Cyber Systems Engineer/Information System Security Engineer; ISSE
Listed on 2026-10-03
-
IT/Tech
Cybersecurity, Information Security & Data Protection
As a Cyber Systems Engineer/ Information System Security Engineer (ISSE) at Amentum, you will play a vital role in safeguarding national security by protecting the integrity, confidentiality, and availability of government-affiliated information systems. Your expertise will directly support critical defense and intelligence missions
, ensuring that cybersecurity risks are identified, mitigated, and continuously monitored in alignment with stringent DoD and DIA standards
.
By serving as the primary security advisor for assigned systems, your work will not only ensure operational compliance but will also contribute to the resilience and trustworthiness of mission-critical infrastructure relied upon by U.S. government agencies. Through close collaboration with engineers, system administrators, government clients, and security assessors, you will help design and maintain secure environments where innovation and mission success are achieved without compromising cybersecurity.
Your contributions will have a lasting impact, enabling rapid threat response, reduced risk exposure
, and the sustained protection of sensitive data and digital assets vital to national defense and intelligence operations
.
- Lead Security Authorization Efforts: Oversee and coordinate the Assessment & Authorization (A&A) processes in alignment with Risk Management Framework (RMF) and Intelligence Community Directives (ICD). This includes interfacing with Group-level Information Systems Security Managers (ISSMs) and Security Controls Assessors (SCAs) to ensure thorough and timely security reviews.
- Develop and Maintain Security Documentation: Prepare and maintain essential security documentation such as System Security Plans (SSPs), Concept of Operations (CONOPS), Contingency Plans (CP), General User Guides (GUG), Privileged User Guides (PUG), and Standard Operating Procedures (SOPs). Ensure documentation accurately reflects the current system architecture and security posture.
- Collect and Analyze Security Artifacts: Coordinate with program managers, system owners, and engineering teams to collect Bodies of Evidence (BoEs) and artifacts necessary for A&A. Analyze and compile documentation that supports security control implementations and Plan of Action & Milestones (POA&Ms) mitigation strategies.
- Coordinate Authorization Milestones: Facilitate and track progress through customer A&A processes to achieve key security milestones such as Authority to Develop (ATD), Interim Authority to Test (IATT), and Authority to Operate (ATO). Maintain up-to-date knowledge of each project's A&A status and communicate updates effectively across technical and leadership levels.
- Support Security Compliance and Audit
Activities:
Act as a liaison during audits and compliance assessments, supporting continuous monitoring and promoting adherence to RMF, DIA policy, IC guidance, and applicable federal laws. Assist in the annual updates of Information Security Continuous Monitoring (ISCM) and Organizational Assessment (OA) Strategy Plans. - Evaluate and Respond to Emerging Threats: Review and revise control volatility sections of security plans in response to evolving threats, policy changes, and updated federal or agency guidance. Provide input on High Value Assets (HVAs), and systems classified at TS/SCI or Secret levels, ensuring appropriate protections are in place.
- Deliver Recommendations and Process Improvements: Generate actionable recommendations to enhance the security program. Identify inefficiencies in current processes and propose improvements based on best practices, audit findings, and lessons learned.
- Technical Content Review: Perform detailed technical and editorial reviews of A&A documentation, ensuring clarity, accuracy, and compliance with relevant standards and frameworks.
- In-depth understanding of the Risk Management Framework (RMF) lifecycle and Intelligence Community Directives (ICDs), particularly ICD 503.
- Ability to lead and coordinate all phases of the A&A process, from system categorization to authorization and continuous monitoring.
- Demonstrated experience engaging with Group-level ISSMs, SCAs
, and other key stakeholders to facilitate timely and thorough security reviews. - Proficiency in interpreting security requirements and guiding implementation across complex system architectures.
- Experience coordinating with PMs, system owners, and engineering teams to gather required Bodies of Evidence (BoEs).
- Strong analytical skills…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).