Modern Technology Solutions, Inc.
Posted 1mo ago

Cyber Security Engineer - Information Systems Security Engineer (ISSE) - Senior Principal

Modern Technology Solutions, Inc.
Dayton or Bedford
OnsiteFull Time
Responsibilities
  • designing requirements
  • assessing risk
  • guiding contractors
Requirements
  • 18+ years cybersecurity/IT experience
  • Knowledge of DoD/NIST/JSIG/STIG guidance
  • CISSP/CCSP/AWS certs preferred
  • Bachelor’s required (master’s preferred)
  • Active Top Secret/SCI clearance and U.S. citizenship required
Technical tools mentioned
DoD 8500.1-MDoDM 5205.07NIST Special Publication 800-53Joint SAP Implementation Guide (JSIG)DISA Security Technical Implementation Guide (STIG)AWSCOMSEC

Job description

Modern Technology Solutions, Inc. (MTSI) is seeking a Cyber Security - Information Systems Security Engineer ( ISSE) in Dayton, OH or Hanscom Air Force Base, MA. 
As a Cybersecurity Engineer / Information Systems Security Engineer (ISSE) with MTSI you will support a customer operating out of Wright Patterson AFB) in Dayton, OH or Hanscom AFB, MA. Position requires travel up to 20%, as required by the Government. The ISSE serves as the Program Office’s information security professional responsible for conducting information system security engineering activities that capture and refine their requirements and ensures security is integrated into system and security architecture designs. The ISSE works with the Systems Engineering teams to incorporate cyber resiliency objectives, techniques, and design principles into all engineering and development efforts throughout the systems development life cycle (SDLC).

Responsibilities:

• Serve as the Information Systems Security Officer (ISSE) providing technical input, recommendations, and assistance with the implementation of both higher and granular-level cyber security approaches, methods and solutions that incorporate and maintain compliance to requirements resulting from laws, regulations, and other pertinent guidance.
• Participate in acquisition meetings (PMR, PDR, CDR, etc.), concept of operation (CONOP) working groups, change boards, technical exchange meetings and other similar activities.
• Design and develop security requirements that drive down risk while maintaining operational capability.
• Work between architecture-level and implementation-level engineering meetings to maintain a system-wide view of security functions and apply risk mitigation strategies at the appropriate level.
• Guide and verify defense contractors’ work against program requirements and goals. This includes participating in technical discussions, trade studies and working groups, and conducting research on industry best practices for potential implementation.
• Interface with program managers to explain security requirements, risks and mitigations relative to their priorities of cost and schedule to ensure an acceptable risk tolerance.
• Evaluate newly identified threats and vulnerabilities to customer information systems to ascertain the need for additional safeguards and develop timely implementation strategies to reduce risk.
• Enforce the design and implementation of trusted relationships among external systems and architectures.
• Assess proposed changes to customer information systems, their operation environment, and mission needs for impacts to cybersecurity architectures and continued compliance with cybersecurity requirements.
• Provide inputs to development teams responsible for designing and developing organizational information systems and upgrading legacy systems.
• Employ best practices when implementing security requirements for information systems including software engineering methodologies, system/security engineering principles, secure design, secure architecture, and secure coding techniques.
• Keep abreast of current and new security technologies and threats to better support the customer in maintaining cybersecurity resilience.
• Identify integration issues related to the implementation of new systems within the existing infrastructure; recommend mitigation and/or resolution options as appropriate.
• Assist in the design of systems and networks that encompass multiple enclaves to include those with differing data protection/classification requirements.

Qualifications:

Required Qualifications:
• 18+ years' technical experience in cybersecurity, information technology with focus on cybersecurity implementations.
• Demonstrated ability to understand cybersecurity needs of systems at varied stages of the SDLC.
• Firm understanding of the DoD 8500.1-M, DoDM 5205.07, Volume 1, Joint SAP Implementation Guide (JSIG), National Institute of Standards and Technology (NIST) Special Publication 800-53, Intelligence Community Directive (ICD) Number 503.
• Excellent oral and written communication skills and ability to clearly translate client technical needs into technical specifications.
• Demonstrated ability to complete tasks, drive projects to closure, assimilate and correlate project information in a fast-paced environment.
• Demonstrated ability to assess and articulate risk, including to non-technical audiences.
Desired Qualifications:
• Experience working on DISA Security Technical Implementation Guide (STIG) implementation.
• Experience working on-site in a government client environment.
• Familiarity with security procedures while working in a SCIF/SAPF environment.
• Cloud Security Implementation experience.
• Familiarity and experience with NSA requirements for COMSEC.
• Experience with DoD Acquisition Lifecycle experience and/or Rapid Acquisition / Rapid Delivery experience
• Capable of applying system security engineering expertise to various client programs/processes (e.g., system security design process, engineering life cycle, information domain and cross domain solutions, identification/authentication/authorization of commercial off-the-shelf and government off-the-shelf software employment, system integration, risk management, intrusion detection, contingency planning, incident handling, configuration control, change management, continuous monitoring, auditing, assessment and authorization, confidentiality, integrity, and availability.

Education Requirements:
• Bachelor’s degree in engineering, computer science, cybersecurity, networking, or programming.
• Master’s degree in engineering, computer science, cybersecurity, networking, or programming, (Highly Desired).
Certification Requirements in one or more of the following:
• Certified Information Systems Security Professional (CISSP or (CISSP-ISSEP/CISSP-ISSAP)
• Certified Cloud Security Professional (CCSP).
• AWS Architect or other similar cloud technology security certification

Clearance Requirements:
Security Clearance Level Required: Must possess an active Top Secret security clearance, current within five (5) years, based upon a T5 or T5R investigation (formerly known as Single Scope Background Investigation (SSBI) or SSBI Periodic Review (SBPR).
• Please Note: U.S. Citizenship is required.
#LI-DB1
#MTSIJobs

About Modern Technology Solutions, Inc.

Provides engineering, technology, and cybersecurity services for national security.

Year founded
1993
Employees
3000
Organization type
Private
Headquarters
US

Similar jobs

Information Systems Security Engineer roles near Dayton, Ohio
2w
Save
Mark Applied
Hide
Information Systems Security Engineer
Wright-Patterson Air Force Base, Ohio, United States
$99k-$225k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
7+ YOE7+ years implementing NIST RMF, TS/SCI clearance, experience with RMF artifacts and vulnerability mitigation, SEIM tools, network/device support, and interfacing with stakeholders.
Palo Alto, data transport, Cisco, Splunk, Elastic, SEIM, eMASS, AWS, Azure
2w
Save
Mark Applied
Hide
Information Systems Security Engineer
Wright Patterson AFB, Ohio, United States
$99k-$225k/yr OnsiteFull Time
Booz Allen Hamilton
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
7+ YOE7+ years implementing NIST RMF, TS/SCI clearance required, DoD 8570 IAM Level II, HS diploma/GED, 3+ years ISSO/ISSM leadership, RMF artifact experience, SEIM (Splunk/Elastic), Cisco/Palo Alto experience.
NIST Risk Management Framework (RMF), Palo Alto, Cisco, Splunk, Elastic, SEIM, eMASS, AWS, Azure
3w
Save
Mark Applied
Hide
Principal Information Systems Security Engineer (ISSE)
Beavercreek, Ohio, United States
OnsiteFull Time
KBR
KBRNYSE: KBR: Provides engineering, technology, and professional services for global markets.
15+ YOEActive TS/SCI clearance, 15+ years cybersecurity/IT experience with a Bachelor's (or 18+ years without), DoD 8570 compliance, RMF and DISA STIG/SRG expertise, ACAS and eMASS experience, SAP experience preferred.
Assured Compliance Assessment Solution (ACAS), eMASS, Fortify, WebInspect, AppDetective, HBSS, NIST 800-53, DISA STIGs, DISA SRGs
1mo
Save
Mark Applied
Hide
Cyber Security Engineer - Information Systems Security Engineer (ISSE) - Senior Principal
Wright-Patterson AFB or Bedford
OnsiteFull Time
Modern Technology Solutions
Modern Technology Solutions: A technology and engineering services that provides cybersecurity and defense support to government customers.
18+ YOE18+ years cybersecurity experience; knowledge of DoD/NIST/JSIG/ICD guidance; active Top Secret/SCI clearance; bachelor's degree in related field (master's preferred); CISSP/CCSP/AWS certs preferred; US citizenship required.
DoD 8500.1-M, DoDM 5205.07, Joint SAP Implementation Guide (JSIG), NIST Special Publication 800-53, Intelligence Community Directive (ICD) 503, DISA Security Technical Implementation Guide (STIG), COMSEC, AWS