More jobs:
Senior Information Systems Security Engineer; RMF Lead
Job in
Virginia Beach, Virginia, 23450, USA
Listed on 2026-07-19
Listing for:
ASEC
Full Time
position Listed on 2026-07-19
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer
Job Description & How to Apply Below
Position: Senior Information Systems Security Engineer (ISSE)/RMF Lead
Job Type: Full-time
Location: NAS Oceana Dam Neck Annex, Virginia Beach, VA.
Key Responsibilities- Lead cybersecurity engineering efforts across Live, Virtual, and Constructive (LVC) training systems and supporting infrastructure.
- Develop and integrate cybersecurity requirements throughout the system development lifecycle (SDLC), from concept and design through implementation and system modernization.
- Design secure system architectures and engineering solutions that satisfy mission objectives while meeting DoD cybersecurity requirements.
- Perform security architecture reviews, system design analyses, and engineering trade studies to ensure cybersecurity is integrated into new and evolving capabilities.
- Define cybersecurity design requirements for networks, mission systems, simulation environments, and supporting infrastructure.
- Lead Risk Management Framework (RMF) engineering activities for assigned systems, ensuring cybersecurity design decisions support successful authorization.
- Conduct security design reviews and provide technical guidance to engineering teams.
- Develop and maintain RMF packages, including System Security Plans (SSPs), security assessments, and authorization artifacts.
- Coordinate with Government Authorizing Officials (AOs), Security Control Assessors (SCAs), and cybersecurity stakeholders.
- Evaluate the cybersecurity impacts of new technologies, interfaces, mission capabilities, and system modifications, recommending engineering solutions to reduce operational risk.
- Track and resolve cybersecurity findings and authorization conditions.
- Ensure compliance with DoDI 8510.01 (RMF), NIST SP 800‑53, DoD Cyber, Workforce requirements, DISA Security Technical Implementation Guides (STIGs), and Navy and NAVAIR cybersecurity policies.
- Ensure secure integration between operational systems, simulators, and external interfaces.
- Review ACAS, vulnerability scans, and security assessment results.
- Prioritize and coordinate remediation activities across engineering, network, and system administration teams.
- Track Plans of Action and Milestones (POA&Ms) through closure.
- Assess cybersecurity risks associated with distributed training events.
- Evaluate security implications of integrating live platforms, simulators, and threat‑representation systems.
- Support cross‑domain and multi‑level security solutions where required.
- Ensure training systems can emulate realistic threats without introducing unacceptable cybersecurity risk.
- Coordinate cybersecurity requirements for coalition and joint interoperability events.
- This position may require up to 25% annual travel.
This description outlines the general nature and scope of the role. Additional duties may be assigned as necessary.
Requirements- Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or a related technical field and ten (10) years of relevant DoD cybersecurity experience. Additional directly related experience may be substituted for a degree where permitted.
- Minimum of five (5) years of experience leading Risk Management Framework (RMF) activities in accordance with DoDI 8510.01, including development of SSPs, security assessments, authorization packages, and ATO documentation.
- Demonstrated experience implementing and maintaining cybersecurity controls in accordance with NIST SP 800‑53, DISA STIGs, ACAS vulnerability management, and POA&M remediation.
- Experience designing and integrating cybersecurity solutions for complex DoD information systems, networks, or mission systems throughout the system development lifecycle.
- Experience coordinating with Government Authorizing Officials (AOs), Security Control Assessors (SCAs), engineering teams, and system administrators to achieve and maintain cybersecurity compliance and system authorization.
- Experience supporting Navy, NAVAIR, or other DoD programs involving classified information systems, distributed networks, or Live, Virtual, and Constructive (LVC) training environments is highly desired.
- Candidates must hold a current IAM‑III certification (e.g., CISM, CISSP, or GSLC) as defined by DoD…
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×