The Senior Cloud Information Systems Security Engineer (SCISSE) will support the Government Program Manager by integrating cybersecurity requirements into system architecture, design, and engineering activities from concept through deployment. Working across the system lifecycle, the SCISSE will develop and maintain security artifacts, including Security Plans, Security Controls Traceability Matrices, architectural diagrams, and engineering documentation.
Responsibilities include performing security engineering analyses such as threat modeling, vulnerability assessments, and security impact analyses for proposed system changes. The SCISSE will select, tailor, and implement security controls in accordance with NIST SP 800-53, CNSSI 1253, the Joint SAP Implementation Guide, and other applicable cybersecurity frameworks.
To support informed decision-making, the SCISSE will communicate engineering risk assessments, including mitigation strategies, residual risks, and risk-benefit recommendations. The role also encompasses requirements analysis, system design, and integration for complex software applications and collaboration infrastructures.
As part of the configuration management process, the SCISSE will submit and review Change Requests while assessing the security implications of proposed modifications. Additional responsibilities include creating and maintaining information system security documentation, developing Standard Operating Procedures, and providing guidance on active Plans of Action and Milestones (POA&Ms).
The SCISSE will conduct continuous and periodic monitoring of systems, documentation, and operational procedures to ensure ongoing compliance with authorization requirements. Close collaboration with ISSOs, system administrators, and development teams will be essential to remediate vulnerabilities, maintain secure system configurations, and support secure engineering practices.
Working with multiple system owners, the SCISSE will address security-related design and integration requirements for hybrid environments while evaluating cloud technologies in areas such as encryption, identity and access management, boundary protection, logging, and monitoring. The position also supports incident response and forensic activities in coordination with cybersecurity teams and contributes to the development and execution of governance frameworks for managing and authorizing national security systems.