
Senior Information Systems Security Engineer
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in United States.
• Provide cybersecurity authorization services for SMIT, the Navy's largest IT services program.
• Act as the primary Information System Security Engineer (ISSE) for Authorization to Operate (ATO) packages under the Navy Risk Management Framework.
• Develop and review ATO submissions while coordinating updates and corrections to Assessment and Authorization (A&A) artifacts.
• Assess software and hardware against minimum security requirements as outlined by NIST SP 800-53 Rev. 5.
• Create, review, coordinate, and submit authorization artifacts to eMASS for Interim Authorization to Test (IATT) and ATO milestones.
• Execute cybersecurity authorization activities in accordance with DoD, DON, and RMF guidelines.
• Continuously monitor system resources through automated scanning and reporting mechanisms.
• Ensure patch compliance verification using ACAS, IAVA dashboards, and Microsoft Defender for Endpoints.
• Collaborate with administrators to troubleshoot and escalate patching issues as necessary.
• Implement security protocols and manage the execution, review, and disposition of STIG checklists.
• Develop and maintain Standard Operating Procedures (SOPs), Tactics, Techniques, and Procedures (TTPs), Plans of Action and Milestones (POA&Ms), and FISMA Score Card documentation.
• Present cybersecurity status updates to clients and assist in meeting ATO conditions alongside government Cyber teams.
• Support site visits, audits, and System Readiness Reviews.
• Ensure secure operation of network systems, architecture, and topology.
• Design secure business processes and engage in planning for network, security, and operations technology.
• Apply principles and practices of defense-in-depth.
• Document Ports, Protocols, Services, data flows, Controlled Access Layer (CAL) boundaries, and Authorization Office registrations.
• Create solutions for complex cybersecurity authorization challenges.
• Serve as the technical point of contact for subcontractors and vendors.
• Influence technical leadership on ISSE solution design and process decisions.
• Bachelor's degree with 8-12 years of relevant experience, or a Master's degree with 6-10 years of relevant experience in Cybersecurity, Information Security, IT, Electrical Engineering, Network Engineering, Computer Science, or a related field.
• Must be a U.S. Citizen and hold an active DoD Secret Clearance.
• Possess an active security certification that complies with DOD 8570 IAT level III or higher.
• Comprehensive understanding of the RMF steps, particularly Steps 4 through 7.
• Capability to identify all applicable STIGs from a system authorization boundary and its components.
• Ability to decompose security controls/security checks and verify that artifacts and test results fulfill controls/AP/checks.
• Familiarity with MITRE ATT&CK exploitation techniques and tactics to evaluate risk and mitigation strategies.
• Aptitude for understanding technical mitigations and identifying appropriate mitigating factors.
• Experience with eMASS, including control inheritance, TR Import, and POAM import functionalities.
• Proven experience in verifying patch compliance using ACAS, IAVA compliance dashboards, and Microsoft Defender for Endpoints.
• Background in utilizing STIG checklists, system security documentation, SOPs, TTPs, POA&Ms, and FISMA Score Cards.
• Hands-on experience with cybersecurity tools and DoD networks.
• Experience in FISMA and other information assurance compliance reporting.
• Familiarity with cybersecurity assessment, vulnerability scanning, integration and testing, data analytics, or security operations.
• Proven experience leading cybersecurity tasks and collaborating with clients, stakeholders, and team members.
• Knowledge of DoD cybersecurity assessment and authorization processes, NIST guidance, RMF documentation, and relevant DoD instructions.
• Experience in supporting formal Cybersecurity/IA testing and preparing System Security Plans.
• Strong verbal and written communication skills, including business writing on complex topics.
• Understanding of security monitoring, reporting, and maintaining compliance with security regulations and policies.
• Knowledge of Security Engineering and Architecture, Assessment and Authorization, Vulnerability Assessment, Incident Management, Vulnerability Management, Security Operations, and Policy and Program Development.
• Ability to lead and work effectively within a matrix organization.
• Nice to have: Top Secret Clearance, cloud authorizations, NMCI authorizations, ITIL processes or ITIL Foundation V4 certification, and willingness to work shifts.
• Comprehensive health and wellness packages.
• Opportunities for professional development and career advancement.
• Competitive salary and performance-based bonuses.
• Flexible work arrangements and work-life balance support.
• Engaging work environment with a focus on team collaboration.
Cisco
RELX
TASQ Staffing Solutions
MRO
Get handpicked remote jobs straight to your inbox weekly.