Information Systems Security Engineer (ISSE) - TS required to apply - multiple locations DC, AL, WV, VA
Bow Wave LLC District of Columbia, United States · $105K–$185K/yr
Security and Investigations · 51-200 employees
About the role
Lead and supervise a team of security professionals in the end-to-end implementation of the RMF lifecycle for FBI IT systems. Serve as a principal technical advisor on cybersecurity, overseeing risk management, system authorization, and continuous monitoring activities.
What they look for
Requirements
Requires 8 years of experience in secure design, analysis, and testing of information security systems. Candidates must hold a CISSP or CEH certification, with cloud certification preferred.
Full description
Security (Cloud a plus) Engineer (ISSE)
Work Description:
- Lead, mentor, and supervise a team of contractor security professionals responsible for the end-to-end implementation of the RMF lifecycle for FBI IT systems.
- Oversee and coordinate activities within the Prepare step, ensuring roles, responsibilities, and risk management strategies are clearly defined and maintained.
- Guide system categorization efforts to ensure all information systems are appropriately classified based on mission/business impact and regulatory requirements.
- Advise on the selection, tailoring, and documentation of security controls aligned with system categorizations, Bureau risk appetite, and compliance requirements.
- Oversee the implementation of technical, operational, and management controls throughout system and application lifecycles, with a particular focus on quality and completeness of all deliverables.
- Ensure comprehensive security control assessments are planned, executed, and documented to validate the effectiveness of implemented safeguards.
- Prepare risk management documentation for system authorization and executive decision-making.
- Direct ongoing monitoring and continuous assessment activities, collecting metrics to adjust security strategies and ensure sustained compliance.
- Serve as a principal technical advisor on cybersecurity, bringing subject-matter expertise to risk analysis, incident response, system remediation, and audit support efforts.
- Foster a culture of security awareness, providing technical guidance and training to both team members and stakeholders.
- Track, report, and communicate status, risks, and improvement opportunities related to security engineering activities to leadership and stakeholders.
- Maintain up-to-date knowledge of RMF, NIST guidance, and industry best practices in support of continuous process improvement.
Required Experience/Skills/Certifications:
- 8 years of experience in secure design, analysis, and test of information security systems and products.
- 8 years of experience applying methods, standards and approaches for ensuring the baseline security safeguards are appropriately implemented and documented.
- 8 years of experience creating and updating security test plans for detecting and mitigating risk to information systems.
- Certified Information Systems Security Professional (CISSP) or Certified Ethical Hacker (CEH) certification required
- Cloud certification preferred
Similar roles
-
Staff Security Engineer
Robots and Pencils United States · $116K–$160K/yr
-
Cybersecurity Awareness Volunteer
CyberUp St. Louis, Missouri, United States
-
Senior Security Engineer
Latitude IT Solutions $119K–$137K/yr
-
Security Engineer
Latitude IT Solutions $102K–$118K/yr
-
2027 Internal Audit - Information Technology & Cybersecurity Summer Internship
Brown Brothers Harriman New York, New York, United States · $52K/yr
-
Security Engineer III - Network and Cloud Security - Hybrid (Remote Considered) - 26-103
PriMed Management Consulting Services, Inc. San Ramon, California, United States · $109K–$144K/yr