Sr. Information Systems Security Engineer (ISSE), (Vulnerability Management)

Illuminate
Dulles, VA, US
Full-time

Overview

The Information Systems Security Officer (ISSO) manages all aspects of an organization's information security system, for classified and unclassified systems, including researching, testing, training and implementing programs designed to safeguard sensitive information from any possible breaches.

The ISSO drives Authority to Operate (ATO) and / or Authority to Proceed (ATP) efforts and makes independent recommendations to the customer during the process.

ISSOs understand and execute the Risk Management Framework process. The ISSO conduct risk analyses and writes documents including Plan of Action and Milestones, System Security Plans, System Specific Policies and Procedures, Configuration Management Plans, Contingency Plans and Test Results, Business Impact Analyses, and Security Impact Analyses.

Responsibilities

As an information systems security engineer (ISSE), you will support the customer in safeguarding networks against unauthorized modification, destruction, or disclosure.

Activities include but are not limited to :

  • Conducting risk analysis on products reviewing CVEs, plugins, CWEs etc;
  • Understanding how to explain and remediate the technical security controls;
  • Facilitating Technical Insertions (the introduction of any new and / or improved hardware or software capabilities into an established operational system) for new products;
  • Reviewing change requests for security impacts and technical documentation from a security perspective;
  • Participates in Agile Planning Events to provide technical input.
  • Providing technical input into trade studies for tools;
  • Providing technical expertise in implementation of technical security controls in government cloud environments (cloud security experience is highly desired);
  • Researching, evaluating, testing, recommending, communicating, and implementing new security software or devices;
  • Implementing, enforcing, communicating internet, network, or other information security policies or security plans for data, internet, software applications, hardware, telecommunications, and computer installations;
  • Managing all aspects of an organization's information security system, including researching, testing, training and implementing programs designed to safeguard sensitive information from any possible breaches.

Qualifications

Required Education, Experience, & Skills

  • Bachelor’s Degree with 7 years related experience including cloud security OR 10 total years of experience in Information Assurance, and IT Security including cloud security
  • Obtain and maintaining an IAT Level III baseline certification within (90) days of hire

Required Clearance : Secret

Specific to cloud environment vulnerability management :

Technical expertise in system security vulnerabilities and remediation techniques, network, and web-related protocols (.

TCP / IP, UDP, IPSEC, HTTP,

  • Technical expertise in security engineering, system and network security, authentication and security protocols, cryptography, and application security
  • Experience with vulnerability scanning and testing tools such as : Burp suite, Rapid7 InsightVM, Tenable Nessus, Web Inspect, Net Sparker, DB Protect, App Detective, Prisma Cloud, Core Impact, Code DX and similar.
  • Experience analyzing vulnerabilities, establish cause and impact, and identify the corrective action needed to eliminate and prevent the event from happening in the future.
  • Experienced in vulnerability validation, Pre-Production, remediation, testing for false positives and vulnerability research skills.
  • Experience using at least one scripting language (. : Perl, Python, PowerShell)
  • Experience with system administration in Windows and / or Linux.
  • Experience testing and operating Amazon Web Services, Azure, and / or Google

The ISSE supports the Information systems security officer (ISSO) in managing all aspects of an organization's information security system, including researching, testing, training and implementing programs designed to safeguard sensitive information from any possible breaches.

The ISSE will support the ISSO in the following activities (including but not limited to) :

  • Conducting risk analyses from vulnerability, compliance scans, pen testing results, or other audit activity; writes including but not limited to Plan of Action and Milestones, System Security Plans, Security Control Traceability Matrices, Configuration Management Plans, Contingency Plans and Test Results, Business Impact Analyses, and Security Impact Analyses;
  • Submitting monthly scan data in support of FISMA scorecard compliance requirements;
  • Responding to data calls, scan requests and weekly and monthly reporting requirements.

Preferred Education, Experience, & Skills

Desired Certifications : CISSP, CCSP, AWS-SEC, MCASEA

30+ days ago
Related jobs
Promoted
Piper Companies
Reston, Virginia

Engineer, implement, and monitor security systems to protect computer systems, networks, and information. Strong knowledge of security operations, threat and vulnerability management, incident response, system administration, and security enhancement. Monitor information systems for security inciden...

Promoted
Peraton
Chantilly, Virginia

Assist in developing systems engineering processes for the planning, design, development, deployment, integration and test, configuration management of R&D ground systems. Peraton is seeking a Senior Systems Engineer to support operations and maintenance efforts for a research and development (R&D) ...

Promoted
Leidos Holding
Reston, Virginia

This role provides information security solutions compliant with the Risk Management Framework (RMF) and ICD 503 Security Accreditation control as part of an Agile team. Responsibilities include collaborating with the customer security organization to ensure RMF processes are followed, policy is tra...

Promoted
KBR
Chantilly, Virginia

KBR is seeking a Systems Engineer to support Model Based Systems Engineering (MBSE) efforts for government programs in Chantilly, Va. Systems Engineering experience with Model-Based Engineering applications and technology. Requires an understanding of systems engineering and of model-based methodolo...

Promoted
Nightwing
Sterling, Virginia

Linux Systems Administrator applies current technologies to the design, development, evaluation and integration of computer information systems and networks to maintain system security. Bachelor’s degree in Systems Engineering, Computer Science, Information Systems or related technical field. Involv...

Promoted
Deloitte
Falls Church, Virginia

The Information System Security Engineer (ISSE) will be responsible for creating and maintaining RMF artifacts and shall implement security controls, patch vulnerabilities on network devices, and resolve system security engineering concerns to ensure cyber compliance and readiness for a Government F...

Promoted
Amazon Web Services, Inc.
McLean, Virginia

Machine Learning Engineer, Global Services Security Engineering. Amazon Web Services is looking for world-class software developers with experience in machine learning to join the Security Innovation team in Global Services Security (GSS). In this role, you are a passionate, talented, and inventive ...

Promoted
Deloitte
McLean, Virginia

The Information System Security Engineer (ISSE) will be responsible for creating and maintaining RMF artifacts and shall implement security controls, patch vulnerabilities on network devices, and resolve system security engineering concerns to ensure cyber compliance and readiness for a Government F...

Amazon Web Services, Inc.
Burke, Virginia

Amazon Web Services is looking for world class software developers with experience in machine learning to join the Security Innovation team in Global Services Security (GSS). In this role, you are a passionate, talented, and inventive Software Development Engineer (SDE) with strong experience in ML,...

7SolutionsUSA
Herndon, Virginia

Performs Systems Engineering activities including concept of operations formulation, requirements definition, analysis and engineering, system architecting, system analysis and design, interface and data architectures, validation and verification, systems integration, system & op. Ensures the lo...