Information System Security Engineer II
Listed on 2026-09-07
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Network Security, Systems Engineer
Description
We are seeking a skilled Information System Security Engineer II to join our dynamic team. The Information System Security Engineer (ISSE) II provides mid-level cybersecurity and systems security engineering support for Department of Defense (DoD) systems throughout the system development, integration, testing, deployment, and sustainment lifecycle. The ISSE is responsible for implementing secure system architectures and configurations, developing and maintaining Risk Management Framework (RMF) documentation, assessing security controls, identifying and remediating cybersecurity vulnerabilities, and ensuring systems remain compliant with applicable DoD cybersecurity requirements.
The ISSE II serves as a technical liaison between software development, systems engineering, network administration, cybersecurity, and Information System Security Manager (ISSM) personnel. The position requires the ability to translate cybersecurity requirements into practical engineering solutions and work collaboratively with technical teams to resolve security and compliance deficiencies.
Key Responsibilities- Develop, update, maintain, and submit RMF security authorization packages within government repositories and tools, including eMASS.
- Support systems throughout the RMF lifecycle, including categorization, security control implementation, assessment, authorization, and continuous monitoring.
- Develop and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and other required cybersecurity artifacts.
- Conduct security control assessments and assist in identifying, documenting, tracking, and remediating security deficiencies.
- Develop and maintain continuous monitoring strategies to ensure systems remain compliant with established cybersecurity requirements.
- Perform automated and manual vulnerability assessments using tools such as ACAS/Nessus, SCAP, and other approved vulnerability and compliance assessment tools.
- Analyze vulnerability scan results and translate findings into actionable remediation requirements.
- Apply DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) to operating systems, applications, databases, network infrastructure, containers, and other system components as applicable.
- Troubleshoot and resolve cybersecurity compliance gaps, vulnerabilities, and configuration deficiencies.
- Support the development and implementation of secure system architectures, security configurations, access controls, boundary protections, and defense-in-depth solutions.
- Assist with the implementation and integration of security technologies, including ACAS, HBSS/ESS, Security Information and Event Management (SIEM) platforms, intrusion detection/prevention systems (IDS/IPS), firewalls, endpoint security tools, and other cybersecurity capabilities.
- Serve as a technical liaison between software development and systems engineering teams and the ISSM, ensuring cybersecurity requirements are incorporated throughout the system lifecycle.
- Participate in engineering change boards, configuration control boards, and technical reviews to evaluate proposed changes for potential cybersecurity impacts.
- Review system designs, configurations, interfaces, and proposed modifications to ensure changes do not negatively impact the system's security posture or authorization boundary.
- Provide cybersecurity engineering support during system integration, testing, deployment, and sustainment activities.
- Analyze security logs and system data to identify anomalous activity, potential vulnerabilities, and indicators of compromise.
- Provide technical support during cybersecurity incidents, investigations, and forensic activities as required.
- Assist with security-related troubleshooting and root-cause analysis of system and network issues.
- Coordinate with system administrators, network engineers, software developers, and other technical personnel to implement and verify security requirements.
- Maintain technical documentation related to system security configurations, vulnerabilities, assessments, remediation activities, and security controls.
- Monitor…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).