NISSC 3 Information Systems Security Engineer II (ISSE)
$96,800–$96,800 year
On-siteColorado Springs, Colorado, United States
Job Summary
Analyze, design, and implement technical security controls to protect mission-critical information systems in accordance with RMF, NIST, and DoD requirements. Perform configuration, vulnerability, and risk assessments; deploy and validate security tools; and support Assessment & Authorization (A&A) activities including system security plans and plans of action and milestones. Conduct security impact analyses for system changes and oversee cybersecurity integration across design, development, test, deployment, and sustainment. Provide technical leadership on security engineering best practices while collaborating with the EDLM/UDLM Manager to ensure emergency maintenance actions comply with cybersecurity standards. Participate in incident tracking, root-cause analysis, and remediation to prevent recurrence. Develop security reports and threat analyses to support program decision-making and senior leadership updates. Contribute to continuous improvement of cybersecurity processes and tooling aligned with evolving DoD and NIST guidance.
Required Qualifications
- 4–6 years of relevant, hands-on experience in systems security engineering, cybersecurity engineering, information assurance, or related discipline, ideally within a DoD or similarly regulated environment.
- Advanced knowledge of systems security engineering principles and practices, with demonstrated experience designing and implementing technical security controls.
- Hands-on experience conducting configuration assessments, vulnerability assessments, and risk assessments for DoD or similar high-assurance systems.
- Proven ability to configure, manage, and validate security tools and technologies in support of RMF, NIST, and DoD compliance.
- Experience supporting the development and maintenance of RMF A&A packages, including security documentation, control implementation statements, and evidence collection.
- Demonstrated capabilities in incident tracking, triage, remediation support, and collaboration with incident response teams.
- Proficiency in developing advanced security solutions and overseeing cybersecurity integration across complex systems and environments.
- Ability to interpret and apply DoD, NIST, and RMF policy, standards, and guidance in an operational environment.
- Strong written and verbal communication skills, including experience producing technical documentation, security reports, and risk/threat analyses.
- Must hold at least one qualifying DoD 8140 certification (e.g., CCSP, Cloud+, CSC, GCLD, GSEC, SecurityX/CASP+).
- Active DoD Secret clearance with eligibility to obtain TS/SCI.
- Bachelor’s degree in one of the following (or closely related) fields: Information Technology (IT), Cybersecurity, Computer Science (CS), Information Systems (IS), Data Science, Software Engineering OR Equivalent DoD/Military training in cybersecurity, information assurance, or systems security engineering.
Desired Qualifications
- Experience with one or more of the following tools (or similar): eMASS, XACTA, CORE, ACAS, SCAP tools, Nessus, Checkmarx, ZAP DAST
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.