Information Systems Security Engineer (ISSE)
West 4th Strategy · $100K–$130K/yr
IT Services and IT Consulting · 51-200 employees
About the role
The ISSE will drive the full Risk Management Framework lifecycle for Facility-Related Control Systems to achieve and maintain Authorities to Operate. Responsibilities include conducting vulnerability assessments, maintaining security documentation, and serving as an active member of the Cyber Emergency Response Team.
What they look for
Requirements
Candidates must have at least 5 years of RMF experience, including 1 year specifically with Facility-Related Control Systems. A current DoDM 8140.03 compliant certification and an active Tier 5 security clearance are required.
Benefits
Full description
Information Systems Security Engineer (ISSE) ROLE We need an experienced Information Systems Security Engineer (ISSE) at Naval Facilities Engineering Systems Command (NAVFAC) Marianas Command Information Office (CIO). NAVFAC Marianas CIO ensures the confidentiality, integrity, and availability of systems, networks, and data supporting Facility-Related Control Systems across Guam military installations. In this role, you will drive the Risk Management Framework (RMF) lifecycle Steps 1 through 6, achieve and maintain Authorities to Operate for FRCS, develop security policies and SOPs aligned to NIST SP 800-53, execute vulnerability and compliance assessments, sustain continuous monitoring, and support incident response as a member of the MAR Cyber Emergency Response Team. This is a full-time opportunity. We can offer a competitive salary, and a comprehensive benefits package. Apply today!
RESPONSIBILITIES• Drive the full RMF lifecycle (Steps 1–6) for Facility-Related Control Systems, verifying system inventories and artifacts for compliance, completeness, and quality, and maintaining accurate records in the Enterprise Mission Assurance Support Service (eMASS)
- Execute ISSE activities to achieve and sustain Authorities to Operate (ATOs) for FRCS, including facilitating annual security reviews and drafting/submitting Memorandums for Record (MFRs) for system baseline changes
- Develop, author, and maintain security policies, standard operating procedures (SOPs), and implementation plans mapped to applicable NIST SP 800-53 control families, tailored to the FRCS operational environment
- Develop, maintain, and execute a comprehensive Vulnerability Management Strategy, including vulnerability and compliance assessments using approved tools (e.g., ACAS, SCAP, Evaluate STIG); perform manual STIG/SRG validations via .ckl/.cklb checklists; generate Security Center and eMASSter reports; and ensure scan results are uploaded and maintained in VRAM
- Sustain System-Level Continuous Monitoring (SLCM) operations, including routine vulnerability scans, audit log analysis, remediation/mitigation tracking, and accurate quarterly Plan of Action and Milestones (POA&M) updates
- Provide targeted on-site validation and testing support to satisfy RMF Step 4 requirements, coordinating with system owners and independent validators to ensure accurate technical evidence collection
- Serve as the technical representative and/or Configuration Management (CM) Officer on the Configuration Control Board (CCB), delivering authoritative security impact analyses and risk assessments for proposed FRCS baseline changes
- Serve as an operational member of the MAR Cyber Emergency Response Team (CERT), executing rapid incident response operations and participating in an on-call rotation to ensure continuous cyber defense coverage
- Deliver bi-weekly RMF status reports to the Information Systems Security Manager (ISSM); create, maintain, and update FRCS RMF project status records in Maximo and/or eProjects on a bi-weekly cadence; and produce a comprehensive Monthly Status Report covering project support, task coordination, and upcoming ATO milestones
BACKGROUND/REQUIRED EXPERIENCE• Minimum of 5 years of Risk Management Framework experience, including at least 1 year of specialized experience working on Facility-Related Control Systems (FRCS) performing RMF and cybersecurity engineering tasks
- Current certification satisfying DoDM 8140.03 Work Role Code 461 (Systems Security Analyst). One of: • Intermediate - CCSP, Cloud+, GICSP, GISF, GSEC, Security+
- Advanced - RCCE Level 1, CISSO, CISSP-ISSEP, CySA+, FITSP-O, GCLD, GCSA, GSNA
- Commitment to complete at least 20 hours annually of Continuing Professional Development (CPD)
- Demonstrated ability to operate independently with minimal government supervision
- Strong oral and written English communication skills, including the ability to author comprehensive technical reports, security policies, and procedures for government stakeholders, system owners, and the ISSM
- Physical ability to perform field duties, including long periods of standing, walking over rough or uneven surfaces, bending/crouching/stooping, climbing ladders, and lifting/moving IT equipment (up to 25 lbs), plus sufficient vision to identify safety concerns
- Reliable personal or company vehicle for routine local travel between Naval Base Guam and secondary sites (MCB Camp Blaz, Andersen AFB); mileage/commuting costs are not separately reimbursed
- Willingness to work on-site full time (no remote telework, situational/emergency exceptions only with COR approval) and to participate in an after-hours on-call rotation with flex-schedule offset (no overtime is authorized)
BACKGROUND/PREFERRED EXPERIENCE• Hands-on experience with eMASS, ACAS/Nessus, SCAP tools, and/or Evaluate STIG in a DoD or federal environment
- Prior experience securing Facility-Related Control Systems (FRCS), Industrial Control Systems (ICS), building automation, or other operational technology (OT) environments
- Experience supporting a Configuration Control Board (CCB) or serving in a Configuration Management (CM) capacity
- Familiarity with Maximo and/or eProjects for project and asset status tracking
- An Advanced-tier DoDM 8140.03 certification (e.g., CISSP-ISSEP, CySA+, GCSA, GSNA)
- Prior Navy, NAVFAC, or other DoD component RMF/ATO support experience
LOCATION• Bldg. 3190, Naval Base Guam, Santa Rita, Guam; regular travel to MCB Camp Blaz and Andersen AFB
CLEARANCE• Active Tier 5 (T5) security clearance, or the ability to obtain one prior to onboarding; ability to be issued a Common Access Card (CAC)
- Must be a US Citizen
CLIENT• NAVFAC, Marianas' Command Information Office (CIO)
HOURS• 40 hours per week
- 8 hours per day
EMPLOYMENT CLASSIFICATION• Employment Classification Eligibility – W2
RELOCATION• Not eligible for relocation benefits
COMPENSATION• Salary range: $100,000 – $130,000
- Benefits: Benefits package includes options for health, dental, and vision insurance coverage; 401k contribution options. Full benefits brochure available for review.
West 4th Strategy is an Equal Opportunity (EEO) employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, gender, sexual orientation, ancestry, national origin, age, marital status, mental disability, physical disability, medical condition, pregnancy, political affiliation, military or veteran status, or any other basis prohibited by federal or state law.
Other Considerations: This position is W-2 only; no Corp-to-Corp or 1099 candidates. Relocation will not be offered. This position requires access to Department of Justice facilities and systems. As a condition of employment, selected candidates must complete and receive favorable adjudication from a federal government background investigation as required by the U.S. Department of Justice. Individual’s primary workstation is located in an office area. The noise level in this environment is low to moderate. Regularly required to sit for extended periods up to 80% of the time; frequently required to move about to access file cabinets and use office equipment such as PC, copier, fax, telephone, cell phone, etc. Occasionally required to reach overhead, bend, and lift objects of up to 10 lbs. Specific vision abilities required by this job include the use of computer monitor screens up to 80% of the time.