Назад
Company hidden
4 дня назад

Information Systems Security Engineer (ISSE)

120 000 - 145 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Information Systems Security Engineer (ISSE) (Cybersecurity/RMF): Supporting a high-priority 24x7 operational system by implementing Information Assurance processes, security policies, System Security Plans, vulnerability assessments, and authorization packages with an accent on DoD cybersecurity compliance, continuous monitoring, and risk remediation. Focus on analyzing threats and vulnerabilities across Linux environments, maintaining POA&M plans, hardening systems with STIGs, and delivering actionable security evidence for Intelligence Community decision-making.

Location: Aurora, Colorado, United States; onsite support for a 24x7 operational system with occasional after-hours support required

Salary: $120,000–$145,000 annual base pay

Company

hirify.global provides engineering and cybersecurity support for government and Intelligence Community programs.

What you will do

  • Implement Information Assurance processes and develop security documentation throughout the system development life cycle using the Risk Management Framework in ServiceNow.
  • Develop and maintain security policies, System Security Plans, authorization packages, and accreditation evidence for geographically separated data centers.
  • Assess vulnerabilities and compliance risks using ACAS, Splunk audit logs, McAfee HBSS, Continuous Monitoring controls, CVEs, plugins, and IAVAs.
  • Evaluate cyber risk, track Heat Map scores, and provide risk evidence for 7-, 30-, 90-, and 365-day control metrics.
  • Coordinate POA&M remediation activities, document milestones and completion dates, and report security posture updates.
  • Collaborate with system engineers, administrators, software developers, ISSOs, ISSMs, and information assurance professionals, including participation in Configuration Control Boards.

Requirements

  • Must be a US Citizen with an active TS/SCI clearance and polygraph.
  • DoD 8570/8140 IAT Level 2 or higher certification is required, such as Security+ or CISSP.
  • 4–6 years of related cybersecurity, systems engineering, or software engineering experience; 8 years may substitute for a formal degree.
  • Bachelor’s degree in engineering, cybersecurity, information technology, information systems security, or a related STEM field.
  • Experience with Linux operating systems, standalone and LAN/WAN configurations, vulnerability assessments, threat mitigation, COTS/FOSS hardening, STIGs, and Continuous Monitoring.
  • Experience with product development across architecture, requirements, design, integration, and testing, plus security compliance and Risk Management Framework processes.

Nice to have

  • Experience onboarding assets to centrally managed enterprise solutions and implementing DISA STIGs.
  • Experience with COTS/GOTS and proprietary software due diligence.
  • Experience with containerization technologies such as Docker, Podman, or Kubernetes.
  • Systems engineering experience with complex embedded systems.
  • Self-motivated approach and ability to complete tasks independently.

Culture & Benefits

  • Company-funded, immediately vested 25% 401(k) profit-sharing plan.
  • Company-paid benefits and premiums with an HSA contribution.
  • Quarterly equity share bonuses.
  • 250 hours of annual leave.
  • Two company-sponsored annual events for employees and their families.
  • Education benefits and occasional after-hours support for the operational system.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →