Cybersecurity Engineer III
INFORMATION SYSTEMS SOLUTIONS, INC San Diego, California, United States · $140K–$150K/yr
IT Services and IT Consulting · 201-500 employees
About the role
The Cybersecurity Engineer III supports Assessment and Authorization (A&A) accreditation efforts and maintains cybersecurity monitoring operations. They are responsible for identifying vulnerabilities, recommending remediation strategies, and developing comprehensive A&A documentation.
What they look for
Requirements
Candidates must have at least 10 years of experience in cybersecurity or incident response and hold an IAM II certification. A Secret clearance is required, along with proficiency in the Risk Management Framework.
Benefits
Full description
Description
Information Systems Solutions (ISS) is seeking a Cybersecurity Engineer III to support the NIWC PAC Information Technology Management Support Services contract. The Cybersecurity Engineer III will be responsible for supporting Assessment and Authorization (A&A) accreditation efforts. This role maintains cybersecurity monitoring operations, performs triage to assess the scope and impact of incidents, identifies vulnerabilities, and recommends remediation strategies. The role requires in-depth knowledge of the Risk Management Framework.
100% onsite
Key Responsibilities:
· Test and apply security controls based on security categorization, the application of overlays (privacy, classified, intel, etc.) and security control tailoring (AI, NOFORN, etc.).
· Conduct active and passive reconnaissance of data, with the ability to assess and author Plans of Milestones and Actions (POA&Ms) containing accurate and verifiable mitigation statements, milestone tracking, and applying to the most relevant security control.
· Development of comprehensive required A&A documentation, including System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Reports (SARs), etc.
· Adherence to the eMASS scheduled tasking within the accreditation cycle, including Quarterly Independent Verification and Validation (IV&V), quarterly STIG checks, Annual Security Review (ASR), monthly POA&M updates, and resubmission for ATO, ATC, IATC and IATT as applicable.
· Maintenance of DISA circuit connections (CCSDs), inheritance from accredited systems and cloud service providers, and the workflow schedule on accreditations.
Why Work For ISS?
At ISS we pride ourselves on providing an employee-focused and family first environment. Being a small business, we take the time to get to know our employees and have a vested interest in helping them achieve their career goals. We work to schedule regular social gatherings within the company to foster camaraderie. ISS values their employees by providing a comprehensive benefits package that includes a fully vested 401(k) matching program, coverage of family medical deductibles, spot bonuses, and educational assistance to further your career.
Requirements
Clearance Level:
Secret
Certification: IAM II
One of the following:
CAP
CASP CISM CISSP (or Associate)
GSLC
Required Qualifications:
· 10+ years of experience in cybersecurity or incident response
· Certifications preferred: Certified Information Systems Security Professional (CISSP)
Skills & Competencies:
· Cybersecurity Monitoring and Incident Response
· Security Testing, Auditing, and Remediation
· Data Analytics and Risk Assessment
· Proficiency with IT Security Software and Web Security Tools
Similar roles
-
Lead Security Engineer, GRC
Anduril Industries Boston, Massachusetts, United States · $166K–$253K/yr
-
Information Security Engineer (R14207)
Oportun Mexico
-
Principal Application Security Specialist
Global Relay Vancouver, British Columbia, Canada · CA$125K–CA$160K/yr
-
HSM & PKI Security Engineer
CCDS Dammam, Eastern Province, Saudi Arabia
-
Security Engineer
Warp New York, New York, United States · $230K–$290K/yr
-
Product Security Engineer
YipitData (Alternative) United States · $180K/yr