Overview
The Information Systems Security Engineer (ISSE) serves as the embedded cybersecurity expert supporting a multidisciplinary research team while maintaining alignment with the OCIO Cyber Security Office. This role is responsible for implementing and maintaining cybersecurity controls, conducting risk assessments, supporting RMF and A&A activities, monitoring system security posture, and ensuring compliance with DoD, Army, and NIST requirements. The ISSE collaborates closely with researchers, system administrators, and IT staff to integrate security into research systems and workflows while protecting sensitive and classified information.
Responsibilities
- Serve as the embedded Information Systems Security Engineer (ISSE) within a multidisciplinary research group, providing direct cybersecurity expertise and support.
- Matrixed position: operationally integrated with the research team while formally reporting to the OCIO Cyber Security Office for policy, oversight, and professional development.
- Develop, implement, and maintain security architectures for research information systems in compliance with DoD, Army, and NIST cybersecurity policies and frameworks (e.g., RMF, NIST SP 800-53).
- Conduct and document security risk assessments and vulnerability analyses for new and existing research systems, networks, and applications.
- Collaborate closely with researchers, system administrators, and IT staff to integrate security controls into system designs and research workflows.
- Prepare and maintain security documentation, including STIG checklists, Plan of Action & Milestones (POA&Ms), Security Assessment Reports, and impact analyses.
- Support the Assessment and Authorization (A&A) process, ensuring research systems are best prepared for ATO efforts.
- Monitor system security posture using security tools (e.g., ACAS, HBSS, Splunk, EvaluateSTIG, Vulnerator) and respond to security incidents or events.
- Advise on secure data handling, storage, and transmission practices for sensitive and classified research data.
- Stay current with emerging cybersecurity threats, vulnerabilities, and technologies relevant to research environments.
Qualifications
- IAT III Certification (CASP+, CISSP, CISA, CISM, CCSP, GCED, GCIH, CCNP Security)
- 8-10 years relevant experience in Cyber Security
Preferred Qualifications:
- Master's degree in information technology or related field
Required Security Clearance:
- US Citizenship and an active DoD Top Secret Clearance per contract requirements.
Pay: $100,000.00 - $125,000.00 per year
Benefits:
- 401(k)
- Dental insurance
- Tuition reimbursement
Security clearance:
Work Location: Hybrid remote in Middle River, MD 21220