Information System Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Information System Security Engineer (Cybersecurity): Designing, implementing, and maintaining cybersecurity controls for mission-focused government information systems with an accent on NIST RMF, FISMA, and authorization processes. Focus on vulnerability management, security architecture, and ensuring system compliance for ATO packages.
Location: Huntsville, AL (On-site). Must have Top Secret (TS) Clearance with SCI eligibility
Company
provides security engineering and system support for high-impact government environments.
What you will do
- Design and implement security architectures and controls across enterprise and mission systems.
- Support the full system lifecycle, including requirements, design, implementation, testing, and operations.
- Manage Risk Management Framework (RMF) activities, including security control implementation and continuous monitoring.
- Develop critical security documentation such as System Security Plans (SSPs), POA&Ms, and ATO packages.
- Coordinate vulnerability management by reviewing scan results and overseeing remediation actions.
- Collaborate with cross-functional engineering and security teams to support authorization activities.
Requirements
- Top Secret (TS) Clearance with SCI eligibility.
- 3-5 years of experience supporting cybersecurity or information assurance for enterprise or mission systems.
- Working knowledge of NIST RMF, FISMA, and ATO processes.
- Experience with vulnerability scanning tools such as Nessus, NMAP, Guardium, or WebInspect.
- Experience with cloud security in AWS GovCloud, C2S, SC2S, or Microsoft Azure, and log analysis using Splunk.
- Ability to document security controls and communicate technical information clearly.
Nice to have
- Relevant certifications: CISSP, CISM, CASP+ CECAP, Security+, or AWS Certified Security – Specialty.
- Experience in high-side or multi-enclave (U/S/TS) environments.
- Experience working with Agile development teams and CI/CD pipelines.
- Familiarity with NIST 800-53 Rev. 5.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →