Information Assurance/Security Engineer IV

3 weeks ago


Herndon, United States Precision Solutions Full time
Overview

Information Assurance/Security Engineer IV

Onsite | Herndon, VA | 5 days a week

Active TS/SCI w/ CI Poly Clearance Required

SummaryOur client provides reliable, effective, and innovative technology solutions that advance federal, state, local, and nonprofit missions. Their technologists and consultants are passionate about solving complex challenges that impact millions of lives. Also, our client takes a Mindful Modernization approach in delivering our application modernization, grants management systems, government data analytics, and advisory services. Mindful Modernization is our client's way of delivering mission impact by aligning our government customers’ strategic objectives to measurable outcomes through people, processes, and technology.

Responsibilities

The Information Assurance/Security Engineer, Level 4 (ISSO), plays a vital role in supporting the security and compliance of information systems within an Intelligence Community (IC) environment. This position involves the design, implementation, and continuous monitoring of security controls to ensure the integrity, confidentiality, and availability of mission-critical systems and data. As an ISSO, you will be responsible for defining security requirements, conducting vulnerability assessments, implementing Security Technical Implementation Guides (STIGs), and supporting security authorization processes in alignment with NIST Risk Management Framework (RMF), FISMA, and other industry standards.

In this role, you will engage in a range of activities to safeguard systems, including configuring security tools such as Splunk, developing Security Test Procedures (STPs), conducting risk analysis, and providing security oversight in Agile development settings. Your work will also include collaborating with system administrators and architects to identify and resolve vulnerabilities, ensuring compliance with regulatory requirements, and supporting reporting to key IC and DoD authorities. You will play a pivotal role in maintaining the security posture of the organization by ensuring that all systems meet or exceed security requirements and compliance standards.

This position is ideal for a highly skilled ISSO professional with a strong background in security engineering, compliance, and risk management, ready to contribute to national security efforts through secure system design and monitoring.

Security Design & Integration

  • Define and integrate information security requirements into hardware, operating systems, and software applications to meet cybersecurity objectives and compliance standards
  • Develop and implement security designs that ensure systems and components align with cyber security requirements, including Security Controls Traceability Matrix (SCTM) compliance
  • Assist system architects and developers in identifying and implementing appropriate security functionalities to ensure consistent application of security policies
  • Support security authorization activities, ensuring alignment with the NIST Risk Management Framework (RMF) and compliance with FISMA, NIST SP 800-53, and related regulations
  • Validate control implementations to ensure they enforce required data access and network flow restrictions as part of a continuous monitoring strategy

Vulnerability Assessment & Risk Analysis

  • Conduct risk analysis using tools like ACAS, CVEs, and plugins to identify security vulnerabilities and assess their impact on the system
  • Provide risk analysis and remediation guidance to system administrators, collaborating to mitigate vulnerabilities
  • Develop and manage Plans of Action & Milestones (PO&AMs) for identified vulnerabilities, tracking progress and remediation efforts
  • Guide the remediation of vulnerabilities and malware, offering technical recommendations to prevent future incidents

Security Testing & Monitoring

  • Implement, validate, and enforce Security Technical Implementation Guide (STIG) requirements for system security and compliance
  • Develop, customize, and configure security monitoring tools such as Splunk to provide enhanced visibility into security events and activities
  • Develop and execute Security Test Procedures (STP) to verify compliance with required security configurations and ensure systems are meeting security standards
  • Conduct self-assessments and support A&A testing to validate the security designs and configurations of existing or new systems
  • Execute continuous monitoring efforts, responding to security data calls, scan requests, and weekly/monthly reporting requirements

Reporting & Documentation

  • Provide detailed and timely reports on system security status, vulnerabilities, and compliance activities to senior management and government stakeholders
  • Prepare and maintain documentation for security processes, assessments, configurations, and policies, ensuring all security measures are properly documented and tracked
  • Participate in the preparation of reports for compliance with government security and regulatory frameworks (e.g., NIST, FISMA, DoD policies)
  • Assist in preparing and delivering security documentation for security audits, assessments, and certifications

Collaboration & Stakeholder Engagement

  • Work with system administrators, engineers, and developers to ensure security controls are applied consistently across all stages of system development and operations
  • Participate in Agile planning events, providing input on security requirements and ensuring security is integrated into development workflows
  • Collaborate with government authorities, such as USCYBERCOM and IC-SCC, to address security concerns and ensure compliance with federal security mandates
  • Engage with external agencies for support and validation during the certification and accreditation process

Incident Response & Security Remediation

  • Provide guidance and support for incident handling, ensuring that security events are promptly identified, analyzed, and mitigated
  • Assist in the investigation and resolution of security incidents, coordinating with incident response teams and providing expert analysis to prevent future occurrences
  • Ensure that incident response procedures align with federal and organizational security policies, maintaining appropriate documentation of events and actions taken

Agile Development & Secure System Lifecycle

  • Participate in Agile development sprints to ensure security requirements are incorporated into the development process from the outset
  • Integrate security features into commercial off-the-shelf (COTS) and government off-the-shelf (GOTS) systems throughout their lifecycle
  • Advise on secure system integration, cross-domain solutions, and secure coding practices to minimize risk during system design and development

Requirements

  • 4+ years of job related experience including Information Systems Security Officer (ISSO), NIST, FISMA and other regulatory requirements
  • 8+ years of relevant Information Assurance and Information Security experience
  • Experience within the following is required:
    • Security and Compliance Frameworks
      • FISMA compliance
      • NIST RMF, NIST SP 800-37, NIST SP 800-53, NIST SP 800-53A
      • CNSSI No. 1243 (Certification & Accreditation)
      • DoD Security Technical Implementation Guides (STIGs)
      • Security Content Automation Protocol (SCAP)
      • NIST Cybersecurity Framework (CSF)
      • Risk Management and Vulnerability Assessment
    • Risk analysis and assessment (ACAS, CVEs, CWEs, and plugins)
      • Plans of Action & Milestones (PO&AM) management
      • Vulnerability remediation and malware guidance
      • Security Control Assessment (SCA) and evaluation
      • Incident handling, response, and remediation
      • FISMA and NIST certification requirements experience
    • Tools and Technologies
      • Splunk configuration and dashboard creation
      • Experience with Xacta and CSAM tools
      • Experience with AWS security configurations
      • Familiarity with ACAS, Nessus, OpenVAS, and similar vulnerability scanning tools
      • Security Information and Event Management (SIEM) tools
    • System Security Design and Architecture
      • Security architecture design and integration
      • Security testing and validation (Security Test Procedures, STIG validation)
      • System integration and cross-domain solutions
      • Authentication, authorization, and cryptographic techniques
      • Configuration management and change control
    • Communication and Reporting
      • Advanced verbal and written communication skills
      • Preparation of security reports and technical documentation
      • Experience presenting findings to government agencies (e.g., USCYBERCOM, IC-SCC)
      • Policy development and security training for federal or DoD programs
    • Agile and Development Integration
      • Agile development lifecycle participation
      • Integration of security into DevSecOps environments
      • Secure coding and software development best practices

Preferred Requirements

  • Experience in Security Control Assessments (NIST SP 800-37, SP 800-53A)
  • Familiarity with CSAM tool for risk management and compliance
  • Experience with Amazon Web Services (AWS), Xacta, and FISCAM compliance

Education/Certification Requirements

  • A Bachelors degree in Computer Science, Information Security, Information Technology, or a related field from an accredited university is required. A Masters degree in a relevant field may reduce the minimum number of years experience by 2 years
    • A Bachelor’s degree may be waived with four (4) additional years of ISSO experience
  • A Security+, CISSP, CISA, or equivalent certification (DOD 8570 IAM 2 level or higher) is required

Clearance Requirements

  • Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; an active TS/SCI clearance with a CI Poly is required.
  Other DutiesPlease note this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice. --------------  About UsNorthern Virginia-based Precision Solutions is an expert in staffing solutions for companies of any size that open the door to new opportunities and seek outstanding talent. We pride ourselves on being versatile enough to tailor our relationships to the needs of each individual client, being agile in the fast-paced marketplace, and being precise in meeting the needs of any company.  Equal Opportunity Employer StatementPrecision Solutions is an equal opportunity employer. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws.

  • Herndon, United States Chameleon Consulting Group Full time

    Company Overview CCG delivers solutions to the most challenging problems our nation faces in cyberspace. We combine extensive cyber tradecraft with a principled, innovative, and asymmetric approach to deliver unparalleled results. Excellence is our standard and mission success is our metric. Role As a CCG ISSE, you will be directly embedded with the team...


  • Herndon, United States iNovex Information Systems Full time

    Job Brief A&A; RMF Job Description We're searching for talented individuals who provide engineering services for network infrastructure as well as sophisticated enterprise computing infrastructure including end-point devices, data center hosted servers, multi-Cloud services as well as virtualized applications, and storage systems. This program will maximize...


  • Herndon, United States The Swift Group Full time

    Job DescriptionJob DescriptionThe Swift Group is seeking an experienced Information Security Systems Engineer (ISSE) to provide expert-level security support and guidance for engineering and technical IT-related activities. The ideal candidate will oversee day-to-day Information Assurance, Certification & Accreditation, and Assessment & Authorization...


  • Herndon, United States Integrated Security Technologies Full time

    Come join our team! At Unlimited Technology, we are committed to our company's core values of Passion, Collaboration, Innovation and Adaptability. With offices throughout the United States, we are a premier cyber and physical security specialty contractor, and we are growing at a rapid pace. We have a wide range of talented and experienced individuals that...


  • Herndon, United States Insight Global Full time

    Title: Information Security Analyst/Cloud Security Analyst - ISSOLocation: FULLY REMOTE - must work EST hoursDuration: 1 year contractCompensation: $50/hr to $62/hr.Required Skills and Experience *- 8+ years of Security Analyst experience- 2+ years working in a Cloud environment and FedRAMP protocols- Expert in FIPS 199 process- Expert with FISMA, risk...


  • Herndon, United States Booz Allen Hamilton Full time

    Information Systems Security EngineerThe Opportunity:Are you looking for an opportunity to share your experience in network security, network scanning, and cloud security architecture to support our country's most important dynamic missions? As a systems security and network security engineer, you can identify the key security needs of a network, assess...


  • Herndon, United States Salesforce.Com Inc Full time

    To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts. Job Category Software Engineering Job Details About Salesforce We're Salesforce, the Customer Company, inspiring the future of business with AI+ Data +CRM. Leading with our core values, we help companies across...


  • Herndon, United States Tenica Global Solutions Full time

    Information System Security Engineer (ISSE) TS/SCI FSPDepartment: Government Customer- Herndon Location: Herndon, VA Information System Security Engineer Minimum Qualifications: Five or more (5+) years' experience maintaining security posture of Sponsor compute environments, including cloud environments. Experience managing the full lifecycle of, and...


  • Herndon, United States Cape Fox Federal Contracting Group Full time

    Job Description Information Systems Security Officer (ISSO) Work Location: Reston, VA; work may also be performed at locations in the Washington, DC National Capital Region (NCR) (i.e., The District of Columbia; Arlington, Fairfax, Loudon, Prince William, and Stafford counties in VA (including incorporated cities) and Prince George and Montgomery...


  • Herndon, United States Unlimited Technology Full time

    Job DescriptionJob DescriptionCome join our team! At Unlimited Technology, we are committed to our company's core values of Passion, Collaboration, Innovation and Adaptability. With offices throughout the United States, we are a premier cyber and physical security specialty contractor, and we are growing at a rapid pace. We have a wide range of talented...

  • CNO Software Engineer

    3 weeks ago


    Herndon, United States iNovex Information Systems Full time

    Job Brief CNO Development; Software Engineering Job Description We're searching for talented individuals who CNO Development support a government customer. This program will maximize the effectiveness and efficiency of our country's most important missions both at home and abroad. If you are ready to support a high-performing team that truly makes a...


  • Herndon, Virginia, United States General Dynamics Information Technology Full time

    Job Title: Senior Director of Cyber Engineering and AutomationJob Summary:We are seeking a highly experienced Senior Director of Cyber Engineering and Automation to lead our team in delivering cutting-edge cybersecurity solutions to our clients. As a key member of our leadership team, you will be responsible for designing and implementing complex security...


  • Herndon, United States QED National Full time

    Position Title: Senior Cloud Security Engineer (Azure) Location: RemotePosition Description: Our client is looking for Senior Cloud Security Engineer candidates for a remote position. The Senior Cloud Security Engineer will advise on cloud security best practices and configure, review, and consult on Azure security environments for our customers. This...


  • Herndon, Virginia, United States Integrated Security Technologies Full time

    Job Title: Lead Security TechnicianIntegrated Security Technologies, Inc. is seeking a highly skilled and experienced Lead Security Technician to join our team. As a key member of our security team, you will be responsible for managing all aspects of access control and IP camera products and systems installed at client sites.Key Responsibilities:Install and...


  • Herndon, United States Booz Allen Full time

    Cloud Security Integration Engineer, SeniorThe Opportunity:Everyone is trying to “harness the cloud,” but not everyone knows how. As a Cloud Engineer, you know how to create a cloud-based technical architecture that meets client needs and takes advantage of cloud capabilities. What if you could use your cloud architecture skills to improve national...


  • Herndon, United States Booz Allen Full time

    Cloud Security Integration Engineer, SeniorThe Opportunity:Everyone is trying to “harness the cloud,” but not everyone knows how. As a Cloud Engineer, you know how to create a cloud-based technical architecture that meets client needs and takes advantage of cloud capabilities. What if you could use your cloud architecture skills to improve national...


  • Herndon, United States Booz Allen Full time $84,600 - $193,000

    Cloud Security Integration Engineer, SeniorSkills, Experience, Qualifications, If you have the right match for this opportunity, then make sure to apply today.The Opportunity:Everyone is trying to “harness the cloud,” but not everyone knows how. As a Cloud Engineer, you know how to create a cloud-based technical architecture that meets client needs and...


  • Herndon, United States Altus Consulting Corp Full time

    Altus Consulting is seeking a skilled Cyber Security Engineer to analyze, design, and implement security solutions across various client environments. You will collaborate with analysts, stakeholders, and internal teams to ensure comprehensive cyber defense and deliver high-quality solutions that meet client needs and exceed security...


  • Herndon, Virginia, United States Cape Fox Federal Contracting Group Full time

    Job OverviewCape Fox Federal Contracting Group is seeking a highly qualified Chief Information Systems Security Officer (ISSO) to join our team in support of a government customer. The ISSO will be responsible for providing knowledge, skills, abilities, staff support, and other related resources necessary to conduct or support the following Risk Management...


  • Herndon, United States Booz Allen Hamilton Full time

    Job Number: R0205849Cloud Security Integration Engineer, Senior The Opportunity: Everyone is trying to "harness the cloud," but not everyone knows how. As a Cloud Engineer, you know how to create a cloud-based technical architecture that meets client needs and takes advantage of cloud capabilities. What if you could use your cloud architecture skills to...