The Role
Provides information security engineering support for lifecycle assessment and authorization, including developing security plans, risk assessments, certification reports, audit artifacts, and operating procedures. Coordinates system testing, tracks authorization projects, manages security documentation, reviews procurements, and advises on policy and technical controls. Monitors cyber risks such as malware, zero-day attacks, and denial-of-service attacks while supporting deployed infrastructure and technical solutions.
Summary Generated by Built In
We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.
SAIC is seeking an Information System Security Engineer (ISSE) to provide information security support. This position is in McLean, VA and requires an active TS/SCI clearance with Polygraph.
This Customer's office is the force of choice for the development of global infrastructure and delivery of solutions that drive influence operations. If you have specialized skills in information security and tech ops, this is the role for you.
Job responsibilities include, but are not limited to:
- Support the Lifecycle Assessment and Authorization (A&A) process.
- Develop a Systems Security Plan (SSP).
- Assist and maintain a formal Information Security Program that includes recommendations on continuous improvement of the processes and architectures.
- Maintain and make accessible documentation of all operational and business process activities in the form of Standard Operating Procedures (SOPs).
- Monitor and track projects in the A&A queue.
- Analyze SSPs to develop an understanding of the customer's systems and applications.
- Coordinate A&A actions and system testing with appropriate security personnel.
- Develop risk assessments, recommend mitigating countermeasures, and write short, succinct risk assessments, and certification reports for submission to the Chief Information Officer (CIO).
- Monitor and track projects in the A&A queue.
- Maintain a document repository where A&A project documentation is stored and recorded and register actions concerning project approvals to operate in the A&A database.
- Assemble and submit A&A packages to the Principal Accreditation Authority or Designated Accreditation Authority.
- Review and approve product requests for procurements.
- Provide security guidance in terms of policy and technical implementation of those policies.
- Produce and assist with production of technical artifacts required for A&A packages such as a System Security Plan, Audit Strategy.
- Configuration Management Plan, Security Controls Traceability Matrix, Project Plan of Action and Milestones.
- Monitor and address cyber risks such as malware, zero-day attacks, denial of service attacks, as well as associated mitigations regarding computer and network devices.
- Active TS/SCI with Polygraph.
- Bachelor's degree and 14 years or more experience; Master's degree and 12 years or more experience; PhD and 9 years or more experience.
- CISSP Certification.
- Demonstrated experience with:
- Computer networking in Windows AND Linux.
- Website configuration.
- Basic software development knowledge.
- Eliciting information on complex technical problems from non-technical personnel for use in diagnosis, analysis, resolution of problems.
- Customer regulations and standards, including Information Security (INFOSEC) and Communications Security (COMSEC).
- Managing security aspects of deployed infrastructure and technical solutions.
Desired Skills:
- Demonstrated experience with Rapid7, WebInspect, AppDetective, CIS-CAT, and other vulnerability assessment tools and processes.
- Information security certifications such as CISSP, CISSE, CISA, CEH, CCSP, etc.
- Demonstrated experience with computer and network vulnerabilities (e.g., malware, zero-day attacks, denial of service attacks, etc.).
We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.
Skills Required
- Active TS/SCI clearance with polygraph
- Bachelor's degree and 14 or more years of experience, or Master's degree and 12 or more years, or PhD and 9 or more years
- CISSP certification
- Experience with computer networking in Windows and Linux
- Experience with website configuration
- Basic software development knowledge
- Experience eliciting information about complex technical problems from non-technical personnel
- Knowledge of customer regulations and standards, including INFOSEC and COMSEC
- Experience managing security aspects of deployed infrastructure and technical solutions
- Experience with Rapid7, WebInspect, AppDetective, CIS-CAT, and other vulnerability assessment tools
- Additional information security certifications such as CISSE, CISA, CEH, or CCSP
- Experience with computer and network vulnerabilities, including malware, zero-day attacks, and denial-of-service attacks
Am I A Good Fit?
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.
Success! Refresh the page to see how your skills align with this role.
The Company
What We Do
Spectrum San Diego is a high tech security innovator, specializing in ultra-low-dose X-ray screening systems.








