Cyber Systems Engineer/ Information System Security Engineer (ISSE)

Posted 3 Days Ago
Be an Early Applicant
Washington, DC, USA
In-Office
180K-220K Annually
Mid level
Security • Cybersecurity
The Role
Lead security authorization and assessment activities for government information systems under RMF, ICD, DIA, and DoD requirements. Develop and maintain security documentation, collect and analyze security artifacts, track ATD, IATT, and ATO milestones, manage POA&Ms, support audits and continuous monitoring, evaluate emerging threats, and recommend security improvements. Coordinate with ISSMs, assessors, program managers, system owners, engineers, and leadership while reviewing technical documentation for compliance and accuracy.
Summary Generated by Built In

As a Cyber Systems Engineer/ Information System Security Engineer (ISSE) at Amentum, you will play a vital role in safeguarding national security by protecting the integrity, confidentiality, and availability of government-affiliated information systems. Your expertise will directly support critical defense and intelligence missions, ensuring that cybersecurity risks are identified, mitigated, and continuously monitored in alignment with stringent DoD and DIA standards.


By serving as the primary security advisor for assigned systems, your work will not only ensure operational compliance but will also contribute to the resilience and trustworthiness of mission-critical infrastructure relied upon by U.S. government agencies. Through close collaboration with engineers, system administrators, government clients, and security assessors, you will help design and maintain secure environments where innovation and mission success are achieved without compromising cybersecurity.


Your contributions will have a lasting impact, enabling rapid threat response, reduced risk exposure, and the sustained protection of sensitive data and digital assets vital to national defense and intelligence operations.


Essential Responsibilities:


·   Lead Security Authorization Efforts: Oversee and coordinate the Assessment & Authorization (A&A) processes in alignment with Risk Management Framework (RMF) and Intelligence Community Directives (ICD). This includes interfacing with Group-level Information Systems Security Managers (ISSMs) and Security Controls Assessors (SCAs) to ensure thorough and timely security reviews.


· Develop and Maintain Security Documentation: Prepare and maintain essential security documentation such as System Security Plans (SSPs), Concept of Operations (CONOPS), Contingency Plans (CP), General User Guides (GUG), Privileged User Guides (PUG), and Standard Operating Procedures (SOPs). Ensure documentation accurately reflects the current system architecture and security posture.


· Collect and Analyze Security Artifacts: Coordinate with program managers, system owners, and engineering teams to collect Bodies of Evidence (BoEs) and artifacts necessary for A&A. Analyze and compile documentation that supports security control implementations and Plan of Action & Milestones (POA&Ms) mitigation strategies.


· Coordinate Authorization Milestones: Facilitate and track progress through customer A&A processes to achieve key security milestones such as Authority to Develop (ATD), Interim Authority to Test (IATT), and Authority to Operate (ATO). Maintain up-to-date knowledge of each project's A&A status and communicate updates effectively across technical and leadership levels.


· Support Security Compliance and Audit Activities: Act as a liaison during audits and compliance assessments, supporting continuous monitoring and promoting adherence to RMF, DIA policy, IC guidance, and applicable federal laws. Assist in the annual updates of Information Security Continuous Monitoring (ISCM) and Organizational Assessment (OA) Strategy Plans.


· Evaluate and Respond to Emerging Threats: Review and revise control volatility sections of security plans in response to evolving threats, policy changes, and updated federal or agency guidance. Provide input on High Value Assets (HVAs), and systems classified at TS/SCI or Secret levels, ensuring appropriate protections are in place.


· Deliver Recommendations and Process Improvements: Generate actionable recommendations to enhance the security program. Identify inefficiencies in current processes and propose improvements based on best practices, audit findings, and lessons learned.


· Technical Content Review: Perform detailed technical and editorial reviews of A&A documentation, ensuring clarity, accuracy, and compliance with relevant standards and frameworks.


Minimum Requirements:


·   In-depth understanding of the Risk Management Framework (RMF) lifecycle and Intelligence Community Directives (ICDs), particularly ICD 503.


· Ability to lead and coordinate all phases of the A&A process, from system categorization to authorization and continuous monitoring.


· Demonstrated experience engaging with Group-level ISSMs, SCAs, and other key stakeholders to facilitate timely and thorough security reviews.


· Proficiency in interpreting security requirements and guiding implementation across complex system architectures.


· Experience coordinating with PMs, system owners, and engineering teams to gather required Bodies of Evidence (BoEs).


· Strong analytical skills to assess artifacts and ensure alignment with RMF controls and A&A package requirements.


· Ability to track and document Plan of Action and Milestones (POA&Ms), and work with stakeholders to ensure timely mitigation and evidence collection.


· Understanding of key cybersecurity milestones including:

  • Authority to Develop (ATD)
  • Interim Authority to Test (IATT)
  • Authority to Operate (ATO)

· Proven ability to track project status, escalate delays, and maintain open communication with both technical teams and leadership.


· Experience navigating customer-specific A&A processes, tools, and review boards.


· Experience supporting internal and external audits, including liaising with auditors and preparing for compliance assessments.


· Familiarity with Information Security Continuous Monitoring (ISCM) strategies and implementation.


· Understanding of agency-specific compliance standards including DIA policies, DoD directives, and federal cybersecurity laws.


· Ability to support and update Organizational Assessment (OA) Strategy Plans annually or as required.


· Ability to perform threat modeling and incorporate emerging threats into the security control strategy.


· Knowledge of High Value Asset (HVA) protection requirements and protocols for systems classified as Top Secret, SCI, and Secret.


· Experience with dynamic updates to the control volatility section of SSPs in response to:

  • Policy changes
  • New threat intelligence
  • Updated guidance from DIA, IC, NIST, etc.

· Experience conducting gap analyses, risk assessments, and security posture evaluations.


· Ability to recommend policy, process, or technical improvements based on A&A findings, lessons learned, and audit outcomes.


· Demonstrated ability to document findings and present them in a clear, actionable format to stakeholders.


· Strong writing and technical editing skills to review A&A documentation for:

  • Compliance with standards
  • Technical accuracy
  • Readability and consistency

· Familiarity with collaborative review processes and version control tools (e.g., SharePoint, Confluence, Git, etc.).


· Must hold and maintain a DoD 8570.01-M IASAE Level II certification


Clearance Required: TS/SCI w/ Poly


Minimum Education:

 Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field. (Relevant experience may substitute for education.)


Minimum Years of Experience:

3–5 years of experience in information system security or cybersecurity roles.


Required Certifications:

  • Must hold and maintain a DoD 8570.01-M IASAE Level II certification

Other Responsibilities:


Safety - Amentum enforces a safety culture whereby all employees have the responsibility for continuously developing and maintaining a safe work environment. As appropriate, each employee is responsible for completing all training requirements and fulfilling all self-aid/buddy aid responsibilities, participating in emergency response tasks and serving on safety committees and teams.


Quality - Quality is the foundation for the management of our business and the keystone to our goal of customer satisfaction. It is our policy to consistently provide services that meet customer expectations. Accordingly, each employee must conform to the Amentum Quality Policy and carry out job activities in compliance with applicable Amentum Quality System documents and customer contracts. Each employee must read and understand his/her Quality Management and Customer Satisfaction responsibilities.


Procedure Compliance - Each employee must read, understand and implement the general and specific operational, safety, quality and environmental requirements of all plans, procedures and policies pertaining to his/her job. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status.


#javelin 

       

Compensation Details:

$180,000 - $220,000

       

The compensation range or hourly rate listed for this position is provided as a good-faith estimate of what the company intends to offer for this role at the time this posting was issued. Actual compensation may vary based on factors such as job responsibilities, education, experience, skills, internal equity, market data, applicable collective bargaining agreements, and relevant laws.


Benefits Overview:

Our health and welfare benefits are designed to support you and your priorities. Offerings include:

  • Health, dental, and vision insurance

  • Paid time off and holidays

  • Retirement benefits (including 401(k) matching)

  • Educational reimbursement

  • Parental leave

  • Employee stock purchase plan

  • Tax-saving options

  • Disability and life insurance

  • Pet insurance


Note: Benefits may vary based on employment type, location, and applicable agreements. Positions governed by a Collective Bargaining Agreement (CBA), the McNamara-O'Hara Service Contract Act (SCA), or other employment contracts may include different provisions/benefits.

       

Original Posting:

10/01/2026 - Until Filled

Amentum anticipates this job requisition will remain open for at least three days, with a closing date no earlier than three days after the original posting. This timeline may change based on business needs.

       

Amentum is proud to be an Equal Opportunity Employer. Our hiring practices provide equal opportunity for employment without regard to race, sex, sexual orientation, pregnancy (including pregnancy, childbirth, breastfeeding, or medical conditions related to pregnancy, childbirth, or breastfeeding), age, ancestry, United States military or veteran status, color, religion, creed,  marital or domestic partner status, medical condition, genetic information, national origin, citizenship status, low-income status, or mental or physical disability so long as the essential functions of the job can be performed with or without reasonable accommodation, or any other protected category under federal, state, or local law. Learn more about your rights under Federal laws and supplemental language at Labor Laws Posters.

Skills Required

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field; relevant experience may substitute
  • 3-5 years of experience in information system security or cybersecurity roles
  • In-depth understanding of the Risk Management Framework lifecycle and Intelligence Community Directives, particularly ICD 503
  • Experience leading and coordinating all phases of the Assessment and Authorization process
  • Experience engaging with ISSMs, Security Control Assessors, system owners, program managers, and engineering teams
  • Experience collecting and analyzing Bodies of Evidence and security artifacts
  • Experience tracking Plan of Action and Milestones and coordinating mitigation activities
  • Understanding of Authority to Develop, Interim Authority to Test, and Authority to Operate milestones
  • Experience supporting audits, compliance assessments, and security review boards
  • Familiarity with Information Security Continuous Monitoring strategies
  • Knowledge of DIA policies, DoD directives, federal cybersecurity laws, and NIST guidance
  • Ability to update Organizational Assessment Strategy Plans
  • Ability to perform threat modeling, gap analyses, risk assessments, and security posture evaluations
  • Knowledge of High Value Asset protection requirements and systems classified at Top Secret, SCI, or Secret levels
  • Strong technical writing, editing, documentation, and stakeholder presentation skills
  • Familiarity with SharePoint, Confluence, Git, or similar collaborative review and version control tools
  • DoD 8570.01-M IASAE Level II certification
  • TS/SCI clearance with polygraph

Amentum Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Amentum and has not been reviewed or approved by Amentum.

  • Healthcare Strength — Healthcare offerings are described as comprehensive, with medical, dental, and vision plans and multiple PPO/HSA options. Mental health support via an employee assistance program and other wellness resources is also included in the benefits mix.
  • Retirement Support — Retirement support is positioned as a meaningful part of total rewards through a 401(k) plan with employer matching. Profit-sharing contributions and immediate or near-term vesting in some cases further strengthen the retirement value proposition.
  • Leave & Time Off Breadth — Time-off benefits are presented as solid for the sector, including tiered PTO accrual by tenure and a set of paid holidays. Role-dependent flexible or remote work options and leave programs add to perceived work-life support.

Amentum Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chantilly, VA
18,261 Employees

What We Do

Amentum is a premier global technical and engineering services partner supporting critical programs of national significance across defense, security, intelligence, energy, and environment. We draw from a century-old heritage of operational excellence, mission focus, and successful execution underpinned by a strong culture of safety and ethics. Headquartered in Germantown, Md., we employ more than 20,000 people in 48 states and 28 foreign countries and territories. Visit us at amentum.com to explore how we deliver excellence for our customers’ most vital missions.

Similar Jobs

Hilton Logo Hilton

Director Of Sales

Software • Hospitality
In-Office
Washington, DC, USA
121228 Employees
In-Office
Washington, DC, USA
121228 Employees
In-Office
Washington, DC, USA
121228 Employees
Remote or Hybrid
2 Locations
175633 Employees
167K-280K Annually

Similar Companies Hiring

SEON Thumbnail
Artificial Intelligence • Cybersecurity
Budapest, Budapest
415 Employees
Milestone Systems Thumbnail
Artificial Intelligence • Security • Software • Analytics • Big Data Analytics
Lake Oswego, OR
1500 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account