Information Systems Security Engineer (ISSE) - TS required to apply - multiple locations DC, AL, WV, VA
Bow Wave LLC District of Columbia, United States · $105K–$185K/yr
Security and Investigations · 51-200 employees
About the role
Lead and supervise a team of security professionals in the end-to-end implementation of the RMF lifecycle for FBI IT systems. Serve as a principal technical advisor on cybersecurity, overseeing risk management, system authorization, and continuous monitoring activities.
What they look for
Requirements
Requires 8 years of experience in secure design, analysis, and testing of information security systems. Candidates must hold a CISSP or CEH certification, with cloud certification preferred.
Full description
Security (Cloud a plus) Engineer (ISSE)
Work Description:
- Lead, mentor, and supervise a team of contractor security professionals responsible for the end-to-end implementation of the RMF lifecycle for FBI IT systems.
- Oversee and coordinate activities within the Prepare step, ensuring roles, responsibilities, and risk management strategies are clearly defined and maintained.
- Guide system categorization efforts to ensure all information systems are appropriately classified based on mission/business impact and regulatory requirements.
- Advise on the selection, tailoring, and documentation of security controls aligned with system categorizations, Bureau risk appetite, and compliance requirements.
- Oversee the implementation of technical, operational, and management controls throughout system and application lifecycles, with a particular focus on quality and completeness of all deliverables.
- Ensure comprehensive security control assessments are planned, executed, and documented to validate the effectiveness of implemented safeguards.
- Prepare risk management documentation for system authorization and executive decision-making.
- Direct ongoing monitoring and continuous assessment activities, collecting metrics to adjust security strategies and ensure sustained compliance.
- Serve as a principal technical advisor on cybersecurity, bringing subject-matter expertise to risk analysis, incident response, system remediation, and audit support efforts.
- Foster a culture of security awareness, providing technical guidance and training to both team members and stakeholders.
- Track, report, and communicate status, risks, and improvement opportunities related to security engineering activities to leadership and stakeholders.
- Maintain up-to-date knowledge of RMF, NIST guidance, and industry best practices in support of continuous process improvement.
Required Experience/Skills/Certifications:
- 8 years of experience in secure design, analysis, and test of information security systems and products.
- 8 years of experience applying methods, standards and approaches for ensuring the baseline security safeguards are appropriately implemented and documented.
- 8 years of experience creating and updating security test plans for detecting and mitigating risk to information systems.
- Certified Information Systems Security Professional (CISSP) or Certified Ethical Hacker (CEH) certification required
- Cloud certification preferred
Similar roles
-
Senior Security Engineer - DevSecOps
carsales Sydney, New South Wales, Australia
-
Lead Cloud Security Engineer (DevSecOps)
Bilue Taguig, National Capital District, Philippines
-
Senior Security Engineer - Detection Engineering
LinkedIn United States · $129K–$212K/yr
-
Security Engineer
AlertMedia Austin, Texas, United States
-
F-35 Air Systems Information System Security Engineer | Active Secret clearance
General Dynamics Information Technology Eglin AFB, Florida, United States · $128K–$172K/yr
-
Full-Stack Engineers (Cybersecurity): Feedback On CI/CD Workflows
Terac United States · $218K/yr