Information Systems Security Engineer
Job in
Chantilly, Fairfax County, Virginia, 22021, USA
Listed on 2025-12-08
Listing for:
TekSynap
Full Time
position Listed on 2025-12-08
Job specializations:
-
IT/Tech
Cybersecurity, Information Security, Systems Engineer, IT Consultant
Job Description & How to Apply Below
Responsibilities & Qualifications
RESPONSIBILITIES
- The Information Systems Security Engineer is expected to be able to:
- Support Engineering and Operations network solutions and strategic adherence to all aspects of the Information Assurance (IA) program as stipulated by various U.S.
- Government requirements including (but not limited to):
Director of Central Intelligence Directives (DCID), IC Directive (ICD) 503 and associated NIST publications. - Preparation of Assessment and Authorization (A&A) documents and procedures.
- Interface with other IA team members, other security disciplines (industrial security, physical security, special programs security, etc.), program personnel, and Government security representatives.
- Serve as a principal advisor to the Government and service lane leads on all matters, technical and otherwise, involving the security of an Information System including, but not limited to, accreditation status, emerging threats, current security posture, ongoing activities, and Plan of Action and Milestones (POA&Ms).
- Adheres to SDA Risk Management Framework (RMF) standards for the performance of the ISSO role, the recommendations comply with the Federal Information Security Modernization Act (FISMA), and in accordance with NIST (National Institute of Standards and Technology) SP 800-37
- Maintains the information system assessment and authorization record within the agency’s authoritative system repository, to include but not limited to, the system security POA&Ms documents.
- Updates XACTA during the lifecycle of the system including updating network diagrams, vulnerability scans, STIG checklists, hardware/software lists, and SCRM certificates.
- Maintains responsibility for the day-to-day security operations of the system ensuring the network, system, application, or service is operated, maintained, and disposed of in accordance with SDA security policies and procedures outlined in the security authorization package.
- Ensures approved operational systems obtain and retain Approval to Operate (ATO).
- Develops POA&M for identified vulnerabilities and ensure compliance through updates as well as developing waivers, exceptions, and risk acceptance documents for information system vulnerabilities.
- Coordinates with engineering ISSE and system SMEs to obtain approval via SDA’s RMF process.
- Conduct reviews of the network, system, application and/or service in accordance with the periodicities set within the Monitoring Strategy of the Security Authorization Package Review and update approved ATO as required or requested in conjunction of auditors, cyber security & Information System Security Engineers.
- Coordinates required system changes due to security notifications, baseline changes and/or elements required to retain ATO.
REQUIRED QUALIFICATIONS
- Active TS/SCI
- 8-10 years proven track record of progressively responsible information assurance experience in ICD 503 certification and accreditation.
- Compliant with DoD 8140 and any other certification/training required by DoD for role.
- Must maintain required technical and security training relative to cybersecurity duties, in accordance with DoD instruction 8510.01, Risk Management Framework for DoD Systems, NIST Special Publication 800-53, Recommended Security Controls for Federal Information Systems and Organizations and DoD Directive 8570.01-M, IA Workforce Improvement Program.
- Must have certifications and/or comprehensive hands‑on technical experience in the technology area(s) of their assigned system(s) in order to effectively carry out their duties.
- Familiarization with NIST Special Publication 800-37 Revision 1, Guide for Applying the Risk Management Framework to Federal Information Systems’, Committee on National Security Systems Instructions (CNSSI) 1253, and NIST SP 80053 Revisions 3 and 4, SP800-39, SP 800-30.
- Demonstrated experience in transitioning applications to IC Information Technology Environment (ITE) and in-depth knowledge of IC ITE services.
We are seeking an Information Systems Security Engineer to join our team supporting the Space Development Agency.
The Information Systems Security Engineer will act as liaison to prepare, review and update…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×