Senior Information System Security Engineer
Senior Information System Security Engineer
Location: Washington, DC
Work Location: onsite
- Lead and execute information system security engineering processes to capture, analyze, and refine security requirements in alignment with organizational and DoD policy.
- Architect, design, and implement security solutions that are integrated into new and existing information systems throughout their development lifecycle.
- Collaborate with system architects, developers, and administrators to ensure security requirements are embedded early in design and configuration decisions.
- Apply best practices in software and systems engineering methodologies, including secure architecture, secure coding techniques, and defense-in-depth strategies.
- Evaluate and advise on system upgrades, modernization efforts, and technology integrations, ensuring continued compliance with DoD and SAP security standards.
- Support risk management and accreditation activities by contributing to documentation, system assessments, and security test and evaluation (ST&E) efforts.
- Provide technical security guidance to system owners, developers, and administrators on implementation of security controls per JSIG, NIST SP 800-53, DoDI 8500.01, and related directives.
- Coordinate with Information System Owners (ISO), Authorizing Officials (AO), and ISSM/ISSO to verify that systems meet security design and implementation requirements.
- Responsible for ensuring the information system is engineered and deployed with appropriate safeguards.
- 20+ years of Information Assurance related work within the Department of Defense (DoD) or Intelligence Community (IC), work experience must be no less than two total years of experience in a SAP and/or SCI environment (at least one year of work in the last five years)
- Experience in information system security engineering, cybersecurity architecture, or secure software/system development.
- Knowledge of DoD RMF, NIST SP 800-37/53, and CNSSI 1253 processes.
- Familiarity with cross-domain solutions, encryption technologies, identity and access management, and secure configuration baselines.
- Advanced technical competency in one or more of the following supported platforms: Microsoft Windows Server, Active Directory, Red Hat Enterprise Linux servers, MS Hyper- V/VMWare/ESx/Xen Hypervisors, Enterprise networking/firewalls/intrusion detection/prevention systems, forensic analysis/vulnerability assessment, Group Policy management and configuration.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Systems, or related field.
- Current/active Top Secret/SCI; Current or recent DoD SAP access
- Subject to a Counterintelligence (CI) polygraph