Senior ISSO – Critical Systems Security & A&A Lead
Listed on 2026-09-02
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations, Network Security
We are seeking a hands-on Cyber Security Engineer at the Subject Matter Expert (SME) level
to lead and execute security engineering activities across complex, enterprise-scale
environments. This role requires deep technical expertise across infrastructure, platforms, and
applications, combined with expert-level, hands-on experience implementing the NIST Risk
Management Framework (RMF) within federal government environments. The ideal candidate is
a technical practitioner, not just an advisor-someone who can design, implement, assess, and
secure systems end-to-ed while directly supporting system authorization, continuous monitoring,
and risk-based decision-making. This role also serves as the technical focal point for all security
incidents, leading triage, investigation, and resolution efforts in coordination with program and
enterprise security teams.
Qualifications
Bachelor's degree in Cybersecurity, IT, or other related technical discipline; or the equivalent
combination of education, technical training, or work/military experience
Minimum ten (10) years applied experience or relevant degree plus five (5) years of
Cybersecurity expertise with demonstrated ability to successfully shepherd IT projects of
varying types through the authorization lifecycle
Required Knowledge/Skills
Candidate must demonstrate hands-on experience in all the following areas{{{{:}}}}
Security & Compliance
Expert-level experience with NIST Risk Management Framework (RMF) in federal
government environments.
Strong knowledge of{{{{:}}}}
- NIST SP 800-53
- NIST SP 800-37
- NIST SP 800-30
Hands-on experience with Security Information and Event Management (SIEM)
platforms (e.g., Splunk, ELK Stack, Arc Sight, Qradar).
Demonstrated experience in security incident detection, analysis, and response.
Proven ability to triage security alerts and determine criticality and impact.
Infrastructure & Platforms (Hands-On)
Networking (e.g., routing, switching, firewalls, load balancers, network security controls)
Operating Systems{{{{:}}}}
- Windows Server
- Linux (RHEL, CentOS)
Databases (SQL and/or No
SQL)
Data Platforms (e.g., HPCC, Hadoop/Cloudera)
Web services, APIs, and application architectures
Software development environments and CI/CD pipelines
Security tooling (e.g., vulnerability scanners, endpoint protection, SIEM)
Engineering Experience
Security engineering and system hardening
Vulnerability discovery and remediation
Secure system design and architecture reviews
Technical documentation supporting RMF compliance
Experience in cloud environments (AWS, Azure, GCP, CI) within federal RMF contexts
Experience with Dev Sec Ops practices
Desired Skills
Hands-on experience with containerization and orchestration (Docker, Kubernetes)
Hands-on experience with infrastructure-as-code
Knowledge of federal overlays (e.g., DoD, FISMA High/Moderate)
Relevant certifications (preferred, not required){{{{:}}}}
- CISSP
- CAP
- CISM
- Security+
- Cloud Security
- Certified Ethical Hacker
officer (ISSO)
Experience with security orchestration, automation, and response (SOAR) platforms
Background in threat hunting and proactive security monitoring
Relevant incident response certifications
Ideal Candidate Profile
Proven hands-on Cyber Security Engineer SME, not policy-only or audit-only
Comfortable working across network, system, platform, and application layers
Deep understanding of how security controls are actually implemented and validated
Experience in federal RMF-driven environments
Able to bridge security, engineering, and compliance effectively
Experienced in managing security incidents from detection through resolution
Skilled at balancing immediate incident response needs with long-term security
improvements
Effective collaborator across organizational boundaries during high-pressure security
events
Key Responsibilities
Serve as the Cyber Security Engineer SME, providing hands-on security engineering
across all system layers (infrastructure, platform, and application).
Engineer, implement, and validate security controls in accordance with NIST SP 800-53
and RMF requirements.
Lead and support RMF lifecycle activities (Categorize, Select, Implement, Assess,
Authorize, Monitor).
Perform security engineering for{{{{:}}}}
- Network architectures and boundary protections
- Windows and Linux operation systems
- Storage and virtualization platforms
- Databases and data platforms
- Web services, APIs, and application stacks
- Custom and COTS/GOTS software solutions
- System Security Plans (SSP)
- Security Control Assessments (SCA) support
- POA&Ms
- Risk assessments and security impact analyses
security into system design and implementation.
Support ATO, re-authorization, and continuous monitoring activities.
Identify security risks and provide…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).