Mantis Security Corporation
Posted 3mo ago

Information Systems Security Engineer (ISSE)

Mantis Security Corporation
Reston, Virginia, United States
OnsiteFull Time
Responsibilities
  • Develops designs
  • Identifies vulnerabilities
  • Configures Splunk
Requirements
  • US citizen
  • 8+ years experience with BS in CS/IS/ISSE or related
  • DoD 8570 IASAE Level 3
  • 3 years scripting/Linux
  • ISSEP and CISSP
  • TS/SCI with polygraph
Technical tools mentioned
LinuxRedHatScripting (Shell, Python, JavaScript, PowerShell)Security Technical Implementation Guide (STIG)SCAPSplunk

Job description

Description

Mantis Security is a leading specialty firm of high caliber talent who specialize in Cyber Operations, Cyber Defense, Information Assurance, Software Development, DevSecOps, Security Engineering, and Cloud Engineering. We enable and protect our nation's most important IT assets and invest in the long-term career development of every employee! We are currently looking for the next Information Systems Security Engineer (ISSE) to join our team of experts!

As an ISSE on the Mantis Security Team, you will define information security requirements and their integration into information systems and its technology component through purposeful security design.

What You'll Be Doing:
• Develops and implements security designs ensure that the hardware, operating systems and software applications adequately address cyber security requirements and Security Controls Traceability Matrix (SCTM).
• Identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations and recommend mitigation strategies.
Implement, validate Security Technical Implementation Guide (STIG) requirements and/or perform SRG assessments for all development and implementation projects.
• Develop, customize, and configure Splunk applications and dashboards.
• Develop Security Test Procedure (STP), conducts self-assessments to verify compliance with required configuration guidance and support A&A testing and validation of security designs.
• Conducting risk analysis reviewing ACAS, CVEs, plugins, CWEs, research, collaborate with System Administrators to mitigate identified vulnerabilities and/or author Plans of Actions and Milestones (PO&AM) as needed.
• Execution of continuous monitoring efforts responds to data calls, scan requests, and various weekly and monthly security metrics reporting requirements.
• Validate control implementations provide enforcement of the require data access and network flow restrictions align with the continuous monitoring strategy.
• Participates in Agile Planning Events to provide technical input.
• Support government activities and reporting to appropriate IC and DoD authorities (i.e., USCYBERCOM, IC-SCC)
• Support security authorization activities in compliance with the customer Information System Certification and Accreditation Process following the NIST Risk Management Framework (RMF), CNSSI No 1243 and other prescribed business processes for security engineering.
• Assist architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of Agency security policy and enterprise solutions.
• Apply system security engineering expertise in one or more of the following to: system security design process; engineering life cycle; information domain; cross domain solutions; commercial off-the-shelf and government off-the-shelf cryptography; identification; authentication; and authorization; system integration; risk management; intrusion detection; contingency planning; incident handling; configuration control; change management; auditing; certification and accreditation process; principles of IA (confidentiality, integrity, non-repudiation, availability, and access control); and security testing.

Requirements

Must Haves:

• Must be a US Citizen
• 8 years of relevant experience and a Bachelor’s degree in Computer Science, Information Assurance, Information Security System Engineering, or related discipline from an accredited college or university is required. A Master’s degree in Computer Science, Information Assurance, Information Security System Engineering, or related discipline may be substituted for two (2) years of additional experience. Four (4) years of additional ISSE experience may be substituted for a bachelor’s degree.
• DoD 8570 compliance with IASAE Level 3 is required
• Three (3) years of experience in scripting languages, Linux/RedHat, and/or Networking Appliances
Information Systems Security Engineering Professional (ISSEP) and CISSP Certifications are required
• Active TS/SCI security clearance with the ability to obtain polygraph is required

Nice to Haves:

• Skilled in implementing mitigation strategies and how to resolve problems, and to re-test/ re-evaluate systems
• Demonstrated experience with DISA Security Technical Implementation Guide (STIG) implementation and Security Content Automation Protocol (SCAP) tool usage
• Possess a working knowledge of administrating servers, system and application security threats and vulnerabilities
• Experience extending existing applications in areas such as security, monitoring, task automation, continuous integration, deployment, and performance optimization
• Demonstrate writing of your own project in scripting/programming (use of Shell scripting, Python, JavaScript, PowerShell) in a Linux or Windows environment to support the various Cyber Security tools and applications required
• Provide guidance on vulnerability and malware remediation.
• Experience analyzing vulnerabilities, establishing cause and impact, and identifying the corrective action needed to eliminate and prevent the event from happening in the future.

About Mantis Security Corporation

Privately held cybersecurity consulting firm serving U.S. intelligence, defense, federal government, and financial-sector clients.

Similar jobs

Information Systems Security Engineer (ISSE) roles near Reston, Virginia
4mo
Save
Mark Applied
Hide
Information Systems Security Engineer (ISSE)
Washington, District of Columbia, United States
OnsiteFull Time
Modern Technology Solutions, Inc.
Modern Technology Solutions, Inc.: Engineering services and technology solutions for national security.
10+ YOE10+ years in cybersecurity/IT/systems engineering; SAP experience; strong RMA and risk assessment skills; excellent communication.
Java, Python, Ruby, C++, Linux (RedHat/RHEL/CentOS), Dynamic & Static Application Security Scanning, Virtualization and containers (EC2, Docker), Vulnerability Scanning (Nessus)
6mo
Save
Mark Applied
Hide
Information Systems Security Engineer (ISSE) [Full Scope Polygraph]
Annapolis Junction, Maryland, United States
$165k-$275k/yr OnsiteFull Time
Modern Technology Solutions, Inc.
Modern Technology Solutions, Inc.: Engineering services and technology solutions for national security.
TS/SCI with Full Scope Polygraph; experience as ISSE; strong leadership and communication; master’s or bachelor’s in computer science or related field.
11mo
Save
Mark Applied
Hide
Cleared Information Systems Security Engineer (ISSE) L3 *
Lorton, Virginia, United States
$140k-$180k/yr OnsiteFull Time
Virtual Service Operations
Virtual Service Operations: Veteran-led managed IT services provider serving government, defense, healthcare, and other regulated commercial organizations.
5+ YOEISSE with DoD 8570 Level III, TS/SCI, 5+ years in related tech; skills in AD, ePO, Splunk, ACAS, STIG/SCAP, Azure, and DoD policies.
Active Directory, ePO, Splunk, STIG/SCAP, ACAS, Azure Monitor/Log Analytics, Azure VPN Gateways, WSUS, YUM
1y
Save
Mark Applied
Hide
Information Security Systems Engineer / ISSE (NSWC IHD Code 104)
Indian Head, Maryland, United States
OnsiteFull Time
EHS Technologies
EHS Technologies: Women-owned IT, cybersecurity, engineering, logistics, and environmental services firm serving U.S. defense and government clients.
5+ YOEFive years of cybersecurity experience; expert with ACAS; Windows/Linux patching and configuration; ACAS server deployment and troubleshooting; U.S. citizenship with active DoD Secret clearance.
ACAS, Windows, Linux, Patching, System configuration, Server deployment, Troubleshooting
3y
Save
Mark Applied
Hide
Information Systems Security Engineer (ISSE)
Reston, Virginia, United States
OnsiteFull Time
Mantis Security Corporation
Mantis Security Corporation: Privately held cybersecurity consulting firm serving U.S. intelligence, defense, federal government, and financial-sector clients.
8+ YOEEight years of relevant experience; DoD 8570 IASAE Level 3; US citizen; BS in CS/IA/ISSE (MS can substitute 2 years); TS/SCI with poly; CISSP/ISSEP certifications.
Splunk, STIG, SCAP, ACAS, RMF, NIST SP 800-53
3y
Save
Mark Applied
Hide
Information Systems Security Engineer (ISSE) Level 3
Fort Meade, Maryland, United States
OnsiteFull Time
The Birchmere Group
The Birchmere Group: Minority-owned, service-disabled veteran-owned technology consulting firm providing cybersecurity and acquisition services to government clients.
20+ YOEExperienced ISSE with TS/SCI and polygraph; 20+ years in cybersecurity, DoD RMF/NISCAP, IA/PKI, and risk management; degrees in CS/IS; IASAE Level 3; CISSP/ISSEP.
DoD RMF, NIST RMF, PKI, Cybersecurity standards, C&A documentation, NISCAP, NIST SP 800-37/53, NSA/CSS policies