CACI International Inc

Information Systems Security Engineer – ISSE

CACI International Inc

full-time

Posted on:

Location Type: Hybrid

Location: DenverColoradoFloridaUnited States

Visit company website

Explore more

AI Apply
Apply

Salary

💰 $98,500 - $206,800 per year

Job Level

Tech Stack

About the role

  • perform advanced Information System Security Engineering support for various information systems throughout the system development lifecycle.
  • system hardening, preparing comprehensive assessment testing procedures, conducting system vulnerability scanning and mitigation, performing system maintenance and configuration, and ensuring thorough documentation.
  • support the engineering team by providing direct input on the information system design to obtain and/or maintain a successful Authorization to Operate (ATO).
  • perform in-depth analysis of various security hardening guides (DISA STIGs, CIS Benchmarks, vendor guides, SANS, etc.) to ensure security control coverage is addressed in the scanning methodology.
  • Analyze and mitigate system security threats, risks, and vulnerabilities throughout the program life cycle.
  • Contribute to security planning, assessment, risk analysis, risk management, certification, and awareness activities for system operations.
  • Execute Assessment & Authorization (A&A) in accordance with government requirements.
  • Ensure that accreditation data is maintained within customer databases (e.g., SNOW).
  • Research emerging technologies, vulnerability information, system hardening (e.g., STIGs), operating systems, application software, and security tools.
  • Execute system configuration and maintenance in support of the Security Engineering discipline.
  • Prepare comprehensive security assessment testing documentation to validate applied security controls in support of A&A testing.
  • Offer technical guidance focused on information security architecture.
  • Create security accreditation artifacts, including Security Plans, Certification Test Plans, and Continuous Monitoring Plans.
  • Track and fulfill liens associated with A&A activities as documented in the Plan of Actions and Milestones (POA&M).
  • Conduct vulnerability assessments using standardized tools (Nessus, DISA STIGs) and perform configuration updates as required to comply with security requirements.
  • Provide guidance on the hardening of operating systems, COTS products, and Open-Source products to support compliance with security requirements.
  • Provide technical engineering services for the support of integrated security systems and solutions.
  • Participate as a member of a security engineering team that designs, develops, implements, evaluates, and/or integrates security architectures, systems, or system components.
  • Support and interact with customers in the enforcement of the design of security throughout the system life cycle.
  • Apply knowledge of IA policies and procedures disseminated by the customer’s organization.

Requirements

  • An active TS/SCI clearance with polygraph is required.
  • Must have a current certification compliant with DoD 8570 IAM or IAT level 2.
  • Bachelor’s degree in Computer Science, Information Assurance, Information Security System Engineering, or equivalent and seven (7) years of directly related experience.
  • Knowledge of DCID 6/3, ICD 503, CNSSI 1253, NIST SP 800-53, NIST SP 800-53A, NIST SP 800-37, and security controls assessment criteria/procedures.
  • Implementing NIST 800-53 controls/ICD 503.
  • Navigating projects through the RMF process to achieve IATT & ATO within the NRO environment.
  • Participating in Assessment and Authorization (A&A) process.
  • Preparing systems security documentation (e.g., security plans, risk assessment reports, Plan of Actions and Milestones (POA&Ms), etc.).
  • Continuous Monitoring, mitigating scan findings, maintaining Ports, Protocols, and Services sheets (PPS).
  • Vulnerability assessment scanning experience (Security Center/NESSUS).
  • Working with engineers and system administrators to correct scan findings/system vulnerabilities.
  • Creation/use of Security Center Dashboards and reports.
  • Excellent communication and interpersonal skills.
  • Efficient time management and workload management.
  • Ability to support a flexible schedule and work in a dynamic, real-time environment with rapidly changing priorities.
Benefits
  • healthcare
  • wellness
  • financial
  • retirement
  • family support
  • continuing education
  • time off benefits
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
Information System Security Engineeringsystem hardeningvulnerability scanningrisk analysissecurity assessment testingsecurity control implementationsecurity architectureconfiguration managementsecurity documentation preparationvulnerability assessment
Soft Skills
communication skillsinterpersonal skillstime managementworkload managementflexibilityadaptabilityteam collaborationtechnical guidancecustomer interactionproblem-solving
Certifications
TS/SCI clearanceDoD 8570 IAM or IAT level 2 certification