Logistics Management Institute

Cybersecurity Information System Security Engineer - Clearance Required

Logistics Management Institute$92K — $158K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Active SECRET security clearance required.
  • Bachelor's degree in IT, Cybersecurity, Computer Science, Information Systems, Data Science, or Software Engineering.
  • 5+ years of hands-on experience in system and/or security engineering for U.S. Government systems.
  • Experience with government cloud platforms (e.g., Azure, AWS C2S) and security operations.
  • Proven ability to maintain RMF documentation, including System Security Plans (SSPs).
  • Familiarity with DoD cyber regulations, FedRAMP, and FISMA compliance.

Responsibilities

  • Collaborate with engineers and program managers to define system security requirements.
  • Lead continuous monitoring and verification of cybersecurity requirements.
  • Serve as a cybersecurity advisor, guiding government stakeholders and contractor teams.
  • Design and refine system security architectures for various environments.
  • Support the RMF process for ATO approvals and compliance management.
  • Identify and mitigate security control gaps and non-compliance areas.
  • Conduct risk assessments and prepare critical security documentation.

Benefits

  • Comprehensive healthcare coverage.
  • 401(k) retirement plan with company match.
  • Professional development opportunities and training programs.
  • Flexible work schedules as applicable.
  • Generous paid time off and holiday policies.
Full Job Description
Overview

LMI is seeking a skilledSenior Cybersecurity Information Systems Security Engineer (ISSE)to support US ArmyCapability Program Executive (CPE) Goundofficeat Ft. Belvoir, Virginia. The ISSE will drive efforts that support software and hardware cybersecurity Risk Management Framework (RMF) Authority to Operate (ATO).

This position requires an active Secret clearance and onsite presence at Ft. Belvoir, VA.

Responsibilities

Responsibilities:

  • Collaborate with system engineers, program managers, and Authorizing Officials (or their delegates) to define and implement system security requirements.
  • Lead efforts to ensure continuous monitoring and verification of cybersecurity requirements throughout the system lifecycle.
  • Serve as a trusted cybersecurity advisor, providing guidance and recommendations to government stakeholders and contractor teams.
  • Design, review, and refine system security architectures for cloud, on-premises, and hybrid environments.
  • Support the Risk Management Framework (RMF) process to achieve andmaintainAuthority to Operate (ATO) approvals.
  • Identify, track, and mitigate security control gaps and areas of non-compliance, ensuring alignment with security standards.
  • Conduct risk assessments, vulnerability assessments, and develop andmaintaincritical documentation, such as System Security Plans (SSPs).
  • Manage andfacilitateInterim Authority to Test (IATT) activities, risk assessments, and all ATO-related processes.
  • Analyze and interpret security control deficiencies to assess their impact on enterprise risk levels and cybersecurity program effectiveness.
  • Partner with the Information System Security Manager (ISSM) and product teams toidentifycontrol gaps, propose mitigations, and prepare Program of Action and Milestone (POAM) plans for ATO submission.
  • Guide system engineers on the mitigation of vulnerability findings usingstate-of-the-artsecurity scanning tools, DoD policies, and industry best practices.
  • Provide cybersecurity engineeringexpertisein evaluating alternatives, assessing trade-offs, and recommending risk treatment strategies.
  • Collaborate with cross-functional teams to ensure the delivery of secure and dependable systems.
  • Develop andmaintaindashboards tomonitorplatform system controls, logs, and compliance status, ensuring seamless reporting.
  • Demonstrateexpertisein implementing cloud cybersecurity solutions and practices.
  • Apply NIST SP 800-53 Revision 4 or 5 security controls and security assessment procedures from NIST SP 800-53A.

Core Knowledge, Skills, Abilities, and Tasks (KSATs) 6 DoD Cyber Workforce (DCWF):

  • In-depth knowledge of computer networking concepts, protocols, and methodologies to ensure effective network security.
  • Expertisein risk management processes, including methodologies foridentifying, assessing, and mitigating risks.
  • Comprehensive understanding of national and international laws, regulations, policies, and ethical standardsimpactingcybersecurity operations.
  • Proficient knowledge of core cybersecurity principles and best practices for protecting information systems and data.
  • Awareness of cyber threats, vulnerabilities, and emerging attack vectors that could compromise systems and information.
  • Strong understanding of the specific operational impacts that cybersecurity lapses can impose on systems, data integrity, and organizationalobjectives.
  • Expertisein cloud computing service models, including Software as a Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS).
  • Solid understanding of cloud computing deployment models, including private, public, hybrid, and the key differences between on-premises and off-premises environments.
  • Knowledge of cloud computing deployment models in private, public, and hybrid environment and the difference between on-premises and off-premises environments.

Qualifications Minimum Qualifications:

  • Active SECRET security clearance (minimumrequirement).
  • Bachelor27s degree in Information Technology, Cybersecurity, Computer Science, Information Systems, Data Science, or Software Engineering from an ABET-accredited or NCAE-C designated institution.
  • 5+ years of hands-on experience in system and/or security engineering within U.S. Government systems.
  • Practical experience working within government cloud platforms (e.g., Azure, Amazon C2S, Commercial Cloud, or GovCloud), including secure implementation of security planning, design, and operations.
  • Proven ability to develop andmaintainRisk Management Framework (RMF) documentation, including System Security Plans (SSPs) and Plans of Action and Milestones (POAMs).
  • Experience working with DoD technologies, systems, and command & control policies and procedures.
  • Hands-on experienceutilizingEnterprise Mission Assurance Support Service(eMASS)for compliance management and reporting.
  • Familiarity with federal IT security requirements, including DoD cyber regulations, FedRAMP, and FISMA compliance.
  • Knowledge of DoD STIGs, SRGs, and security requirements outlined in NIST SP 800-53 and its corresponding assessment procedures.
  • Strong communicationand interpersonal skills, capable of effectively interacting with both technical teams and non-technical stakeholders.
  • One or more of the following certifications: GISF, Security+, CASP+, CSSP, Cloud+, CSSLP, GSEC, or GSEC-equivalent. (If not currently held, must obtain within the first 30 days of employment).

Preferred Additional Qualifications:

  • Expertisein cloud security planning, design, and operations.
  • Experience with systems engineering lifecycle processes and Agile development methodologies.
  • Familiarity with Continuous Integration/Continuous Delivery (CI/CD) frameworks andDevSecOpspractices.
  • Tactical military experience is strongly preferred.

Target salary range: $92,075 - $158,138.39

Disclaimer: The salary range displayed represents the typical salary range for this position and is not a guarantee of compensation. Individual salaries are determined by various factors including, but not limited to location, internal equity, business considerations, client contract requirements, and candidate qualifications, such as education, experience, skills, and security clearances.

#LI-SH1

Applicants must meet eligibility requirements for a U.S. Government security clearance. Only US Citizens are eligible for a security clearance. For this position, LMI will only consider applicants with security clearances or applicants who are eligible for security clearances, due to the nature of the work.

Job LocationsUS-VA-Fort Belvoir

About Logistics Management Institute

Logistics Management Institute (LMI) is a consulting firm dedicated to improving the management of government. LMI provides leaders with the objective analysis, tools, and programs they need to make informed decisions for their organizations. LMI is a not-for-profit organization that has been providing innovative solutions to complex problems since 1961. LMI serves clients in the federal government, state and local governments, and the private sector.
Learn more about Logistics Management Institute
Size
1,700 employees
Industry

Similar Jobs

More Jobs at Logistics Management Institute

More Aerospace & Defense Jobs

Find similar Cybersecurity Information System Security Engineer - Clearance Required jobs: