Information System Security Engineer - Senior
Listed on 2026-05-30
-
IT/Tech
Cybersecurity
Position Overview
In support of a challenging, critical, and rewarding program that provides integrated voice, video, and data services throughout the Information Technology lifecycle, Amentum is seeking a Senior Information System Security Engineer (ISSE) to serve as a subject matter expert in the design, implementation, and optimization of enterprise security toolsets. The successful candidate will lead the engineering efforts for the Trellix (ePO) ecosystem and the ACAS (Nessus) suite, ensuring mission‑critical assets remain secure, compliant, and resilient.
This role requires a blend of high‑level security architecture, hands‑on troubleshooting, and the ability to drive secure‑by‑design principles across the System Development Life Cycle (SDLC). You must be a critical thinker, have a strong work ethic, and be able to work independently or as a member of a team in a dynamic environment.
- Endpoint Security Engineering (Trellix/ePO) Ecosystem Management:
Design, configure, and maintain Trellix components (ePO, Trellix Agent, DLP, HIPS, Policy Auditor, ABM, and VSE) across Windows and Linux environments. - Policy Development:
Author and deploy endpoint security policies for ENS modules (Threat Prevention, Firewall, Web Control) based on DISA STIGs and organizational needs. - Threat Mitigation:
Develop custom signatures, rules, and exceptions to address zero‑day threats and specific operational requirements. - Operational Continuity:
Validate custom exceptions to ensure uninterrupted operation of mission‑critical processes without compromising compliance. - Vulnerability Management (ACAS/Nessus) Architecture & Strategy:
Design enterprise‑wide vulnerability scanning strategies and manage the deployment of Security Centers and Nessus scanners. - Advanced Troubleshooting:
Serve as the final escalation point for complex scan issues, credentialing problems, and system communication failures. - Risk Reporting:
Configure automated reporting of compliance data to continuous monitoring systems and risk‑scoring repositories. - Security Integration & Engineering Tool Orchestration:
Integrate Trellix and ACAS with tools such as Splunk, XSOAR, and Service Now to automate workflows and enhance incident response. - RMF Support:
Provide recommendations and ACAS‑generated artifacts to support the Assessment and Authorization (A&A) process and RMF packages for Authority to Operate (ATO). - Strategic Oversight:
Lead the maintenance and scalability of test, development, and operational environments, collaborating with Network and Dev Sec Ops teams to enhance resilience. - Multi‑Tier Support:
Deliver Tier1–3 maintenance and incident response for the full cybersecurity portfolio (ACAS, Trellix, Splunk, XSOAR). - Compliance Mastery:
Deep understanding of DISA STIGs, NIST
800‑53, and the Risk Management Framework (RMF).
- Active Top‑Secret clearance with SCI or TS with the ability to acquire SCI knowledge; experience with NESSUS/ACAS and Trellix administration.
- Experience in a Splunk role within a clustered environment.
- Ability to work a 40‑hour work week, normally Monday through Friday; overtime during critical peaks and availability for last‑minute requests.
- Travel 5–10% primarily within 75 miles.
- Familiarity with MS Office applications such as Excel, Word, Outlook, SharePoint, Project, and Visio.
- Exceptional attention to detail; excellent verbal and written communication skills; strong critical thinking, organizational, time‑management, and problem‑solving skills.
- Ability to work independently and as part of a team in a dynamic environment.
- Clearance Required:
Active Top‑Secret clearance with SCI or TS with the ability to acquire SCI. - Bachelor’s Degree in a related field (Cyber or Engineering).
- Minimum 8 years of relevant experience.
- Required certifications (must possess or be able to obtain before a start date):
- Level
II: CCNA Security, GISCP, GSEC, Security+CE, SSCP - Level
III: CASPCE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH
- Level
- RHEL Administration:
Proficient understanding of Red Hat Enterprise Linux (RHEL)8 and 9, monitoring and maintaining cybersecurity tools at the OS level. - SOAR…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).