This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Information Systems Security Engineer (ISSE) is responsible for designing, developing, and implementing secure information systems in compliance with organizational policies, client requirements, and federal cybersecurity standards. The ISSE integrates security into every phase of the system development lifecycle (SDLC), ensuring confidentiality, integrity, and availability are preserved throughout system design, deployment, and sustainment. As a key member of the Cybersecurity Operations Team, the ISSE works closely with system owners, architects, engineers, developers, and assessors to translate security requirements into technical solutions, mitigate risks, and implement effective security controls. The ISSE provides subject matter expertise in system security architecture, secure integration, regulatory frameworks (RMF, NIST CSF, FedRAMP, DoD), and the configuration of security technologies.
Job Responsibility:
Developing and integrating security engineering solutions throughout the SDLC
Ensuring security is incorporated into requirements, design, implementation, testing, and maintenance
Applying secure design principles such as defense-in-depth and least privilege
Collaborating with architects to align system security architecture with mission needs
Identifying and translating cybersecurity requirements into technical specifications
Interpreting security requirements from NIST SP 800-53, CNSSI 1253, and related standards
Converting organizational policies and federal regulations into actionable technical requirements
Balancing security requirements with operational and mission objectives
Conducting system-level risk assessments and supporting vulnerability management
Performing risk analyses, threat modeling, and vulnerability assessments
Recommending and documenting mitigation strategies for identified risks
Contributing to continuous monitoring activities by reviewing system risk posture
Conducting static and Dynamic code review when necessary
Analysis of scripts as necessary
Developing and maintaining security documentation to support authorization activities
Drafting and updating SSPPs, Risk Assessment Reports (RARs), SARs, and related artifacts
Supporting preparation of documentation for ATOs or equivalent authorizations
Ensuring documentation reflects current system architecture and controls
Collaborating with stakeholders to guide secure design and system authorization
Coordinating with ISSOs, ISOs, developers, and assessors throughout security testing and evaluation
Providing security engineering input to development and integration teams
Supporting compliance with RMF and authorization processes to maintain ATO status
Implementing and supporting cybersecurity tools and technologies
Assisting with the configuration and management of tools such as SIEMs, endpoint protection, firewalls, and vulnerability scanners
Analyzing security tool outputs to identify anomalies and potential threats
Recommending improvements in tool integration and effectiveness
Providing technical expertise during incident response activities
Supporting investigations by analyzing system architecture and configurations
Assisting in implementing corrective actions to address vulnerabilities and prevent recurrence
Requirements:
Master's degree in information technology, cybersecurity, data science, information systems, or computer science, from an ABET accredited or CAE designated institution
Education Equivalency: One-and-one- half (1.5) years of additional experience can substitute for one (1) year of a typical degree program
Minimum 10 years of experience in Information Technology (IT) / Information Security (IS)
At least one (1) DoD 8140 certification for their respective area or the ability to obtain certification within six (6) months of onboarding