Information Systems Security Engineer

Chantilly, VA, United States

Arcfield

Arcfield was purpose-built to defend against the near-peer threat through innovations in systems engineering and integration, modeling, simulation and analysis, space and launch support, cybersecurity and test range support.

View company page

Overview

Arcfield is a leading provider of full lifecycle, mission-focused systems engineering and integration capabilities to the U.S. government and its allies. The company has more than 60 years of proven experience providing advanced engineering and analysis, IT and C5ISR capabilities to support our nation’s most critical national security missions. Headquartered in Chantilly, VA and with 16 offices around the world, Arcfield employs approximately 1,200 engineers, analysts, IT specialists, and other professionals who put our customers’ missions first, helping them solve their most complex challenges through innovations in modeling, simulation and analysis, digital transformation and C5ISR. Visit arcfield.com for more details.

Responsibilities

The Information Systems Security Engineer provides technical and programmatic Information Assurance Services to internal and external customers in support of network and information security systems.

 

  • Designs, develops, and implements security requirements within an organization’s business processes.
  • Prepares documentation from information obtained from customer using accepted guidelines such as DITSCAP (DoD Information Technology Security Certification and Accreditation Process).
  • Prepares Security Test and Evaluation plans.
  • Provides certification and accreditation support in the development of security and contingency plans and conducts complex risk and vulnerability assessments.
  • Analyzes policies and procedures against Federal laws and regulations and provides recommendations for closing gaps.
  • Develops and completes system security plans and contingency plans.
  • Recommends system enhancements to improve security deficiencies.
  • Develops, tests, and integrates computer and network security tools.
  • Secures system configurations and installs security tools, scans systems to determine compliancy and report results and evaluates products and various aspects of system administration.
  • Conducts security program audits and develops solutions to lessen identified risks.
  • Develops strategies to comply with privacy, risk management, and e-authentication requirements.
  • Provides information assurance support for the development and implementation of security architectures to meet new and evolving security requirements.
  • Evaluates, develops, and enhances security requirements, policy, and tools. Provides assistance in computer incident investigations.
  • Performs vulnerability assessments including development of risk mitigation strategies.

 

Specific Position Description:

 

This is an Information Systems Security Engineer (ISSE) position supporting a government customer's IT Security team in the ongoing process of assessing and accrediting new and upgraded systems to be compliant with the IC's ICD-503 policy on IT systems security.  The ISSE will work with all members of an acquisition team, from the customer & SETA teams to the development contractors, to help ensure an IT system can get through the Assessment & Authorization (A&A) process and eventually be given the Authority to Operation (ATO).  The ISSE will advise on and potentially assist with the development of artifacts that will be included in a Body of Evidence (BOE) that the ISSE will submit on behalf of the program.  The ISSE will then represent the program, answering all questions, concerns or issues generated by the reviewing authorities.  The ISSE will also work with engineers at the beginning stages of an acquisition to ensure security requirements are built into the baseline to make security an integral part of the system.

Qualifications

Required:

  • Must possess and be able to maintain a TS/SCI clearance with Poly.
  • 5 to 7 years’ experience with IT systems security and a BS in IT field (Cyber Security, Comp Sci, Information Systems or related); or 3 to 5 years with MS
  • Experience performing a wide variety of information assurance and information systems security engineering duties, to include the certification and accreditation of information systems using DIACAP (formerly DITSCAP), NIACAP, NIST SP 800-37, and/or ICD-503 frameworks.
  • Able to work under general supervision, providing solutions to technical problems of moderate scope/complexity
  • Experienced with frequent use and application of technical standards, principles and theories.
  • CompTIA Security+CE or equivalent certification and desire to obtain CISSP certification.
  • Demonstrated success in working well within a team of engineers.
  • Demonstrated success in working well with government customers.

 

Desired:

  • CASP or Assoc. CISSP certification or the ability to obtain cert within 6 months.
  • Prior experience with Intel Community Directive 503 (ICD-503), the IT systems accreditation process, POAMs, Creating Bodies of Evidence, understanding of the Risk Management Framework (RMF).
  • IT Systems and/or network infrastructure background for providing design advice on developing systems that meet ICD-503.
  • Experience with the systems development life cycle and working in security requirements from the beginning.

 

EEO Statement

EEO

Arcfield proactively fulfills its role as an equal opportunity employer. We do not discriminate against any employee or applicant for employment because of race, color, sex, religion, age, sexual orientation, gender identity and expression, national origin, marital status, physical or mental disability, status as a Disabled Veteran, Recently Separated Veteran, Active-Duty Wartime or Campaign Badge Veteran, Armed Forces Services Medal, or any other characteristic protected by law.

Apply now Apply later
  • Share this job via
  • or

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Tags: Audits CASP+ CERT CISSP Clearance CompTIA DIACAP DoD ISSE Network security NIST Privacy Risk management RMF SDLC Security+ System Security Plan TS/SCI

Perks/benefits: Career development

Region: North America
Country: United States
Job stats:  5  0  0

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.