Senior Information Systems Security Engineer; RMF Lead
Listed on 2026-07-16
-
IT/Tech
Cybersecurity, Systems Engineer
What You'll Do:
As the Senior Information Systems Security Engineer (ISSE)/RMF Lead
, you will serve as the cybersecurity authority supporting advanced Live, Virtual, and Constructive (LVC) training environments that prepare Navy and coalition forces for real-world combat operations. You will lead the integration of cybersecurity requirements into mission systems, networks, and simulation environments while overseeing all Risk Management Framework (RMF) activities required to maintain operational authorization. Working across engineering, network, and program teams, you will help ensure the secure delivery of realistic, high-fidelity training capabilities that enable warfighter readiness against emerging and advanced threats.
This position will be based at the NAS Oceana Dam Neck Annex in Virginia Beach, VA.
Key Responsibilities:- Lead cybersecurity engineering efforts across Live, Virtual, and Constructive (LVC) training systems and supporting infrastructure.
- Develop and integrate cybersecurity requirements throughout the system development lifecycle (SDLC), from concept and design through implementation and system modernization.
- Design secure system architectures and engineering solutions that satisfy mission objectives while meeting DoD cybersecurity requirements.
- Perform security architecture reviews, system design analyses, and engineering trade studies to ensure cybersecurity is integrated into new and evolving capabilities.
- Define cybersecurity design requirements for networks, mission systems, simulation environments, and supporting infrastructure.
- Lead Risk Management Framework (RMF) engineering activities for assigned systems, ensuring cybersecurity design decisions support successful authorization.
- Conduct security design reviews and provide technical guidance to engineering teams.
- Develop and maintain RMF packages, including System Security Plans (SSPs), security assessments, and authorization artifacts.
- Coordinate with Government Authorizing Officials (AOs), Security Control Assessors (SCAs), and cybersecurity stakeholders.
- Evaluate the cybersecurity impacts of new technologies, interfaces, mission capabilities, and system modifications, recommending engineering solutions to reduce operational risk.
- Track and resolve cybersecurity findings and authorization conditions.
- Ensure compliance with DoDI 8510.01 (RMF), NIST SP 800-53, DoD Cyber, Workforce requirements, DISA Security Technical Implementation Guides (STIGs), and Navy and NAVAIR cybersecurity policies.
- Ensure secure integration between operational systems, simulators, and external interfaces.
- Review ACAS, vulnerability scans, and security assessment results.
- Prioritize and coordinate remediation activities across engineering, network, and system administration teams.
- Track Plans of Action and Milestones (POA&Ms) through closure.
- Assess cybersecurity risks associated with distributed training events.
- Evaluate security implications of integrating live platforms, simulators, and threat‑representation systems.
- Support cross‑domain and multi‑level security solutions where required.
- Ensure training systems can emulate realistic threats without introducing unacceptable cybersecurity risk.
- Coordinate cybersecurity requirements for coalition and joint interoperability events.
- May require up to 25% annual travel.
This description outlines the general nature and scope of the role. Additional duties may be assigned as necessary.
Requirements What You'll Bring:- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or a related technical field and ten (10) years of relevant DoD cybersecurity experience. Additional directly related experience may be substituted for a degree where permitted.
- Minimum of five (5) years of experience leading Risk Management Framework (RMF) activities in accordance with DoDI 8510.01, including development of SSPs, security assessments, authorization packages, and ATO documentation.
- Demonstrated experience implementing and maintaining cybersecurity controls in accordance with NIST SP 800-53, DISA STIGs, ACAS vulnerability management, and POA&M remediation.
- Experience designing and integrating cybersecurity…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).