Expert Cyber Security Engineer
Listed on 2026-09-20
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
In today’s rapidly evolving cyber security landscape, new and more dangerous threats are emerging daily, and vulnerabilities are being exploited almost as fast as they are discovered. The previous mindset of designing solutions, developing software, building environments, and then applying security is totally inadequate in the face of today’s realities. Agencies and programs must focus less on “What do we have to do to get an Authorization to Operate (ATO)?”
and more on “What must we do to keep the data, systems, services, and resources within our boundary protected to the fullest extent possible while successfully serving the mission?” Adopting a “Cyber Security First and Continuously;
Mission Always” approach will lead naturally to ATOs. The safety of our country, people, warfighters, and vital information depends on it.
As an Information Systems Security Officer (ISSO) and Cyber Security Subject Matter Expert, you will serve as a critical bridge between high-level security policies and their technical implementation, driving the Risk Management Framework (RMF) and Assessment & Authorization (A&A) lifecycle across multiple applications and environments. Your primary purpose is to ensure that system designs and implementations inherently meet rigorous security objectives by evaluating IT architectures, guiding development teams, and enforcing compliance with NIST SP 800-53 Rev 5 and other enterprise standards from concept to deployment.
In this role, your work directly safeguards mission-critical systems and reduces organizational risk. By proactively identifying, tracking, and mitigating vulnerabilities through continuous monitoring, STIG enforcement, and POA&M management, you ensure the resilience of enterprise capabilities. Your leadership in disaster recovery planning and IAVA compliance empowers engineers and developers to securely deliver operations, ultimately protecting the integrity and availability of our technological infrastructure.
Work Schedule:
Work hours are 9am – 5pm, Monday thru Friday, at least four days at customer or Amentum site.
Essential Responsibilities:
- Working with Security, Operations, and Development teams to gather information about all the systems, software, components, access permissions, and data flows that are part of the GEODS environments as well as the types of data that are input, manipulated, stored, and output from the authorization boundary.
- Documenting this information to create the Body of Evidence artifacts required as part of our Assessment and Authorization (A&A) packages and to maintain the artifacts as systems evolve.
- Reviewing reports and scan results to identify vulnerabilities and settings not configured in compliance with applicable DISA STIGs and create patching and remediation plans to protect systems in accordance with Agency requirements.
- Documenting clear justifications and exception statements when patching or configuration requirements cannot be met due to adverse functional or performance consequences.
- Building good working relationships within the GEODS teams and with agency A&A personnel to understand expectations and deliver required artifacts within prescribed timelines.
- Updating information in Service+ including CMDB Inventory information and Service Tickets.
Work Environment, Physical Demands, and Mental Demands:
Most work will be done at a desk or computer.
Minimum Requirements (Knowledge, Skills, and Abilities):
Skills & Tasks –
- Extensive knowledge of all applicable compliance requirement documents, such as NIST SP 800-53 REV 5, CNSSI 1253 and Overlays, DISA Security Technical Implementation Guides (STIGs), and Zero Trust.
- Experience with Windows Server, Red Hat Enterprise Linux Server, and Oracle Linux Server Operating Systems,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).