Information Systems Security Engineer

Markon, LLC.

$185K — $225K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Active TS/SCI with a current CI polygraph.
  • Deep understanding of the RMF authorization lifecycle including NIST 800-37 and NIST 800-53.
  • Experience in system security across networking, computing, and enclave environments.
  • Strong background in IT engineering, especially Linux system administration.
  • Proficiency in reading logs, interpreting configuration files, and troubleshooting containerized applications.
  • Exceptional customer service and communication skills, translating technical jargon for stakeholders.
  • DoD 8140/8570 IAM or IAT baseline certification required at hire (Security+ minimum).

Responsibilities

  • Perform technical security assessments to identify vulnerabilities and compliance issues.
  • Maintain system security designs across various environments with different data classification requirements.
  • Integrate Information Assurance into operationally deployed systems and support the security architecture.
  • Assess and mitigate security threats and risks throughout the program life cycle.
  • Install and configure TECTIX on customer premises or in AWS GovCloud environments.
  • Apply platform updates and maintain STIG compliance for installations.
  • Support customer use of TECTIX to produce RMF artifacts and provide user training as needed.

Benefits

  • Opportunity to work with an AI/ML-enabled risk management platform.
  • Hands-on technical lead position with direct customer engagement.
  • Support a classified environment with unique security challenges.
  • Engagement with a collaborative development team for ongoing improvements.
  • Extensive career development opportunities within Markon.
Full Job Description
Description

PLEX Solutions, A Part of Markon, is looking for an Information System Security Engineer (ISSE) to support a position in Annapolis Junction, MD. The Information Systems Security Engineer (ISSE) serves as the on-site technical lead responsible for deploying, maintaining, and supporting a customer's TECTIX instance while supporting the security engineering and authorization workload the platform is built to accelerate. TECTIX is an AI/ML-enabled Risk Management Framework (RMF) automation platform. This role integrates system security engineering with hands-on IT deployment, so the ideal candidate reasons fluently about NIST 800-53 control implementation and the RMF authorization lifecycle while remaining comfortable standing up containerized infrastructure in the customer environment. The engineer is the customer's primary point of contact for the platform and the interface between the customer environment and the TECTIX development team.

Responsibilities

Security Engineering and Authorization

• Perform and review technical security assessments of the computing environment to identify vulnerabilities and non-compliance with established Information Assurance standards, and recommend mitigation strategies.

• Validate and verify system security requirements, and establish and maintain system security designs across networking, computing, and enclave environments, including enclaves with differing data protection and classification requirements.

• Build Information Assurance into systems deployed to operational environments, and support the customer's security architecture and the trusted relationships among connected systems.

• Assess and mitigate system security threats and risks throughout the program life cycle, and contribute to security planning, risk analysis, and risk management activities.

• Support security authorization activities in compliance with the DoD Risk Management Framework and the NIST RMF process, and review certification and accreditation documentation for completeness and compliance.

 

TECTIX Deployment

• Install, configure, and validate TECTIX in the customer environment across the supported deployment paths, including AWS GovCloud and on-premises or disconnected installations.

• Provision and configure supporting services, including containers and required managed database resources.

• Execute and verify installation against the user’s guide and industry best practices, and document environment-specific deviations back to the product team.

Maintenance and Sustainment

• Apply platform updates, patches, and configuration changes on a defined cadence with minimal disruption to the customer, under disciplined configuration and change control.

• Maintain STIG compliance for the deployment, including a workable STIG update approach for disconnected environments.

• Monitor container, database, and application health, and remediate issues before they affect users.

• Manage vulnerability scan results, software bill of materials (SBOM) validation, and integrity hash verification as part of ongoing security posture upkeep.

RMF Tooling and Customer Support

• Support the customer's use of TECTIX to produce and maintain RMF artifacts, including System Security Plans, control implementation statements, POA&Ms, and assessment evidence.

• Assist with eMASS integration and data flows between TECTIX and the customer's authorization tooling.

• Provide Tier 1 and Tier 2 support to customer users, deliver user training, and maintain customer-facing operational documentation.

• Capture enhancement requests and defects, and coordinate resolution with the TECTIX development team

Qualifications

• Active TS/SCI with a current CI polygraph.

• Demonstrated depth in the RMF authorization lifecycle, including NIST 800-37, NIST 800-53, security control assessment, and certification and accreditation review.

• System security engineering experience across networking, computing, and enclave environments, including environments with differing classification levels.

• Solid IT engineering background, including Linux system administration, basic networking, and comfort operating in a command-line environment.

• Working software aptitude sufficient to read logs, interpret configuration files, understand containerized applications, and troubleshoot deployment issues.

• Strong customer service and communication skills, with the ability to translate between technical detail and customer stakeholders.

• DoD 8140/8570 IAM or IAT baseline certification appropriate to the task order at time of hire (for example, Security+ at minimum).

 

Desired Qualifications:

• CISSP, CGRC (formerly CAP), or equivalent RMF/GRC certification.

• Hands-on experience with GRC or authorization tooling such as eMASS, Xacta, or similar.

• AWS GovCloud experience, including ECS/Fargate, and container tooling such as Docker and Docker Compose.

• PostgreSQL administration and general database troubleshooting.

• STIG and SCAP experience, container hardening, and vulnerability management workflows.

• Prior experience supporting an Intelligence Community or DoD customer in a classified environment.

Salary RangeUSD $185,000.00 - USD $225,000.00 /Yr.The Markon pay range for this position is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Similar Jobs

More Jobs at Markon, LLC.

More Aerospace & Defense Jobs

Find similar Information Systems Security Engineer jobs: