Information System Security Engineer

Unisity, LLC

$120K — $145K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years of experience as an ISSE on large technical programs.
  • Strong understanding of security practices and hands-on vulnerability testing.
  • Experience with Risk Management Framework application.
  • Proficient in formulating and assessing IT security policy.
  • Knowledgeable in common security tools like Nessus and NMAP.
  • Familiar with secure configurations for desktop and server operating systems.
  • Excellent verbal and written communication skills.

Responsibilities

  • Validate and verify system security requirements for large-scale systems.
  • Identify and implement appropriate information security architectures.
  • Recommend technical solutions based on security architecture standards.
  • Assess and mitigate system security threats throughout the program life cycle.
  • Collaborate with internal technical experts to address security issues quickly.
  • Lead security planning, assessment, and risk management activities.
  • Analyze system implementation against security compliance policies.

Benefits

  • Company contributes 12% to 401k with no employee match requirement.
  • Eligible for various medical plan options including HSAs.
  • Vision and dental coverage with additional funds provided for benefits.
  • Company-paid life and AD&D benefits.
  • Company-paid short and long-term disability coverage.
Full Job Description
ISSE
The selected candidate will have numerous responsibilities from day to day drawn from a wide array of activities. The strongest candidates will have experience working in these areas:
  • Validating and verifying system security requirements and establishing system security designs for large-scale systems, major system elements, and interfacing systems that are part of a large complex network environment with geographically distributed components.
  • Identifying and implementing appropriate information security architectures and functionality to ensure uniform application of security policy and enterprise solutions.
  • Recommending and developing technical solutions, products, and standards based on current and desired system security architecture.
  • Assessing and mitigating system security threats and risks throughout the program life cycle.
  • Leading and/or contributing to the security planning, assessment, risk analysis, risk management, certification and awareness activities for various system and networking operations.
  • Effectively collaborating with other internal technical experts on a day-to-day basis.
  • Communicating with Program Managers and POCs from customer organizations when necessary, regarding Security issues of significant importance.
  • Participating in Program Increment Planning and related agile team activities.
  • Working closely with System Engineering, Test Engineering, and Integration teams to ensure that the hardware and software architecture and implementation meet security requirements.
  • Analyzing and assessing system implementation against multiple security compliance policies and recommending and implementing enhancements.
  • Evaluating security solutions to ensure they meet customer specified requirements for processing information.
  • Evaluating the impact of new development on the operational security posture of the system.
  • Evaluating, reviewing, and testing critical software.
  • Proposing, assessing, coordinating, implementing, and enforcing information systems security policies, standards, and methodologies.
  • Auditing and assessing system security configuration settings using common methodologies and tools.
  • Managing and enforcing security strategies and policies that affect various components of geographically distributed systems.
  • Providing configuration management for security-relevant information system software.
  • Serving as a subject matter expert in security architecture to include providing advice to Program Managers, Customer technical experts, and internal program teams.
  • Formulating security compliance requirements for new system features.
  • Identifying and remediating security issues throughout the system.
  • Supporting risk assessment, risk management, security control assessment, continuous monitoring, service design, and other IA program support functions.
  • Working with development teams to enrich team-wide understanding of different types of vulnerabilities, attack vectors and remediation approaches.
  • Planning and conducting security verification testing of relevant type 1 devices.
Basic Qualifications
  • Must have at least 12 years of experience working as an ISSE on a large technical program.
  • Must have a solid understanding of security practices and policies and hands-on vulnerability testing experience using Customer tools.
  • Must have experience applying Risk Management Framework.
  • Must have experience formulating and assessing IT security policy.
  • Must have demonstrated knowledge of and experience with common security tools, such as Nessus, NMAP and Wireshark hardware/software security implementation, communication protocol, encryption techniques/tools, and web services.
  • Must have experience with secure configurations of commonly used desktop and server operating systems.
  • Must be comfortable working on multiple systems and components simultaneously in various configurations.
  • Must have strong verbal and written communications skills.
  • Must be committed to adopting and adhering to best practices.
  • Must be able to effectively plan and prioritize tasking and communicate clearly regarding technical options and trade-offs.
  • Must be capable of performing high-quality work both independently and with a team in a fast-moving environment.
Preferred Qualifications
  • Bachelor's degree in Computer Science, Information Assurance, Information Security System Engineering, or a related discipline.
  • Five (5) years of experience with Defense in Depth Principals/technology (including access control, authorization, identification and authentication, public key infrastructure, network and enterprise security architecture) and applying risk assessment methodology to system development.
  • DoD 8570 compliance with IASAE Level 2 or 3.
  • Information Systems Security Engineering Professional (ISSEP) Certification.
  • Computer Information Systems Security Professional (CISSP) Certification.
  • Experience developing/implementing integrated security services management processes, such as assessing and auditing network penetration testing, anti-virus planning assistance, risk analysis, and incident response.
  • Experience providing information assurance support for application development that includes system security certifications and project evaluations for firewalls that encompass the development, design, and implementation.
  • Experience with penetration testing tools.
  • Experience with scripting languages.
Due to federal contract requirements, United States Citizenship and position appropriate security clearance is required. (e.g. Active TS/SCI security clearance with customer appropriate polygraph).

Salary Range: Coming Soon (Annually)
Annual Compensation Figures listed for this position serve as a general guideline and are not a guarantee of compensation. Compensation will vary dependent upon factors including but not limited to: Government contract rates; education; relevant prior work experience, knowledge, skills, and competencies; certifications, and geographic location.

Benefits Package:
Unisity, LLC believes in generously supporting employees as they prepare for retirement. The company automatically contributes an additional 12% of each employee's gross compensation to the company 401k plan, with no requirement for employee matching. All contributions are fully vested from day one, ensuring immediate ownership of retirement funds.

Full-time employees have the option to participate in a variety of voluntary benefit plans including:
  • A Choice of Medical Plan Options, some with Health Savings Account (HSA)
  • Vision and Dental
    • Unisity, LLC provides an additional 12% of employee's gross compensation to be used for benefits, any remaining funds are then forwarded to the employee as taxable income
  • Life and AD&D Benefits (Company Paid)
  • Short and Long-Term Disability (Company Paid)

Similar Jobs

More Information Technology Jobs

Find similar Information System Security Engineer jobs: