Information Systems Security Engineer (ISSE)
Virginia Beach, VA
Full Time
Experienced
Job Type: Full-Time
Security Clearance: Active Secret
Location: Virginia Beach- Onsite
AERMOR is seeking an experienced Information Systems Security Engineer (ISSE) to support the Navy Expeditionary Combat Command (NECC). The ISSE will provide cybersecurity and technical support focused on Risk Management Framework (RMF), Assessment & Authorization (A&A), security authorization packages, vulnerability management, and cybersecurity compliance for Navy information systems and networks.
The ideal candidate will have hands-on experience supporting DoD or Navy RMF processes, developing and maintaining cybersecurity authorization artifacts, assessing security controls, identifying and mitigating vulnerabilities, and maintaining systems in accordance with Department of Defense (DoD) and Department of the Navy (DoN) cybersecurity requirements.
Key Responsibilities
Required Qualifications
Compensation:
Compensation for this position is based on several considerations, including applicable contract wage rates and labor categories, geographic location, relevant professional experience, technical expertise, education, certifications, and overall alignment with the role's requirements.
AERMOR is committed to providing competitive pay along with a benefits package designed to support employees throughout their careers. Eligible employees may receive medical, dental, and vision insurance, a 401(k) plan, paid time off, and professional development opportunities.
Salary Range: $105,000-$125,000/yr
Security Clearance: Active Secret
Location: Virginia Beach- Onsite
AERMOR is seeking an experienced Information Systems Security Engineer (ISSE) to support the Navy Expeditionary Combat Command (NECC). The ISSE will provide cybersecurity and technical support focused on Risk Management Framework (RMF), Assessment & Authorization (A&A), security authorization packages, vulnerability management, and cybersecurity compliance for Navy information systems and networks.
The ideal candidate will have hands-on experience supporting DoD or Navy RMF processes, developing and maintaining cybersecurity authorization artifacts, assessing security controls, identifying and mitigating vulnerabilities, and maintaining systems in accordance with Department of Defense (DoD) and Department of the Navy (DoN) cybersecurity requirements.
Key Responsibilities
- Support Risk Management Framework (RMF) and Assessment & Authorization (A&A) activities for Navy information systems.
- Develop, maintain, and update Navy Security Authorization Packages and associated cybersecurity documentation.
- Develop and maintain RMF artifacts, including Plans of Action & Milestones (POA&Ms), risk assessments, Security Assessment Plans, security plans, and supporting authorization documentation.
- Assess and validate the implementation of applicable security controls and support continuous monitoring activities.
- Maintain RMF and authorization documentation within eMASS, ensuring packages remain current as systems, software, hardware, infrastructure, and operating environments change.
- Conduct system and network vulnerability analysis and evaluate cybersecurity risks associated with system changes and integrations.
- Analyze vulnerability and compliance findings using ACAS/Tenable and support remediation and risk-mitigation activities.
- Support system hardening and cybersecurity compliance in accordance with applicable DISA Security Technical Implementation Guides (STIGs) and DoD/DoN cybersecurity requirements.
- Evaluate system and network configurations for compliance with cybersecurity policies and security requirements.
- Provide cybersecurity analysis related to ports and protocols, firewall policies, system/network configurations, contingency planning, and risk mitigation.
- Work with system administrators, government personnel, and cybersecurity stakeholders to resolve security findings and maintain system authorization and cybersecurity posture.
- Develop technical documentation, SOPs, checklists, workflow processes, briefings, and other documentation supporting RMF and cybersecurity activities.
Required Qualifications
- Bachelor’s degree in a technical or managerial-related discipline. Additional qualifying experience may be accepted in lieu of the degree.
- DoD 8570 IAT Level II certification. - Security+ or greater.
- 5+ years of practical experience in cybersecurity, engineering, A&A, RMF, or a closely related field. Candidates without a bachelor's degree must possess 7+ years of qualifying experience.
- Strong working knowledge of the DoD Risk Management Framework (RMF) and associated documentation requirements.
- Hands-on experience supporting Assessment & Authorization (A&A) and security authorization packages.
- Experience developing and maintaining cybersecurity/RMF artifacts such as POA&Ms, risk assessments, Security Assessment Plans, security plans, and security control documentation.
- Knowledge and experience with Information Assurance (IA)/INFOSEC concepts and requirements.
- Experience performing system/network vulnerability analysis, risk assessments, and risk mitigation.
- Familiarity with eMASS and vulnerability/compliance tools such as ACAS/Tenable.
- Knowledge of DISA STIGs, security controls, ports and protocols, firewall policies, and contingency planning.
- Experience supporting DoD and/or Navy cybersecurity environments and authorization processes.
Compensation:
Compensation for this position is based on several considerations, including applicable contract wage rates and labor categories, geographic location, relevant professional experience, technical expertise, education, certifications, and overall alignment with the role's requirements.
AERMOR is committed to providing competitive pay along with a benefits package designed to support employees throughout their careers. Eligible employees may receive medical, dental, and vision insurance, a 401(k) plan, paid time off, and professional development opportunities.
Salary Range: $105,000-$125,000/yr
Apply for this position
Required*