Job Closed
This listing is no longer active.
Enterprise Horizon solves complex IT and business challenges for the DoD, Federal, and Private sectors.
Information Systems Security Engineer – ISSE
Location
District of Columbia + 1 moreAll locations: District of Columbia | Washington
Posted
166 days ago
Salary
0
Seniority
Senior
Job Description
Information Systems Security Engineer – ISSE
Enterprise Horizon Consulting Group
• Engineer and implement security controls to support system ATO and ongoing authorization • Lead and support Risk Management Framework (RMF) activities from system categorization through authorization and continuous monitoring • Develop, review, and maintain ATO documentation including SSPs, SAPs, SARs, POA&Ms, and supporting artifacts • Map and implement security controls in accordance with NIST SP 800-53, DoDI 8510.01, and DoD cybersecurity policies • Support security control assessments and coordinate with Authorizing Officials (AOs) and assessors • Perform security engineering analysis to ensure system designs meet confidentiality, integrity, and availability (CIA) requirements • Conduct vulnerability assessments and support remediation efforts to reduce risk prior to and after ATO • Analyze system changes and assess security impact to maintain ATO posture • Support continuous monitoring activities, including vulnerability scanning, STIG compliance, and annual assessments • Utilize eMASS to manage RMF artifacts, control status, and ATO packages • Provide guidance on secure system configurations, hardening, and best practices • Support audits, inspections, and compliance reviews
Job Requirements
- Active Secret Security Clearance
- Bachelor’s degree in Cybersecurity, Computer Science, Engineering, or a related field (or equivalent experience)
- Experience supporting DoD or federal information systems
- Strong knowledge of RMF, NIST cybersecurity standards, and DoD cybersecurity policies
- Experience with system security engineering throughout the system development lifecycle (SDLC)
- Experience with Enterprise Mission Assurance Support Service (eMASS)
- Familiarity with the RMF process for integration tools such as MuleSoft a plus
- Ability to analyze technical designs and identify security risks
- Strong verbal and written communication skills
- Exceptional technical writing and documentation skills
Benefits
- Medical, Dental, & Vision
- Life Insurance, Short-term Disability, Long-term Disability
- SIMPLE IRA with Company Match
- Federal Holidays
- Vacation & Sick Leave
- $500 Referral Bonus
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Physical Security Specialist
Control RisksThe global specialist risk consultancy - Helping organisations succeed in a volatile world
• Control Risks is looking to bring on a consultant as a part of an embedded project with a top tier client of ours in the tech industry. • This role will conduct onsite operational security assessments of the client’s data center facilities within North America. • The Consultant will travel to the client’s facilities to conduct detailed interviews with facility stakeholders and perform a physical site assessment to ensure compliance with existing security standards and requirements. • Utilize the client’s existing standards to assess compliance with physical, technical, and operational security requirements • Conduct interviews with a wide array of security stakeholders to determine the operational security practices in place at each facility • Ensure findings are collected and presented in a clear and consistent manner to facilitate reliable analysis across a high volume of sites • Provide clear and consistent recommendations regarding security policies and practices • Maintain technical proficiency in the security industry, sharing knowledge throughout the firm and enhancing the department's current document templates and methodology • Continuously enhance client relationships through consistent delivery of high-quality reports and professional presentation
• Conducting vulnerability assessments of the assigned security infrastructure • Provide mitigation recommendations/ security architecture reviews to Government decision makers • Research/ Development/ Testing/ Implementation and Documentation changes to software • Work with networking to close out open vulnerabilities • Ensure all DISA STIGS are applied to networks, network devices and information systems where applicable
• Lead the design, development, delivery, and quality assurance of the organization’s global safety and security training framework • Establish consistent, high-quality internal training for Relief International staff and partners operating in complex and high-risk contexts • Deliver training directly and build internal capacity across all countries of operation • Ensure an inclusive approach for safety and security training across the organization • Deploy in support of country teams/incident management in a responder capacity • Develop a global organizational training strategy for safety and security training based on industry and sector best practice • Develop modular training that can be adapted on a need basis • Create training for both online/e-learning and in-person • Align training with recognized training bodies and standards for quality assurance
• Drive the implementation of technical controls and evidence gathering in collaboration with engineering for compliance standards and frameworks such as ISO 42001 and FedRAMP 20X. • Manage the daily operational reality of audits, customer questionnaires, and internal IT/Security support requests while relentlessly identifying friction and engineering automated workflows to make these tasks self-service over time. • Rapidly prototype and ship internal tools, custom Vanta integrations, and scripts using AI-assisted development to close automation gaps and eliminate manual work across Security, IT, and Engineering. • Work with application, data, infrastructure, and ML engineering teams on implementing secure design patterns and governance best-practices. You will be a trusted technical advisor and doer who speeds up production deployments rather than blocking them by automating processes like AI risk assessments and secure architecture reviews.




