Your Mission:Join ClearPoint as an
Information System Security Engineer III, where you will lead the security engineering and accreditation work behind
MERIDIAN, our AI-Enabled Secure Space Operations & Management Platform. You will work closely with internal and external stakeholders to build security into the system throughout its lifecycle, reviewing architecture, testing the system as it's built, and shaping controls alongside engineers concurrently with development and implementation.
You will own the RMF package for MERIDIAN's implementation, from SSP and SAR development through POA&M management and continuous monitoring, while staying technically engaged with the platform as it evolves.
You Will Excel in This Role If You Are:- Experienced leading RMF/ATO efforts for classified DoD or IC systems
- Comfortable reviewing and shaping secure system architecture alongside engineers, not just documenting it after the fact
- Skilled in vulnerability assessment and security testing of live systems
- Familiar with NIST SP 800-53 and DoD RMF processes at an implementation level
- Capable of translating security findings into concrete, actionable remediation guidance
- Comfortable balancing compliance documentation with ongoing hands-on technical engagement
- Experienced mentoring less experienced security staff
A Day in the Life:- Develop and maintain SSP, SAR, and POA&M documentation for RMF accreditation
- Review system architecture and provide security guidance to engineers during design and development
- Conduct vulnerability scans and security assessments of the system as it's built
- Identify security weaknesses and recommend system-level remediation
- Implement and manage security controls, including identity/RBAC, audit logging, and encryption
- Track and drive remediation of findings identified during security assessment
- Mentor junior security staff and provide technical guidance
What We Are Expecting From You:- Active TS/SCI with Polygraph clearance; U.S. citizenship
- Bachelor's degree in Computer Science, Software Engineering, or related field (4 years of experience may substitute), plus 8 years of experience in information systems
- 5-8 years of experience as an ISSE or Cybersecurity Engineer
- Proficiency with networking, firewalls, and security monitoring tools
- Knowledge of operating systems, system security design, risk analysis, and security policies
- Experience with NIST Risk Management Framework (RMF) or DoD 8500 series compliance
- Experience reviewing and shaping secure system architecture alongside development teams
- Experience conducting vulnerability assessments and security testing
Nice to Have:- Experience embedding security into CI/CD pipelines and DevSecOps workflows
- Familiarity with container and cloud security tooling
- Experience with automated security scanning (SAST/DAST) as part of the development lifecycle
- Experience with cryptography, encryption technologies, and application security
- Experience with penetration testing
- Experience with physical security or facility accreditation practices, such as ICD 705 or similar frameworks