
Information Systems Security Engineer – ISSE
CACI International Inc
full-time
Posted on:
Location Type: Hybrid
Location: Denver • Colorado • Florida • United States
Visit company websiteExplore more
Salary
💰 $98,500 - $206,800 per year
Tech Stack
About the role
- perform advanced Information System Security Engineering support for various information systems throughout the system development lifecycle.
- system hardening, preparing comprehensive assessment testing procedures, conducting system vulnerability scanning and mitigation, performing system maintenance and configuration, and ensuring thorough documentation.
- support the engineering team by providing direct input on the information system design to obtain and/or maintain a successful Authorization to Operate (ATO).
- perform in-depth analysis of various security hardening guides (DISA STIGs, CIS Benchmarks, vendor guides, SANS, etc.) to ensure security control coverage is addressed in the scanning methodology.
- Analyze and mitigate system security threats, risks, and vulnerabilities throughout the program life cycle.
- Contribute to security planning, assessment, risk analysis, risk management, certification, and awareness activities for system operations.
- Execute Assessment & Authorization (A&A) in accordance with government requirements.
- Ensure that accreditation data is maintained within customer databases (e.g., SNOW).
- Research emerging technologies, vulnerability information, system hardening (e.g., STIGs), operating systems, application software, and security tools.
- Execute system configuration and maintenance in support of the Security Engineering discipline.
- Prepare comprehensive security assessment testing documentation to validate applied security controls in support of A&A testing.
- Offer technical guidance focused on information security architecture.
- Create security accreditation artifacts, including Security Plans, Certification Test Plans, and Continuous Monitoring Plans.
- Track and fulfill liens associated with A&A activities as documented in the Plan of Actions and Milestones (POA&M).
- Conduct vulnerability assessments using standardized tools (Nessus, DISA STIGs) and perform configuration updates as required to comply with security requirements.
- Provide guidance on the hardening of operating systems, COTS products, and Open-Source products to support compliance with security requirements.
- Provide technical engineering services for the support of integrated security systems and solutions.
- Participate as a member of a security engineering team that designs, develops, implements, evaluates, and/or integrates security architectures, systems, or system components.
- Support and interact with customers in the enforcement of the design of security throughout the system life cycle.
- Apply knowledge of IA policies and procedures disseminated by the customer’s organization.
Requirements
- An active TS/SCI clearance with polygraph is required.
- Must have a current certification compliant with DoD 8570 IAM or IAT level 2.
- Bachelor’s degree in Computer Science, Information Assurance, Information Security System Engineering, or equivalent and seven (7) years of directly related experience.
- Knowledge of DCID 6/3, ICD 503, CNSSI 1253, NIST SP 800-53, NIST SP 800-53A, NIST SP 800-37, and security controls assessment criteria/procedures.
- Implementing NIST 800-53 controls/ICD 503.
- Navigating projects through the RMF process to achieve IATT & ATO within the NRO environment.
- Participating in Assessment and Authorization (A&A) process.
- Preparing systems security documentation (e.g., security plans, risk assessment reports, Plan of Actions and Milestones (POA&Ms), etc.).
- Continuous Monitoring, mitigating scan findings, maintaining Ports, Protocols, and Services sheets (PPS).
- Vulnerability assessment scanning experience (Security Center/NESSUS).
- Working with engineers and system administrators to correct scan findings/system vulnerabilities.
- Creation/use of Security Center Dashboards and reports.
- Excellent communication and interpersonal skills.
- Efficient time management and workload management.
- Ability to support a flexible schedule and work in a dynamic, real-time environment with rapidly changing priorities.
Benefits
- healthcare
- wellness
- financial
- retirement
- family support
- continuing education
- time off benefits
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
Information System Security Engineeringsystem hardeningvulnerability scanningrisk analysissecurity assessment testingsecurity control implementationsecurity architectureconfiguration managementsecurity documentation preparationvulnerability assessment
Soft Skills
communication skillsinterpersonal skillstime managementworkload managementflexibilityadaptabilityteam collaborationtechnical guidancecustomer interactionproblem-solving
Certifications
TS/SCI clearanceDoD 8570 IAM or IAT level 2 certification