Point your AI agent at freehire and let it find you a job.

Get the CLI →

TRISTAR

Open 23d

Information System Security Engineer III

Posted Updated 4 views
Discussion

We are seeking a dedicated Information System Security Engineer III to join our team. The Information System Security Engineer (ISSE) III provides expert-level cybersecurity engineering, security architecture, and systems security engineering support for complex and mission-critical Department of War networks and information systems. Aligned with the DoD 8570/8140 IASAE Level III (Information Assurance System Architecture and Engineering) category, the ISSE III serves as a senior technical Subject Matter Expert (SME) responsible for integrating cybersecurity requirements throughout the complete system lifecycle.


The ISSE III applies advanced systems engineering and cybersecurity principles to the design, development, integration, assessment, authorization, and sustainment of secure systems. This position provides technical leadership in addressing complex cybersecurity challenges, developing resilient security architectures, mitigating sophisticated threats, and ensuring systems maintain an acceptable security posture throughout their operational lifecycle.


The ISSE III serves as a primary technical security advisor to Government stakeholders, program managers, system architects, engineers, cybersecurity personnel, and other technical teams. The position requires significant independent judgment, technical leadership, and the ability to translate mission requirements and evolving cybersecurity threats into practical, secure engineering solutions.


Key Responsibilities

  • Serve as a senior cybersecurity engineering and Information Assurance System Architecture and Engineering (IASAE) Subject Matter Expert for complex DoD systems and networks.
  • Integrate cybersecurity and security functional requirements throughout the system acquisition, architecture, engineering, development, integration, testing, deployment, and sustainment lifecycle.
  • Develop and evaluate secure system architectures that address mission requirements, cybersecurity threats, vulnerabilities, and applicable DoD security requirements.
  • Design and implement end-to-end security solutions for enterprise networks, applications, databases, cloud environments, infrastructure, and other mission-critical systems.
  • Apply systems engineering methodologies to identify and mitigate cybersecurity risks throughout the system lifecycle.
  • Harden application interfaces, data repositories, operating environments, cloud infrastructure, and system components in accordance with applicable security requirements and best practices.
  • Incorporate Zero Trust Architecture principles, defense-in-depth, boundary protection, network segmentation, firewalls, access controls, identity management, and cryptographic protections into system designs.
  • Evaluate system architectures, interfaces, and security boundaries to identify potential attack paths, weaknesses, and opportunities for improved protection.
  • Lead or support threat modeling, attack-surface analysis, vulnerability assessments, risk assessments, and security architecture reviews.
  • Analyze security vulnerabilities and threat intelligence to develop and implement proactive defensive measures against sophisticated adversaries.
  • Develop, review, and maintain comprehensive Risk Management Framework (RMF) documentation, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and other authorization artifacts.
  • Provide technical leadership and support for RMF authorization activities, including preparation for and maintenance of Interim Authority to Test (IATT) and Authority to Operate (ATO).
  • Support the development and execution of security control assessment strategies and provide technical responses to assessment findings.
  • Evaluate proposed system changes, engineering designs, interfaces, and configuration modifications for cybersecurity impacts.
  • Participate in Configuration Control Boards, Engineering Change Boards, architecture reviews, technical interchange meetings, and security working groups.
  • Lead technical walkthroughs, security design reviews, architecture assessments, and cybersecurity technical exchanges with Government and contractor personnel.
  • Serve as the primary technical cybersecurity advisor to Government stakeholders, program managers, system engineers, software developers, system administrators, and cybersecurity leadership.
  • Provide authoritative technical recommendations regarding cybersecurity risks, system vulnerabilities, security controls, architecture decisions, and remediation strategies.
  • Analyze system and security logs to identify anomalous activity, indicators of compromise, and emerging security threats.
  • Provide senior-level technical expertise during cybersecurity incident response, containment, mitigation, and recovery activities.
  • Assist with forensic investigations and root-cause analysis involving suspected or confirmed cybersecurity incidents.
  • Develop and implement technical solutions to address complex cybersecurity vulnerabilities and compliance deficiencies.
  • Evaluate the integration and effectiveness of security technologies, including SIEM, IDS/IPS, firewalls, endpoint security, vulnerability management, identity and access management, encryption, and other defensive cybersecurity capabilities.
  • Provide technical oversight and mentorship to junior cybersecurity engineers and other technical personnel.
  • Participate in intelligence-community, DoD, industry, and technical working groups to evaluate emerging cybersecurity technologies, threats, standards, and engineering practices.
  • Translate evolving cybersecurity policies, standards, threat information, and mission requirements into actionable engineering requirements.
  • Support cybersecurity assessments, audits, inspections, accreditation activities, and other Government compliance requirements.
  • Maintain current knowledge of DoD cybersecurity policies, NIST standards, DISA guidance, RMF requirements, Zero Trust principles, and emerging cybersecurity threats.
  • Perform other related cybersecurity engineering and systems security duties as assigned.
Apply

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available