Information System Security Officers (ISSO), Senior Security Engineers & Security Engineering Leads (CBP)
Summary
Leads cybersecurity operations for U.S. Customs and Border Protection, ensuring systems stay authorized and secure. Roles include Information System Security Officers (ISSO), Senior Security Engineers, and Security Engineering Leads, focusing on root-cause remediation, early security integration, and accurate security posture reporting.
The Work
What Success Looks Like
- Findings that get closed stay closed, instead of returning in the next scan under a new number.
- Remediation addresses why the condition existed, not only the instance a scanner happened to catch.
- Recurring finding types get traced back to the build, the process, or the standard that produced them.
- Where something cannot be fixed, the reason and the compensating control are written down and hold up when somebody challenges them.
- Engineers bring you in early because your answer saves them work, not because a gate makes them.
- Requirements arrive in time to change a decision rather than to document one already made.
- You can tell an engineer what will and will not pass, and be right often enough that they stop checking around you.
- Somebody can ask about the state of a system and get an answer that is current rather than an answer from the last assessment.
- What is recorded as implemented matches what is running.
- Risk that leadership needs to know about reaches them while there is still a decision to make.
Where You'd Fit
- Information System Security Officer. You own whether your assigned systems stay authorized and stay honestly described. You decide what counts as an acceptable control implementation, what belongs on a POA&M, and when a change needs a security review before it proceeds.
- Senior Security Engineer. You own how systems get hardened, monitored, and remediated. You decide what the secure configuration is, what tooling the program runs, and which risks get engineered out rather than accepted and tracked.
- Security Engineering Lead. You own the security engineering function as a whole, including the standards other engineers build against. You are accountable when a design meets a threat or an audit finding it did not anticipate.
What You Bring
- One or more of the following certifications required:
- Active Certified Information Systems Security Professional (CISSP)
- Active Certified Information Security Manager (CISM)
- Other relevant certifications (e.g., CCSP, CEH) may be considered.
- Bachelor’s degree in computer science, Engineering, STEM, Information Technology, or Cybersecurity
- A minimum of eight (8) years of experience in information security, with at least 5 years specifically in a lead ISSO or similar leadership capacity on large complex USG programs.
- Active CISSP
- Active Project Management Professional (PMP) certification
- Active ISC2 Certified in Governance, Risk and Compliance (CGRC)
- Knowledge of FedRAMP
- Knowledge of A-123 audit Experience and Expertise with GRC tools such as CSAM
- You have carried a system through authorization and can say what the hard part actually was.
- You have worked inside RMF or an equivalent federal authorization framework, not only a private-sector control set.
- You have closed a class of findings rather than a list of them, and can describe what you changed to make that stick.
- You have written or reviewed security documentation that somebody else then had to defend in front of a government reviewer.
- You have run continuous monitoring where the data was incomplete and had to be made useful anyway.
- You hold an active CBP BI, a fitness determination at another DHS component, or an active DoD clearance. Any of these shortens your start date.
- Certifications such as CISSP, CISM, CAP, or Security+ are useful, but they are not a substitute for having done the work.
A note on timing
Employee Benefits
- Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do.
- Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated.
- Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support.
- Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task.
- Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges.
- Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success.
As published by lever
Resume/CV, Full name, Email, Phone, Current location, Current company
- Are you authorized to work in the US? choose one
- What is your full street address? (Street, City, State, Zip)
- Are you open to relocating for this position, or another position with Agile Defense? choose one
- What is your desired salary?
- Are you a current employee of Agile Defense or any of its subsidiaries, affiliates, or acquired companies? choose one
- Have you ever been employed by Agile Defense or any of its subsidiaries, affiliates, or acquired companies? choose one
- How did you hear about us? choose one
- Do you have a higher education degree? choose one
- What is your highest level of education? choose one
- Do you have any active industry related certifications? choose one
- What active industry related certifications do you have? written answer
- Please upload a copy of your certification(s) if applicable upload · optional
- Are you a current or former U.S. Government employee or U.S. armed forces? choose one
- Are you currently subject to any post-employment obligations from a current or former employer that could restrict your ability to perform this role if hired? choose one
- If yes, please briefly describe the type of obligation and its duration (you may exclude employer names and confidential terms). If no, please respond with "N/A". written answer
- If hired, would you have any ongoing outside employment, consulting, or business activities that could conflict with this role or the company’s interests? written answer
- If yes, please briefly describe. If no, please respond with "N/A". written answer
- I certify that the information provided is accurate to the best of my knowledge and understand that additional details may be requested later in the hiring process. choose one
- Have you ever been employed, directly or indirectly, by U.S. Customs and Border Protection? choose one · optional
- Have you ever held an active CBP Background Investigation? choose one · optional
- Have you ever worked, directly or indirectly, for any other component of DHS other than CBP (i.e. ICE, TSA, USCIS, USCG, USSS, CISA, FEMA, FLETC). Check all that apply: yes / no · optional
- Have you ever successfully completed a DHS Suitability Investigation for any non-CBP component of DHS? choose one · optional
- Do you have a Department of Defense (DOD) Recognized Security Clearance? choose one
- What level of DOD clearance do you have? choose one

