Назад
Company hidden
14 часов назад

Principal Systems Security Engineer / Senior ISSM (Cybersecurity)

165 010 - 226 889$
Формат работы
hybrid/onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Principal Systems Security Engineer / Senior ISSM (Cybersecurity): Leading end-to-end cybersecurity posture, compliance governance, and system accreditation for a multi-classification defense program with an accent on vulnerability management, security monitoring, STIG hardening, and RMF/ATO governance. Focus on owning authorization packages, building SIEM and Tenable capabilities, managing incident response, and briefing security posture to government Authorizing Officials.

Location: Lone Tree, Colorado, United States; office or hybrid environment

Estimated starting salary: $165,010.21–$226,889.04 per year, plus performance-based annual incentive pay.

Company

hirify.global develops aerospace, aviation, ISR, C4ISR, and national security systems, including next-generation airborne command-and-control capabilities.

What you will do

  • Lead the end-to-end cybersecurity posture, compliance governance, and system accreditation for information systems in a multi-classification defense program.
  • Execute and oversee vulnerability scanning, security monitoring, incident response, configuration hardening, and DISA STIG implementation.
  • Own the RMF and ATO lifecycle, including SSPs, SARs, POA&Ms, evidence packages, and authorization decisions.
  • Develop and enforce security policies and procedures while training and mentoring ISSOs and ISSEs.
  • Coordinate with DCSA, DoD, IC, government stakeholders, and Authorizing Officials, including formal security briefings.
  • Operate and improve Tenable, ELK, and Splunk security monitoring and reporting capabilities.

Requirements

  • Bachelor’s degree in systems security, network engineering, information technology, or a related engineering discipline, plus 12+ years of IT security experience; 16 years of related experience may substitute for the degree.
  • At least 8 years in a formal ISSM role with direct ATO package ownership and government Authorizing Official interface responsibility.
  • Hands-on experience with Nessus/Tenable, ELK Stack, Splunk SIEM, DISA STIGs, RHEL/Linux, VMware, scripting, PKI, RMF/ATO, DCSA requirements, CMMC, TEMPEST, and PPSM.
  • Deep working knowledge of NIST 800-53 Rev. 5, including control families, tailoring, inheritance, and assessment procedures.
  • Experience presenting security posture directly to government stakeholders and managing security assessment evidence and authorization packages.
  • Current/active Top Secret U.S. security clearance with SCI eligibility and U.S. citizenship are required.

Nice to have

  • CISSP, CISM, CASP+, IAM Level III, or IAT Level III certification.
  • GitLab, GitHub Advanced Security, or RHCSA certification.
  • Experience with enterprise Tenable Security Center, cross-domain solutions, Zero Trust architecture, and multidisciplinary RMF teams.
  • Knowledge of PMI/PMP practices and JIRA for project and earned-value tracking.

Culture & Benefits

  • Mission-focused work supporting aerospace, defense, and national security programs.
  • Medical, dental, and vision coverage.
  • 401(k) with a 150% match on contributions up to 6%.
  • Life insurance, three weeks of paid time off, and tuition reimbursement.
  • On-call incident-response rotation and occasional travel may be required.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →