OverviewLMI is seeking a skilledSenior Cybersecurity Information Systems Security Engineer (ISSE)to support US ArmyCapability Program Executive (CPE) Goundofficeat Ft. Belvoir, Virginia. The ISSE will drive efforts that support software and hardware cybersecurity Risk Management Framework (RMF) Authority to Operate (ATO).
This position requires an active Secret clearance and onsite presence at Ft. Belvoir, VA.
Responsibilities
Responsibilities:
- Collaborate with system engineers, program managers, and Authorizing Officials (or their delegates) to define and implement system security requirements.
- Lead efforts to ensure continuous monitoring and verification of cybersecurity requirements throughout the system lifecycle.
- Serve as a trusted cybersecurity advisor, providing guidance and recommendations to government stakeholders and contractor teams.
- Design, review, and refine system security architectures for cloud, on-premises, and hybrid environments.
- Support the Risk Management Framework (RMF) process to achieve andmaintainAuthority to Operate (ATO) approvals.
- Identify, track, and mitigate security control gaps and areas of non-compliance, ensuring alignment with security standards.
- Conduct risk assessments, vulnerability assessments, and develop andmaintaincritical documentation, such as System Security Plans (SSPs).
- Manage andfacilitateInterim Authority to Test (IATT) activities, risk assessments, and all ATO-related processes.
- Analyze and interpret security control deficiencies to assess their impact on enterprise risk levels and cybersecurity program effectiveness.
- Partner with the Information System Security Manager (ISSM) and product teams toidentifycontrol gaps, propose mitigations, and prepare Program of Action and Milestone (POAM) plans for ATO submission.
- Guide system engineers on the mitigation of vulnerability findings usingstate-of-the-artsecurity scanning tools, DoD policies, and industry best practices.
- Provide cybersecurity engineeringexpertisein evaluating alternatives, assessing trade-offs, and recommending risk treatment strategies.
- Collaborate with cross-functional teams to ensure the delivery of secure and dependable systems.
- Develop andmaintaindashboards tomonitorplatform system controls, logs, and compliance status, ensuring seamless reporting.
- Demonstrateexpertisein implementing cloud cybersecurity solutions and practices.
- Apply NIST SP 800-53 Revision 4 or 5 security controls and security assessment procedures from NIST SP 800-53A.
Core Knowledge, Skills, Abilities, and Tasks (KSATs) 6 DoD Cyber Workforce (DCWF):
- In-depth knowledge of computer networking concepts, protocols, and methodologies to ensure effective network security.
- Expertisein risk management processes, including methodologies foridentifying, assessing, and mitigating risks.
- Comprehensive understanding of national and international laws, regulations, policies, and ethical standardsimpactingcybersecurity operations.
- Proficient knowledge of core cybersecurity principles and best practices for protecting information systems and data.
- Awareness of cyber threats, vulnerabilities, and emerging attack vectors that could compromise systems and information.
- Strong understanding of the specific operational impacts that cybersecurity lapses can impose on systems, data integrity, and organizationalobjectives.
- Expertisein cloud computing service models, including Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS).
- Solid understanding of cloud computing deployment models, including private, public, hybrid, and the key differences between on-premises and off-premises environments.
- Knowledge of cloud computing deployment models in private, public, and hybrid environment and the difference between on-premises and off-premises environments.
Qualifications
Minimum Qualifications:
- Active SECRET security clearance (minimumrequirement).
- Bachelor27s degree in Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, or Software Engineering from an ABET-accredited or NCAE-C designated institution.
- 5+ years of hands-on experience in system and/or security engineering within U.S. Government systems.
- Practical experience working within government cloud platforms (e.g., Azure, Amazon C2S, Commercial Cloud, or GovCloud), including secure implementation of security planning, design, and operations.
- Proven ability to develop andmaintainRisk Management Framework (RMF) documentation, including System Security Plans (SSPs) and Plans of Action and Milestones (POAMs).
- Experience working with DoD technologies, systems, and command & control policies and procedures.
- Hands-on experienceutilizingEnterprise Mission Assurance Support Service(eMASS)for compliance management and reporting.
- Familiarity with federal IT security requirements, including DoD cyber regulations, FedRAMP, and FISMA compliance.
- Knowledge of DoD STIGs, SRGs, and security requirements outlined in NIST SP 800-53 and its corresponding assessment procedures.
- Strong communicationand interpersonal skills, capable of effectively interacting with both technical teams and non-technical stakeholders.
- One or more of the following certifications: GISF, Security+, CASP+, CSSP, Cloud+, CSSLP, GSEC, or GSEC-equivalent. (If not currently held, must obtain within the first 30 days of employment).
Preferred Additional Qualifications:
- Expertisein cloud security planning, design, and operations.
- Experience with systems engineering lifecycle processes and Agile development methodologies.
- Familiarity with Continuous Integration/Continuous Delivery (CI/CD) frameworks andDevSecOpspractices.
- Tactical military experience is strongly preferred.
Target salary range: $92,075 - $158,138.39
Disclaimer: The salary range displayed represents the typical salary range for this position and is not a guarantee of compensation. Individual salaries are determined by various factors including, but not limited to location, internal equity, business considerations, client contract requirements, and candidate qualifications, such as education, experience, skills, and security clearances.
#LI-SH1
Applicants must meet eligibility requirements for a U.S. Government security clearance. Only US Citizens are eligible for a security clearance. For this position, LMI will only consider applicants with security clearances or applicants who are eligible for security clearances, due to the nature of the work.
Job LocationsUS-VA-Fort Belvoir