Information System Security Engineer (ISSE)

The Marlin Alliance

$95K — $125K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Information Systems, or related field
  • 3 to 5 years of experience in information systems security engineering or RMF/cybersecurity accreditation
  • DoD 8140 / IAM Level II certification: Active CISSP, CISM, CASP+, or CGRC
  • Experience navigating eMASS workflows and preparing IATT/ATO artifacts
  • Working knowledge of STIG assessment and remediation processes
  • Strong communication skills, with ability to convey technical concepts
  • US citizenship with active SECRET security clearance

Responsibilities

  • Serve as primary accountability for an assigned eMASS package
  • Lead Interim Authorization to Test (IATT) extension activities
  • Develop and maintain Plans of Action and Milestones (POA&Ms)
  • Conduct Security Technical Implementation Guide (STIG) assessments
  • Support Microsoft 365 DDIL testing from a security engineering perspective
  • Prepare and review authorization artifacts per RMF and DoD guidelines
  • Coordinate with Information System Security Managers for accreditation decisions
  • Monitor and report on security posture of assigned systems

Benefits

  • Career growth opportunities within a reputable organization
  • Working in a supportive team environment focused on cybersecurity excellence
  • Minimal travel requirements (up to 10%)
  • Active engagement with the Navy's cybersecurity initiatives
  • On-site position in San Diego, CA
Full Job Description
The Marlin Alliance is seeking a dedicated Information System Security Engineer (ISSE) to support a Navy client's cybersecurity accreditation efforts. This role will take ownership of an assigned eMASS package, driving the interim authorization process and supporting broader Risk Management Framework (RMF) compliance activities. The ISSE will also contribute to STIG assessments and remediation efforts, including support for Microsoft 365 DDIL (Disconnected, Denied, Intermittent, Limited) testing initiatives.

Location: San Diego, CA - On Site
Clearance: Active SECRET clearance required
Travel: Minimal travel may be required (up to 10%)

Responsibilities:
  • Serve as the primary point of accountability for an assigned eMASS package, ensuring accuracy and currency of all associated documentation
  • Lead and execute Interim Authorization to Test (IATT) extension activities to maintain continuity of testing authority
  • Develop, update, and maintain Plans of Action and Milestones (POA&Ms) in support of ongoing accreditation efforts
  • Conduct Security Technical Implementation Guide (STIG) assessments and coordinate remediation activities across relevant systems
  • Support Microsoft 365 DDIL (Disconnected, Denied, Intermittent, Limited) testing efforts from a security engineering perspective
  • Prepare and review authorization artifacts in accordance with RMF and DoD cybersecurity guidance
  • Coordinate with Information System Security Managers (ISSMs) and Authorizing Officials to support accreditation decisions
  • Monitor and report on the security posture of assigned systems, identifying and tracking vulnerabilities to closure
  • Assist in the development and maintenance of security control implementation documentation

Required Qualifications:
  • Bachelor's degree in Computer Science, Information Systems, or a related field
  • 3 to 5 years of experience in information systems security engineering or RMF/cybersecurity accreditation support
  • DoD 8140 / IAM Level II certification: Active CISSP, CISM, CASP+, or CGRC
  • Demonstrated experience navigating eMASS workflows, managing POA&Ms, and preparing IATT/ATO artifacts
  • Working knowledge of STIG assessment and remediation processes
  • Strong written and verbal communication skills, with the ability to convey technical concepts to diverse audiences
  • Ability to analyze technical challenges and contribute to effective solutions in a team environment
  • Must be a US citizen and possess an active SECRET security clearance

Preferred Qualifications:
  • Master's degree in Computer Science, Information Systems, or a related field
  • Experience supporting Microsoft 365 or other enterprise collaboration platform security assessments
  • Familiarity with DDIL (Disconnected, Denied, Intermittent, Limited) operational environments
  • Experience with automated STIG scanning and remediation tools (e.g., SCAP, ACAS)
  • Additional certification such as CGRC, CISM, or CASP+ beyond the minimum required

Work Environment and Mental/Physical Demands:

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this position. Reasonable accommodations may be made to enable individuals with disabilities to perform the functions.
  • Typical office environment with no unusual hazards
  • The noise level in the work environment is usually moderate
  • Constant sitting while using the computer terminal
  • Constant use of sight abilities while reviewing documents
  • Constant use of speech/hearing abilities for communication
  • Occasional reaching, stooping, kneeling, or crouching may be required
  • Occasional lifting up to 20 pounds
  • Constant use of mental alertness
  • Frequent work under deadlines

Job Classification:
Associate
$95,000 - $125,000

Disclaimer:

This job description in no way states or implies that these are the only duties to be performed by the employee(s) incumbent in this position. Employees will be required to follow any other job-related instructions and to perform any other job-related duties requested by any person authorized to give instructions or assignments. All duties and responsibilities are essential functions and requirements and are subject to possible modification to reasonably accommodate individuals with disabilities.

To perform this job successfully, the incumbents will possess the skills, aptitudes, and abilities to perform each duty proficiently. Some requirements may exclude individuals who pose a direct threat or significant risk to the health or safety of themselves or others. The requirements listed in this document are the minimum levels of knowledge, skills, or abilities.

This document does not create an employment contract, implied or otherwise, other than an "at-will" relationship.

Similar Jobs

More Jobs at The Marlin Alliance

More Information Technology Jobs

Find similar Information System Security Engineer (ISSE) jobs: