Information Systems Security Engineer

Full Time Mid Level

Posted 3 weeks ago

Interested in this position?

Upload your resume and we'll match you with this and other relevant opportunities.

Upload Your Resume

About This Role

This Information Systems Security Engineer (ISSE) role supports mission-critical systems related to national security, focusing on continuous monitoring, vulnerability management, and security control implementation across complex enterprise environments. The position is for a security professional who excels in deep technical work within a high-trust federal setting.

Responsibilities

  • Review, document, and maintain Continuous Monitoring (CONMON) activities
  • Review and analyze audit logs weekly for each system, identifying trends, anomalies, and security findings
  • Track system vulnerabilities across multiple tools and platforms
  • Apply STIGs and implement mitigations
  • Assist with and perform SCAP scans
  • Apply and manage Nessus plugins and ensure proper scan configurations
  • Review and analyze Nessus and Enterprise ACAS scans, mitigating findings and creating POA&Ms
  • Review systems for IAVAs and IAVMs, ensuring proper mitigation and documentation
  • Provide input into Security Control Implementation and RMF artifacts
  • Review and approve software products, patches, and updates, and submit software packages for customer approval
  • Review System Test Procedures with System Administrators to validate system functionality
  • Document procedures in System Test Plans for each system and ensure security requirements are met throughout the system lifecycle
  • Attend and actively participate in Configuration Change Board (CCB) meetings
  • Support the creation, review, and validation of security requirements
  • Partner with technical teams to balance mission needs with security best practices

Requirements

  • Active CI Polygraph clearance
  • Strong experience supporting classified systems in a federal environment
  • Hands-on experience with vulnerability scanning and remediation
  • Hands-on experience with POA&M development and tracking
  • Hands-on experience with RMF / NIST security controls
  • Experience working with system administrators and engineers

Nice to Have

  • Experience using Splunk for audit log analysis and security monitoring
  • Familiarity with Nessus / ACAS
  • Familiarity with STIGs and SCAP
  • Familiarity with CCB and SCRM processes

Skills

Splunk * ACAS * RMF * NIST * STIGs * Nessus * SCAP *

* Required skills

About Ortman Consulting LLC

Technology
View all jobs at Ortman Consulting LLC →