Now Hiring: Information Systems Security Engineer
Location: Chantilly, VA
Requirement: TS/SCI with Poly
Apply Online: https://warcollar-jobs.services.agileonboarding.com/jobs/details/11041
The Information Systems Security Engineer is vital position that informs and advises all levels of the information security process when developing and certifying systems for secure operations on the customer's network. The ISSE first must determine the client’s security requirements and then take measures to build systems around those requirements to maintain the security of systems and information. The ISSE designs the architecture of an information system (IS) and chooses the pieces of the system used to perform the needed functions. The ISSE then prepares a security design for the system and chooses the components to instill system security measures. This can involve selecting commercial off-the-shelf (COTS) software or custom products. Next, the ISSE implements system security by ensuring that the entire system works as planned. This includes testing and documenting the entire system and may include training people on the systems.
Required Skills
Possess multi-tasking skills, as well as be a good communicator/facilitator. Comfortable at all levels from developer to senior staff.
Knowledge of the complex network environments involving shared networks and multiple security enclaves.
Possess the ability to bridge the technical implementation (i.e. developer talk), into commonly understood security words. Often this is a skillset and is not an actual language, but frequently translation or a basic understand needs to be conveyed by the ISSE when speaking with others or in writing the documentation in order to ensure it’s easy to understand.
Document the various security control implementations as well as gather the artifacts that support the Risk Management Framework (RMF) and ICD 503 Security Accreditation for various Assessment and Authorization (A&A) efforts
Document and obtain a general understanding of the architecture being developed or that was developed for each project in order to write the Systems Security Plans (SSP)/CONOPS in the customer’s compliance applications.
Gather the information by working with various team members in order to write various additional A&A related documents such as Contingency Plan (CP), General User Guide (GUG), Privileged User Guide (PUG), Standard Operating Procedures (SOP’s), etc.
Support Accreditation and Authorization (A&A) reviews by ISSO/M, as well as the Security Controls Assessor (SCA)
Document the Plans of Actions and Milestones (POA&Ms) implementation responses or mitigations, as well as provide all required artifacts (i.e. evidence gathering from the teams)
Coordinating with various contractor and staff personnel to obtain the A&A content, as well as working with various customer security organizations to navigate the customer’s A&A process in order to achieve Authority to Develop (ATD), Interim Authority to Operation (IATT), as well as Authority to Operate (ATO).
Keep track of where each of the various A&A projects are within the customer’s A&A process in order to know when it’s time to re-submit for accreditation or an accreditation extension.
Our Benefits
100% medical insurance premium covered for the employee and their family;
Pay for every hour that you work (work 50, get paid for 50);
Paid time off (PTO) earned at 10% of billable hours, all federal holidays and your birthday;
Retirement 401k including generous company match and profit sharing;
Generous education reimbursement for formal education, certifications and conferences to include paid days off for training;
Quarterly performance bonuses;
Recruiting bonus up to $10,000 per hired referral;
Monthly team building events;
Pet insurance and identity protection; and an
Epic company holiday parties and summer events.

