This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
In support of a challenging, critical, and rewarding program that provides integrated voice, video, and data services throughout the Information Technology lifecycle, Amentum is seeking Senior Information System Security Engineer (ISSE) to serve as a subject matter expert in the design, implementation, and optimization of enterprise security toolsets. The successful candidate will lead the engineering efforts for the Trellix (ePO) ecosystem and the ACAS (Nessus) suite, ensuring mission-critical assets remain secure, compliant, and resilient. This role requires a blend of high-level security architecture, hands-on troubleshooting, and the ability to drive secure-by-design principles across the System Development Life Cycle (SDLC). You must be a critical thinker, have a strong work ethic, and be able to work independently or as a member of a team in a dynamic environment. We value candidates who are detail-oriented while also being able to think and react quickly to emerging and unique problem sets. To be successful, you must be able to rapidly adapt and learn how to operate the front and back end of new products and processes.
Job Responsibility
Endpoint Security Engineering (Trellix/ePO): Expertly design, configure, and maintain Trellix components (ePO, Trellix Agent, DLP, HIPS, Policy Auditor, ABM, and VSE) across Windows and Linux environments
Author and deploy endpoint security policies for ENS modules (Threat Prevention, Firewall, Web Control) based on DISA STIGs and organizational needs
Develop custom signatures, rules, and exceptions to address zero-day threats and specific operational requirements
Validate custom exceptions to ensure uninterrupted operation of mission-critical processes without compromising compliance
Vulnerability Management (ACAS/Nessus): Design enterprise-wide vulnerability scanning strategies and manage the deployment of Security Centers and Nessus scanners
Serve as the final escalation point for complex scan issues, credentialing problems, and system communication failures
Configure automated reporting of compliance data to continuous monitoring systems and risk-scoring repositories
Security Integration & Engineering: Integrate Trellix and ACAS with tools such as Splunk, XSOAR, and ServiceNow to automate workflows and enhance incident response
Provide authoritative recommendations and ACAS-generated artifacts to support the Assessment and Authorization (A&A) process and RMF packages for Authority to Operate (ATO)
Lead the maintenance and scalability of test, development, and operational environments, collaborating with Network and DevSecOps teams to enhance resilience
Deliver Tier 1–3 maintenance and incident response for the full cybersecurity portfolio (ACAS, Trellix, Splunk, XSOAR)
Deep understanding of DISA STIGs, NIST 800-53, and the Risk Management Framework (RMF)
Requirements
Must have active Top-Secret clearance with SCI or TS with the ability to acquire SCI
Knowledge and experience with NESSUS/ACAS and Trellix administration
Experience in Splunk role while working in a Splunk Clustered Environment
Must be able to work a 40-hour work week, normally Monday through Friday
Ability to work overtime during critical peaks and be available to meet last-minute requests for overtime if needed
Ability to travel (5-10%) primarily within 75 miles
Familiarity with MS Office applications such as Excel, Word, Outlook, SharePoint, Project, and Visio
Exceptional attention to detail
excellent verbal and written communication skills
strong critical thinking, organizational, time-management, and problem-solving skills
Ability to work both independently and as part of a team in a dynamic environment
Must have active Top-Secret clearance with SCI or TS with the ability to acquire SCI
Bachelor’s Degree in a related field (Cyber and/or Engineering)
8 years of relevant experience
Must possess, or be able to obtain, one of the following 8140 IAT Level II or III baseline certifications before a start date: Level II certifications include – CCNA Security, GISCP, GSEC, Security+ CE, SSCP
Level III certifications include – CASP CE, CCNP Security, CISA, CISSP (or Associate), GCED, GCIH
Nice to have
RHEL Administration: Proficient understanding of Red Hat Enterprise Linux (RHEL) 8 and 9, including the ability to monitor and maintain cybersecurity tools at the OS level
SOAR Automation: Experience managing the full lifecycle of XSOAR infrastructure, including building complex playbooks, custom scripts, and integrations to automate cyber workflows
Splunk O&M: Proficiency in Splunk Operations & Maintenance, including managing distributed components, index management, version upgrades, and creating custom dashboards via the Monitoring Console