Job DescriptionDefend the systems that power the Pacific mission 🌴SOSi is seeking a talented
Information System Security Engineer (ISSE) to lead cybersecurity engineering efforts supporting critical operations at Joint Base Pearl Harbor-Hickam. In this high-impact role, you'll drive RMF compliance, architect secure solutions, and help safeguard mission systems across a dynamic and evolving threat landscape. Join a collaborative cyber team where your expertise directly contributes to national security and operational readiness throughout the Indo-Pacific region.
Essential Job Duties:- Design, review, and implement cybersecurity architecture and engineering solutions supporting enterprise and mission systems.
- Integrate security requirements into system design, development, testing, implementation, and sustainment activities.
- Support and lead RMF activities throughout the authorization lifecycle, including categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
- Develop, review, and maintain RMF documentation including System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms).
- Evaluate system changes, upgrades, and new capabilities to determine cybersecurity impacts and authorization requirements.
- Validate implementation of NIST SP 800-53 security controls and DISA Security Technical Implementation Guides (STIGs).
- Conduct cybersecurity architecture reviews, security engineering analyses, and technical risk assessments.
- Analyze ACAS, Tenable, Nessus, and SCAP assessment results and coordinate remediation efforts with system administrators and engineering teams.
- Develop and implement continuous monitoring strategies to maintain cybersecurity compliance and authorization status.
- Participate in Configuration Control Boards (CCBs), Technical Review Boards (TRBs), and engineering working groups.
- Provide technical guidance and cybersecurity recommendations to system owners, ISSOs, ISSMs, and senior leadership.
- Support cybersecurity inspections, Security Control Assessor (SCA) assessments, and Command Cyber Readiness Inspections.
- Evaluate interconnections, data flows, and system architectures to identify security risks and recommend mitigations.
- Track vulnerability remediation efforts and maintain POA&M activities to meet organizational and regulatory requirements.
- Support implementation and adoption of Zero Trust principles and cybersecurity modernization initiatives.
- Prepare technical reports, executive summaries, and briefing materials for leadership decision-making.
QualificationsMinimum Requirements:- Active Secret clearance with the ability to obtain and maintain a Top-Secret clearance.
- Must meet DoD 8140 qualification requirements for DCWF 652 Security Architect Intermediate (Primary)
- Bachelors Degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering // OR // GMON, SecurityX, CCSP, CISSO, Cloud+, CSSLP, FITSP-D, GCSA, or GSEC.
- DCWF 461 Systems Security Analyst Intermediate (Secondary)
- Bachelors Degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering // OR // CCSP, Cloud+, GICSP, GISF, GSEC, or Security+.
- Six (6) years of experience supporting cybersecurity, information assurance, systems engineering, or RMF-related activities.
- Experience supporting DoD Assessment and Authorization (A&A) or RMF processes.
- Experience with eMASS and maintenance of RMF authorization packages.
- Experience implementing and assessing NIST SP 800-53 security controls.
- Experience with ACAS, Tenable Security Center, Nessus, SCAP, and vulnerability management processes.
- Working knowledge of Windows, Linux, networking, virtualization, and enterprise information systems.
- Strong communication skills with the ability to engage both technical and non-technical stakeholders.
Preferred Qualifications:- Active Top Secret clearance with SCI eligibility.
- CISSP certification.
- CISSP-ISSEP, CCSP, CGRC, SecurityX (formerly CASP+), or CSSLP certification.
- Experience supporting Combatant Command, Navy, or Joint operational environments.
- Experience with Zero Trust Architecture implementation.
- Knowledge of Cross Domain Solutions (CDS) and Commercial Solutions for Classified (CSfC).
- Experience with cloud security technologies and hybrid cloud environments.
- Experience conducting cybersecurity architecture reviews and secure design assessments.
- Experience using JIRA, Confluence, ServiceNow, or similar collaboration and workflow platforms.
- Experience supporting Security Control Assessor reviews and ATO renewals.
Additional InformationWork Environment:- Working conditions are normal for an office environment.
- Fast paced, deadline-oriented environment.
- May require periods of non-traditional working hours including consecutive nights or weekends.