Information System Security Engineer II

TRISTAR

$88K — $105K *
Aerospace & Defense
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-9 years of experience in cybersecurity engineering or related fields.
  • Proficient in DoD Risk Management Framework (RMF) and security authorization processes.
  • Experience developing and maintaining RMF documentation in eMASS or similar tools.
  • Familiar with vulnerability assessment tools like ACAS/Nessus.
  • Knowledge of DISA STIGs and cybersecurity compliance requirements.
  • Ability to analyze security findings and propose remediation measures.
  • Bachelor's degree in a relevant technical field or equivalent experience.

Responsibilities

  • Develop and maintain RMF security authorization packages.
  • Support RMF lifecycle activities for various systems.
  • Create and manage essential cybersecurity documentation and artifacts.
  • Conduct assessments of security controls and track vulnerabilities.
  • Implement continuous monitoring strategies for compliance.
  • Perform vulnerability assessments and analyze scan results.
  • Troubleshoot cybersecurity compliance and configuration issues.

Benefits

  • Full-time position with potential for career growth.
  • Collaboration with a dynamic team of cybersecurity professionals.
  • Exposure to various technologies and security architectures.
  • Opportunity to work on Department of Defense systems.
  • Contributions to critical national security initiatives.
Full Job Description
Job Type

Full-time

Description

We are seeking a skilled Information System Security Engineer II to join our dynamic team. The Information System Security Engineer (ISSE) II provides mid-level cybersecurity and systems security engineering support for Department of Defense (DoD) systems throughout the system development, integration, testing, deployment, and sustainment lifecycle. The ISSE is responsible for implementing secure system architectures and configurations, developing and maintaining Risk Management Framework (RMF) documentation, assessing security controls, identifying and remediating cybersecurity vulnerabilities, and ensuring systems remain compliant with applicable DoD cybersecurity requirements.

The ISSE II serves as a technical liaison between software development, systems engineering, network administration, cybersecurity, and Information System Security Manager (ISSM) personnel. The position requires the ability to translate cybersecurity requirements into practical engineering solutions and work collaboratively with technical teams to resolve security and compliance deficiencies.

Key Responsibilities
  • Develop, update, maintain, and submit RMF security authorization packages within government repositories and tools, including eMASS.
  • Support systems throughout the RMF lifecycle, including categorization, security control implementation, assessment, authorization, and continuous monitoring.
  • Develop and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and other required cybersecurity artifacts.
  • Conduct security control assessments and assist in identifying, documenting, tracking, and remediating security deficiencies.
  • Develop and maintain continuous monitoring strategies to ensure systems remain compliant with established cybersecurity requirements.
  • Perform automated and manual vulnerability assessments using tools such as ACAS/Nessus, SCAP, and other approved vulnerability and compliance assessment tools.
  • Analyze vulnerability scan results and translate findings into actionable remediation requirements.
  • Apply DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) to operating systems, applications, databases, network infrastructure, containers, and other system components as applicable.
  • Troubleshoot and resolve cybersecurity compliance gaps, vulnerabilities, and configuration deficiencies.
  • Support the development and implementation of secure system architectures, security configurations, access controls, boundary protections, and defense-in-depth solutions.
  • Assist with the implementation and integration of security technologies, including ACAS, HBSS/ESS, Security Information and Event Management (SIEM) platforms, intrusion detection/prevention systems (IDS/IPS), firewalls, endpoint security tools, and other cybersecurity capabilities.
  • Serve as a technical liaison between software development and systems engineering teams and the ISSM, ensuring cybersecurity requirements are incorporated throughout the system lifecycle.
  • Participate in engineering change boards, configuration control boards, and technical reviews to evaluate proposed changes for potential cybersecurity impacts.
  • Review system designs, configurations, interfaces, and proposed modifications to ensure changes do not negatively impact the system's security posture or authorization boundary.
  • Provide cybersecurity engineering support during system integration, testing, deployment, and sustainment activities.
  • Analyze security logs and system data to identify anomalous activity, potential vulnerabilities, and indicators of compromise.
  • Provide technical support during cybersecurity incidents, investigations, and forensic activities as required.
  • Assist with security-related troubleshooting and root-cause analysis of system and network issues.
  • Coordinate with system administrators, network engineers, software developers, and other technical personnel to implement and verify security requirements.
  • Maintain technical documentation related to system security configurations, vulnerabilities, assessments, remediation activities, and security controls.
  • Monitor changes to applicable DoD cybersecurity policies, standards, and technical guidance and assist in incorporating new requirements into supported systems.
  • Provide technical recommendations to engineering and cybersecurity leadership regarding system security risks, vulnerabilities, and remediation strategies.
  • Support audits, inspections, assessments, and other cybersecurity compliance activities as required.
  • Perform other cybersecurity engineering and systems security support duties as assigned.


Requirements

  • 5-9 years of professional experience in cybersecurity engineering, systems engineering, network administration, information assurance, or a related technical discipline.
  • Experience supporting DoD Risk Management Framework (RMF) activities and security authorization processes.
  • Experience developing or maintaining RMF documentation and artifacts within eMASS or comparable government cybersecurity repositories.
  • Experience performing vulnerability assessments using ACAS/Nessus, SCAP, or similar cybersecurity assessment tools.
  • Working knowledge of DISA STIGs, SRGs, security controls, vulnerability remediation, and cybersecurity compliance requirements.
  • Experience with security configuration, hardening, and assessment of Windows, Linux, network, application, database, or other enterprise systems.
  • Understanding of system security engineering principles, secure configurations, defense-in-depth, access control, and network boundary protection.
  • Ability to analyze technical security findings and develop practical remediation solutions.
  • Strong written and verbal communication skills, with the ability to communicate technical cybersecurity requirements to both engineering and non-engineering personnel.
  • Ability to work independently while coordinating effectively with government customers, ISSMs, system administrators, software developers, engineers, and other stakeholders.
  • DoD 8570/8140 IASAE Level II or equivalent qualification.
  • Experience supporting systems through the full RMF lifecycle from system development through authorization and sustainment.
  • Experience with eMASS, Xacta, or other RMF/GRC platforms.
  • Experience with ACAS/Nessus, SCAP Compliance Checker, HBSS/ESS, SIEM, IDS/IPS, endpoint security, and vulnerability management platforms.
  • Experience applying DISA STIGs to Windows Server, RHEL/Linux, databases, applications, containers, network devices, and virtualized environments.
  • Experience supporting cybersecurity incident response, security investigations, or digital forensics.
  • Knowledge of DoD cybersecurity policies, including applicable DoD Instructions, DISA guidance, NIST publications, and RMF security control frameworks.
  • Bachelor's degree in Computer Science, Information Assurance, Cybersecurity, Systems Engineering, Information Technology, or a related technical field. Equivalent relevant professional experience may be considered in lieu of the degree on a case-by-case basis.
  • Must have or be able to obtain and present a CompTIA Security Plus certification prior to start date.
  • Ability to obtain and maintain a security clearance.
  • Must be a U.S. Citizen.


Similar Jobs

More Jobs at TRISTAR

More Aerospace & Defense Jobs

Find similar Information System Security Engineer II jobs: