Information Systems Security Engineer (ISSE) - Clearance Required
Job LocationsUS-VA-Tysons | US-PA-Mechanicsburg
Job ID
2024-11271of Openings1Category
LogisticsOverviewLMI seeks a skilled Cybersecurity Information Systems Security Engineer (ISSE) to support activities related to shipyard modernization as part of enterprise-wide U.S. Navy strategic modernization and improvement efforts. LMI is helping NAVSUP, NAVSEA, and the shipyards use technology to track materiel through the shipyards to address long-standing problems.
LMI: Innovation at the Pace of Need
At LMI, we're reimagining the path from insight to outcome at the new speed of possible. Combining a legacy of over 60 years of federal expertise with our innovation ecosystem, we minimize time to value and accelerate mission success. We energize the brightest minds with emerging technologies to inspire creative solutioning and push the boundaries of capability. LMI advances the pace of progress, enabling our customers to thrive while adapting to evolving mission needs.ResponsibilitiesDefine system security requirements in coordination with security stakeholders including system engineers, program managers, security control assessors, and authorizing officials.
Ensure cybersecurity requirements are identified, allocated, implemented, verified, and continuously monitored throughout the system life cycle.
Provide independent cybersecurity advice and guidance to government stakeholders and contractor team members.
Participate in recurring cybersecurity working group meetings.
Develop or review system security designs and architectures, including those for IoT or OT devices.
Support Assessment and Authorization (A&A) cybersecurity reviews, identify gaps, and support risk management plans for cybersecurity personnel to execute.
Support the Risk Management Framework (RMF) process for each product in the portfolio.
Provide SME level cybersecurity engineering support and input to product leads and cybersecurity teams to produce authority to operate (ATO) packages and successfully achieve ATOs.
Support interim authority to test (IATT), risk assessment /acceptance, and all other ATO related activities.
Interpret security control noncompliance to determine the impact on levels of risk and/or overall effectiveness of the enterprise's cybersecurity program.
Work with product teams to identify controls, develop appropriate mitigations, and develop and track Program of Action and Milestone (POAM) documents to ensure that ATO packages are technically sound before submission to the program cyber staff for review.
Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs).
Advise system engineers on the best methods to remediate vulnerability findings through the use of security scanning tools and DoD / Industry best practices.
Support cybersecurity engineering analysis of alternatives, tradeoffs, and risk treatment decisions.
Work with interdisciplinary teams to deliver trustworthy and secure systems.QualificationsRequired:
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field
5 years minimum of system and/or security engineering work performed in support of U.S. Government customers
Experience reviewing and developing of RMF Assessment and Authorization (A&A) documentation, e.g., System Security Plans (SSPs), Security Assessment Reports (SARs), and Plans of Action and Milestones (POAMs)
Experience implementing DoDI 8510.01 Risk Management Framework for DoD
DoD 8570 IASAE Level II baseline certification (CISSP, CCSP, etc.)
Must possess and maintain a Secret Security Clearance
Desired:
Knowledge of Cloud (i.e., Azure, Amazon C2S, Commercial and GovCloud) security planning, design, and operations.
One or more years of experience with networking and network security
Ability to explain complex cy ersecurity issues to a diverse audience in layman's terms.
Experience presenting verbal/written communications to Senior leadership including - Information Systems Security Engineer (ISSM), System Owners, Authorizing officials, and security leads.
Experience with systems engineering lifecycle processes.
Proven ability to balance priorities in a dynamic, mission-oriented environment.
Experience with agile frameworks and Continuous Integration/Continuous Delivery (CI/CD) frameworks such as DevOps or DevSecOps.
Experience with cloud cybersecurity implementations.
DoD 8570 IASAE Level III certification, such CISSP-ISSAP or CISSP-ISSEP or ability to be certified at level III within 6 months of start.LMI is an Equal Opportunity Employer. LMI is committed to the fair treatment of all and to our policy of providing applicants and employees with equal employment opportunities. LMI recruits, hires, trains, and promotes people without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, pregnancy, disability, age, protected veteran status, citizenship status, genetic information, or any other characteristic protected by applicable federal, state, or local law. If you are a person with a disability needing assistance with the application process, please contact [email protected]
Colorado Residents: In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.
Need help finding the right job?We can recommend jobs specifically for you!
Click here to get started.LMI is committed to the fair treatment of all and to our policy of providing applicants and employees with equal employment opportunities. LMI recruits, hires, trains, and promotes people without regard to race, color, religion, sex, sexual orientation, gender identity, pregnancy, age, national origin, disability, veteran status, or any other factors protected by applicable law. We welcome applications for employment from qualified disabled veterans, veterans of the Vietnam era, and other covered veterans.