Omm IT Solutions

Information Systems Security Engineer (ISSE)

Omm IT Solutions · Sånta Rita-Sumai Municipality, Guam, United States

IT Services and IT Consulting · 11-50 employees

Yesterday
Senior (5-10 yrs) Full-time Contractor United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The ISSE manages the end-to-end Risk Management Framework lifecycle and maintains Authorities to Operate for facility-related control systems. They also conduct vulnerability assessments, perform continuous monitoring, and provide technical support for incident response.

What they look for

Risk Management Framework Cybersecurity Engineering Vulnerability Management eMASS ACAS Nessus STIG Configuration Management Incident Response NIST SP 800-53 NIST SP 800-82 Facility-Related Control Systems Operational Technology Security Compliance Audit Log Analysis

Requirements

Candidates must have at least 5 years of RMF experience and a minimum of 1 year of specialized experience with Facility-Related Control Systems. A DoD Cyberspace Workforce certification and an active Top Secret security clearance are mandatory.

Full description

PLEASE NOTE:

  • IT IS 100 % ON SITE POSITION in Santa Rita
  • Primary Work Location: NAVFAC Marianas, Building 3190, Naval Base Guam (NBG), Santa Rita, Guam 96915
  • Secondary Sites: Marine Corps Base Camp Blaz (MCBCB), Andersen Air Force Base (AAFB), Guam
  • Employment Terms: Full-Time (40 hours/week, standard business hours; 100% in-person; remote telework not authorized)
  • Clearance: Active Tier 5 (T5) Top Secret security clearance
  • Must be a United States citizen.
  • Must maintain a Privately Owned Vehicle

POSITION OVERVIEW

The Information Systems Security Engineer (ISSE) provides critical cybersecurity engineering and Risk

Management Framework (RMF) execution services for the Naval Facilities Engineering Systems Command

(NAVFAC) Marianas CIO. Operating in a specialized Operational Technology (OT) and Facility-Related Control

Systems (FRCS) environment, the ISSE plays an essential role in driving end-to-end RMF lifecycles, maintaining

Authorities to Operate (ATOs), managing vulnerabilities, and safeguarding mission-critical physical

infrastructure networks across military installations in Guam.

KEY RESPONSIBILITIES & ESSENTIAL TASKS

1. RMF Lifecycle Execution & ATO Maintenance

  • Drive end-to-end Risk Management Framework (RMF) lifecycle execution (Steps 1–6) in strict
  • alignment with DoN and NAVFAC Echelon II directives.
  • Format, verify, and upload system inventories, security controls, and compliance artifacts into the
  • Enterprise Mission Assurance Support Service (eMASS).
  • Facilitate annual security reviews and author Memorandums for Record (MFRs) for system baseline
  • modifications to attain and maintain Authorities to Operate (ATOs) for FRCS assets.

2. Vulnerability Management & Compliance Assessments

  • Develop and execute an overarching Vulnerability Management Strategy tailored to the FRCS
  • operational environment.
  • Conduct automated scanning and compliance checks using DoN-approved tools (e.g., ACAS/Nessus,
  • SCAP, Evaluate STIG).
  • Perform manual STIG and Security Requirements Guide (SRG) validations (.ckl / .cklb files), generate
  • Security Center and eMASSter reports, and upload scan results to the Vulnerability Remediation Asset
  • Management (VRAM) database.

3. Continuous Monitoring & Configuration Management

  • Sustain System-Level Continuous Monitoring (SLCM) by analyzing audit logs, driving vulnerability
  • mitigations, and updating quarterly Plan of Action and Milestones (POA&M) reports.
  • Serve as a technical representative and Configuration Management (CM) Officer on the Configuration
  • Control Board (CCB), providing authoritative security impact analyses and risk assessments.

4. On-Site Validation, Incident Response & Operational Coordination

  • Provide on-site technical testing and validation support to satisfy RMF Step 4 requirements in
  • coordination with independent validators.
  • Serve as an operational member of the MAR Cyber Emergency Response Team (CERT), participating in
  • on-call rotation schedules and authoring After-Action Incident Response (IR) reports.
  • Provide bi-weekly RMF progress reports to the Information Systems Security Manager (ISSM) and
  • update FRCS project records in Maximo and/or eProjects.

Requirements

REQUIREMENTS & SKILL SETS

Experience & SME Qualifications

  • General RMF Experience: Recommended minimum of 5 years of hands-on Risk Management

Framework (RMF) experience.

  • FRCS Specialization: Minimum of 1 year of specialized experience working on Facility-Related Control

Systems (FRCS) performing RMF and cybersecurity engineering tasks.

  • Independent Execution: Demonstrated ability to operate independently with minimal government

supervision.

  • Formal Degree: A formal college degree

DoD Cyberspace Workforce (CWF) Certification (DoDM 8140.03 WRC 461)

Must possess at least one (1) active baseline commercial certification satisfying Work Role Code 461 (Systems

Security Analyst) prior to onboarding:

  • Intermediate Level (Minimum): Security+, CCSP, Cloud+, GICSP, GISF, or GSEC.
  • Advanced Level (Automatically Qualifies): CISSP-ISSEP, CYSA+, RCCE Level 1, CISSO, FITSP-O, GCLD,
  • GCSA, or GSNA.
  • Requirement: Complete a minimum of 20 hours annually of Continuous Professional Development
  • (CPD) to keep credentials active.

Technical Tools & Environment Knowledge

  • Platforms & Databases: eMASS, VRAM, eMASSter, Maximo, eProjects.
  • Scanning & Analysis Tools: ACAS (Nessus), SCAP Compliant Scanners, Evaluate STIG, .ckl/.cklb STIG
  • Viewer checklists.
  • Frameworks & Standards: NIST SP 800-53 control families, NIST SP 800-82 (ICS/OT), DoN/NAVFAC
  • Echelon II business rules, SRGs/STIGs.

Physical Requirements & Local Transportation

  • Capable of physical exertion typical of industrial and FRCS sites: long periods of standing, walking over
  • rough/uneven surfaces, bending, crouching, climbing ladders, and lifting IT equipment up to 25 lbs.
  • Must maintain a Privately Owned Vehicle (POV) or company vehicle for required local commuting
  • between sites across Guam (expenses are non-reimbursable as a cost of doing business).