Post a job

Information Systems Security Engineer - Clearance Required

Logistics Management Institute logo

Location
United States
Logistics Management Institute

Job Description

Overview

LMI is seeking an Information Systems Security Engineer (ISSE) with a minimum of a SECRET clearance to provide cybersecurity Risk Management Framework (RMF) Authority to Operate (ATO) support for the United States Army.

LMI is a consultancy dedicated to powering a future-ready, high-performing government, drawing from expertise in digital and analytic solutions, logistics, and management advisory services. We deliver integrated capabilities that incorporate emerging technologies and are tailored to customers’ unique mission needs, backed by objective research and data analysis. Founded in 1961 to help the Department of Defense resolve complex logistics management challenges, LMI continues to enable growth and transformation, enhance operational readiness and resiliency, and ensure mission success for federal civilian and defense agencies.

LMI has been named a 2022 and 2024 #TopWorkplace in the United States by Top Workplaces! We are honored to be recognized as a company that values a people-centered culture, and we are grateful to our employees for making this possible!

This position requires an active Secret clearance, TS/SCI Preferred.

Responsibilities

  • Define system security requirements in coordination with security stakeholders including system engineers, program managers, security control assessors, and Authorizing Officials (or their delegates).
  • Ensure cybersecurity requirements are identified, allocated, implemented, verified, and continuously monitored throughout the system life cycle.
  • Provide independent cybersecurity advice and guidance to government stakeholders and contractor team members.
  • Participate in recurring cybersecurity working group meetings.
  • Develop or review system security designs and architectures, including those for cloud, on-prem or hybrid.
  • Support Assessment and Authorization (A&A) cybersecurity reviews, identify gaps, and support risk management plans for to also then execute.
  • Support the Risk Management Framework (RMF) process for each product in the portfolio at all different classification levels.
  • Provide SME level cybersecurity engineering support and input to product leads and cybersecurity teams to produce and maintain Authority to Operate (ATO) packages and successfully achieve/maintain ATOs.
  • Support Interim Authority to Test (IATT), risk assessment/acceptance, and all other ATO related activities.
  • Identify and interpret security control non-compliance to determine the impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program.
  • In concert with ISSM, work with product teams to identify controls, develop appropriate mitigations, and develop and track Program of Action and Milestone (POAM) documents to ensure that ATO packages are technically sound before submission to the program cyber government staff for review.
  • Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs).
  • Advise system engineers on the best methods to remediate vulnerability findings using security scanning tools and DoD / Industry best practices.
  • Support cybersecurity engineering analysis of alternatives, tradeoffs, and risk treatment decisions.
  • Work with interdisciplinary teams to deliver trustworthy and secure systems.
  • Be able to build and maintain dashboards including but not limited to Platform system controls, logs, and compliance monitoring.

Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field
  • 5 years minimum of system and/or security engineering work performed in support of U.S. Government customers
  • Experience authoring and maintaining (or contributing documents) of RMF Assessment and Authorization (A&A) documentation, e.g., System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POAMs)
  • Experience implementing DoDI 8510.01 Risk Management Framework for DoD
  • DoD 8140 Foundational Qualification Options in the Intermediate category for Cybersecurity Quals in the 500 series.
  • Must possess and maintain a SECRET Security Clearance, TOP SECRET preferred.
  • Knowledge of Cloud (i.e., Azure, Amazon C2S, Commercial and GovCloud) security planning, design, and operations.
  • Ability to explain complex cybersecurity issues to a diverse audience in layman's terms.
  • Experience presenting verbal/written communications to Senior leadership including – Information Systems Security Engineer (ISSM), System Owners, Authorizing officials, and security leads.
  • One or more years of experience with networking and network security.
  • Experience with systems engineering lifecycle processes.
  • Proven ability to balance priorities in a dynamic, mission-oriented environment.
  • Experience with agile frameworks and Continuous Integration/Continuous Delivery (CI/CD) frameworks such as DevOps or DevSecOps.
  • Experience with cloud cybersecurity implementations.
  • Experience implementing NIST SP 800-53 Revision 4 or 5 security requirements and NIST SP 800-53A security assessment procedures.

Advice from our career coach

As someone interested in the Information Systems Security Engineer (ISSE) position at LMI, it is crucial to understand the key responsibilities and qualifications required for this role. To stand out as an applicant, consider the following tips:

  • Ensure you have a minimum of a SECRET clearance, with a TS/SCI clearance preferred.
  • Highlight your experience in defining system security requirements and providing independent cybersecurity advice to stakeholders.
  • Showcase your expertise in developing system security designs and architectures, including for cloud, on-premises, or hybrid environments.
  • Demonstrate your ability to support Assessment and Authorization (A&A) cybersecurity reviews and identify gaps.
  • Emphasize your knowledge of DoD risk management frameworks and NIST security requirements, as well as your experience with cloud security planning and operations.
  • Illustrate your communication skills by presenting complex cybersecurity issues to diverse audiences, including senior leadership.
  • Highlight your experience with networking, network security, systems engineering lifecycle processes, agile frameworks, and CI/CD frameworks.

Apply for this job

Expired?

Please let Logistics Management Institute know you found this job with RemoteJobs.org. This helps us grow!

RemoteJobs.org mascot