Information System Security Engineer (ISSE)
- Full-time
- Clearance Requirement: Secret
- Compensation: USD 124512 - USD 168091 - yearly
Company Description
Founded in 1989 and headquartered in Reston, Virginia, SOSi is a private defense and government solutions business specializing in advanced technology systems and mission support. Its capabilities include data science, software development, network engineering, intelligence, surveillance, and reconnaissance (ISR), and logistics.
Job Description
Defend the systems that power the Pacific mission 🌴
SOSi is seeking a talented Information System Security Engineer (ISSE) to lead cybersecurity engineering efforts supporting critical operations at Joint Base Pearl Harbor-Hickam. In this high-impact role, you'll drive RMF compliance, architect secure solutions, and help safeguard mission systems across a dynamic and evolving threat landscape. Join a collaborative cyber team where your expertise directly contributes to national security and operational readiness throughout the Indo-Pacific region.
Essential Job Duties:
- Design, review, and implement cybersecurity architecture and engineering solutions supporting enterprise and mission systems.
- Integrate security requirements into system design, development, testing, implementation, and sustainment activities.
- Support and lead RMF activities throughout the authorization lifecycle, including categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
- Develop, review, and maintain RMF documentation including System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms).
- Evaluate system changes, upgrades, and new capabilities to determine cybersecurity impacts and authorization requirements.
- Validate implementation of NIST SP 800-53 security controls and DISA Security Technical Implementation Guides (STIGs).
- Conduct cybersecurity architecture reviews, security engineering analyses, and technical risk assessments.
- Analyze ACAS, Tenable, Nessus, and SCAP assessment results and coordinate remediation efforts with system administrators and engineering teams.
- Develop and implement continuous monitoring strategies to maintain cybersecurity compliance and authorization status.
- Participate in Configuration Control Boards (CCBs), Technical Review Boards (TRBs), and engineering working groups.
- Provide technical guidance and cybersecurity recommendations to system owners, ISSOs, ISSMs, and senior leadership.
- Support cybersecurity inspections, Security Control Assessor (SCA) assessments, and Command Cyber Readiness Inspections.
- Evaluate interconnections, data flows, and system architectures to identify security risks and recommend mitigations.
- Track vulnerability remediation efforts and maintain POA&M activities to meet organizational and regulatory requirements.
- Support implementation and adoption of Zero Trust principles and cybersecurity modernization initiatives.
- Prepare technical reports, executive summaries, and briefing materials for leadership decision-making.
Qualifications
Minimum Requirements:
- Active Secret clearance with the ability to obtain and maintain a Top-Secret clearance.
- Must meet DoD 8140 qualification requirements for DCWF 652 Security Architect Intermediate (Primary)
- Bachelors Degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering // OR // GMON, SecurityX, CCSP, CISSO, Cloud+, CSSLP, FITSP-D, GCSA, or GSEC.
- DCWF 461 Systems Security Analyst Intermediate (Secondary)
- Bachelors Degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering // OR // CCSP, Cloud+, GICSP, GISF, GSEC, or Security+.
- Six (6) years of experience supporting cybersecurity, information assurance, systems engineering, or RMF-related activities.
- Experience supporting DoD Assessment and Authorization (A&A) or RMF processes.
- Experience with eMASS and maintenance of RMF authorization packages.
- Experience implementing and assessing NIST SP 800-53 security controls.
- Experience with ACAS, Tenable Security Center, Nessus, SCAP, and vulnerability management processes.
- Working knowledge of Windows, Linux, networking, virtualization, and enterprise information systems.
- Strong communication skills with the ability to engage both technical and non-technical stakeholders.
Preferred Qualifications:
- Active Top Secret clearance with SCI eligibility.
- CISSP certification.
- CISSP-ISSEP, CCSP, CGRC, SecurityX (formerly CASP+), or CSSLP certification.
- Experience supporting Combatant Command, Navy, or Joint operational environments.
- Experience with Zero Trust Architecture implementation.
- Knowledge of Cross Domain Solutions (CDS) and Commercial Solutions for Classified (CSfC).
- Experience with cloud security technologies and hybrid cloud environments.
- Experience conducting cybersecurity architecture reviews and secure design assessments.
- Experience using JIRA, Confluence, ServiceNow, or similar collaboration and workflow platforms.
- Experience supporting Security Control Assessor reviews and ATO renewals.
Additional Information
Work Environment:
- Working conditions are normal for an office environment.
- Fast paced, deadline-oriented environment.
- May require periods of non-traditional working hours including consecutive nights or weekends.
Working at SOSi:
All interested individuals will receive consideration and will not be discriminated against for any reason.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply