (RMF), DIACAP, NIACAP, or DCID 6/3 frameworks.
- Proficiency in developing System Security Plans (SSP) and performing vulnerability scans.
Desired Experience We encourage all candidates who meet the basic requirements to apply, even if you do not have any of the following experience:
- Professional certifications such as CISSP, ISSEP, or CISM.
- Experience with modern cloud security environments (AWS, Azure, or Google Cloud).
- Familiarity with automated compliance tools and DevSecOps pipelines.
- Operational experience with DataBricks, GitLab, or Jira in a secure environment.
- Experience leading a team of junior security analysts or engineers.
\n$140,000 - $160,000 a year
\nThe salary range provided for this position represents the anticipated base salary for successful candidates. Actual compensation will be determined based on a variety of factors, including relevant experience, education, certifications, skills, security clearance level, geographic location, market conditions, and internal equity. In addition to base salary, eligible employees may participate in Redhorse's comprehensive benefits programs and may be eligible for performance-based or other incentive compensation, where applicable.
Redhorse Corporation is an equal opportunity employer. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status, disability, or any other protected class.
If you are a qualified individual with a disability or a disabled veteran, you may request a reasonable accommodation if you are unable or limited in your ability to access job openings or apply for a job on this site as a result of your disability. You can request reasonable accommodations by contacting Talent Acquisition at Talent-Acquisition@redhorsecorp.com
Redhorse Corporation shall, in its discretion, modify or adjust the position to meet Redhorse’s changing needs. This job description is not a contract and may be adjusted as deemed appropriate in Redhorse’s sole discretion.
Similar roles
-
Cybersecurity Intern
CLS Health PLLC Webster, Texas, United States
-
Security Engineer
SambaSafety United States · $130K–$150K/yr
-
Enterprise Account Exec (Cybersecurity)
ServiceNow São Paulo, Southeast, Brazil
-
Enterprise Account Exec - Cybersecurity (Armis/Veza)
ServiceNow Plano Piloto, Federal District, Brazil
-
Senior Corporate Security Engineer
Robinhood Menlo Park, California, United States · $129K–$195K/yr
-
Application Security Engineer (Full Scope Poly)
Concept Plus, LLC Reston, Virginia, United States