Information Security Systems Engineer
Listed on 2026-01-16
-
IT/Tech
Cybersecurity, Systems Engineer
Overview
Company Overview By Light Professional IT Services LLC readies warfighters and federal agencies with technology and systems engineered to connect, protect, and prepare individuals and teams for whatever comes next. Headquartered in McLean, VA, By Light supports defense, civilian, and commercial IT customers worldwide.
Cole Engineering Services (CESI), a By Light company, is recognized as a premier provider of modeling and simulation (M&S) training solutions to the Federal Government and industry. Since 2004, CESI has been at the forefront of developing, maintaining, and integrating simulation-based training, serious gaming, technical services, training and other support in live, virtual, constructive, and gaming (LVCG) domains. CESI also designs, builds and runs infrastructure, platforms, applications and processes that enable cyber training for the integrated multi-domain force.
Our vision is to become a worldwide full spectrum LVCG and cyber training/analysis developer, integrator and services provider.
The ISSE will conduct information system security engineering activities for new and existing systems to ensure cyber security and maintain compliance with all applicable Government cyber security requirements.
This position is located onsite, Annapolis Junction, MD.
Responsibilities- Defines information security requirements and their integration into information systems and its technology component through purposeful security design.
- Develop and implement security designs ensurse the hardware, operating systems and software applications adequately address cyber security requirements and Security Controls Traceability Matrix (SCTM).
- Identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations and recommend mitigation strategies.
- Implement, validate Security Technical Implementation Guide (STIG) requirements and/or perform SRG assessments for all development and implementation projects.
- Develops Security Test Procedure (STP), conducts self-assessments to verify compliance with required configuration guidance and support A&A testing and validation of security designs.
- Conducts risk analysis reviewing ACAS, CVEs, plugins, CWEs, research, collaborating with System Administrators to mitigate identified vulnerabilities and/or author Plans of Actions and Milestones (PO&AM) as needed.
- Execution of continuous monitoring efforts responds to data calls, scan requests, and various weekly and monthly security metrics reporting requirements.
- Participates in Agile Planning Events to provide technical input.
- Support security authorization activities in compliance with the customer Information System Certification and Accreditation Process following the NIST Risk Management Framework (RMF), CNSSI No 1243 and other prescribed business processes for security engineering.
- Assist architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of Agency security policy and enterprise solutions.
- Perform other duties as assigned.
- 5+ years of information security experience as a contractor in the DoD and IC community.
- Demonstrated experience in Liunx, Windows Server, and/or Networking Appliances.
- Demonstrated experience with DISA Security Technical Implementation Guide (STIG) implementation and Security Content Automation Protocol (SCAP) tool usage.
- Demonstrated experience performing Systems Security tasks including Security Information and Event Monitoring, Endpoint Security, and Compliance and vulnerability scanning.
- Demonstrated experience with creating and validating evidence for NIST security controls.
- Bachelor’s degree in a technical field or relevant experience.
- DoD 8570 IAT Level III certification or ability to achieve certification within 6 months of start of employment.
- Skilled in implementing mitigation strategies and how to resolve problems, and to re-test/ re-evaluate systems.
- Possess a working knowledge of administrating servers, system and application security threats and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).