Information Systems Security Engineer (ISSE)

Posted Yesterday
Be an Early Applicant
Sterling, VA, USA
In-Office
73K-149K Annually
Senior level
Information Technology • Consulting • Defense
The Role
Design, implement, and maintain secure systems in classified environments by integrating security throughout the SDLC. Lead RMF A&A activities to achieve and maintain ATOs, perform DISA STIG hardening and SCAP vulnerability assessments, automate compliance, support continuous monitoring, and coordinate remediation with development and infrastructure teams. Engage with customer security stakeholders and support incident response and forensic activities.
Summary Generated by Built In
Job Title: Information Systems Security Engineer (ISSE)

Job Category: Security

Time Type: Full time

Minimum Clearance Required to Start: TS/SCI

Employee Type: Regular

Percentage of Travel Required: Up to 25%

Type of Travel: Continental US

* * *

The Opportunity:

We are seeking a highly motivated Information Systems Security Engineer (ISSE) to support the security, accreditation, and continuous monitoring of advanced mission-critical collection systems operating within complex classified environments. This role offers the opportunity to influence both current and next-generation system architectures by integrating security throughout the system development lifecycle and ensuring compliance with evolving cybersecurity requirements.

As part of a collaborative team of engineers, cybersecurity professionals, and software developers, you will play a critical role in designing, implementing, assessing, and maintaining secure solutions that support our customer's mission. We are looking for an individual who embraces continuous learning, process improvement, and innovation while helping shape the future security posture of our systems.

This position provides opportunities to work with cutting-edge technologies, engage directly with customer security stakeholders, and contribute to high-impact national security programs.

This position requires onsite support 100% of the time in Sterling, VA. Domestic and international travel opportunities may be available.
 

Responsibilities:

  • Collaborate with software, systems, network, and DevOps engineers to integrate cybersecurity requirements throughout the System Development Life Cycle (SDLC).
  • Lead and support Assessment and Authorization (A&A) activities to achieve and maintain Authorization to Operate (ATO) under the Risk Management Framework (RMF).
  • Partner directly with customer Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), and Authorizing Officials (AOs) to navigate accreditation efforts and resolve compliance-related findings.
  • Develop, maintain, and update RMF security documentation, including:
    • System Security Plans (SSPs)
    • Security Assessment Reports (SARs)
    • Security Control Traceability Matrices (SCTMs)
    • Plan of Action and Milestones (POA&Ms)
    • Security Test Plans and Procedures
  • Conduct security control assessments and validation activities aligned with ICD 503, NIST 800-53, CNSSI, and DoD cybersecurity requirements.
  • Perform system hardening and security baseline implementation using DISA STIGs, Security Technical Implementation Guides, and industry best practices.
  • Execute and analyze DISA SCAP scans, vulnerability assessments, and compliance audits to identify security gaps and remediation requirements.
  • Coordinate remediation efforts with development and infrastructure teams to address vulnerabilities, configuration deficiencies, and compliance findings.
  • Monitor system security posture and support Continuous Monitoring (ConMon) activities, including vulnerability management, patch compliance, and security reporting.
  • Evaluate system architectures, network designs, and software solutions to identify potential security risks and recommend mitigations.
  • Support security incident response activities, forensic investigations, and root-cause analysis efforts when required.
  • Review system changes, software releases, and infrastructure modifications for security impacts and RMF compliance.
  • Assist in developing cybersecurity strategies, security engineering plans, and risk management approaches for future system capabilities.
  • Automate compliance validation, system auditing, and security reporting through scripting and security tooling.
  • Support secure configuration management processes and Infrastructure-as-Code (IaC) initiatives to improve consistency, repeatability, and compliance.
  • Participate in Agile development ceremonies and provide cybersecurity guidance throughout sprint planning, design reviews, and release cycles.
  • Stay current on emerging cybersecurity threats, DoD policies, security technologies, and industry best practices to continuously improve security posture.

Qualifications:
Required: 

  • 5+ years of experience as an Information Systems Security Engineer (ISSE), Information Assurance Engineer, Cybersecurity Engineer, and/or Linux Systems Administrator.
  • Active Top Secret clearance with SCI eligibility.
  • DoD 8570/8140 IAT Level II certification (Security+ CE, CySA+, SSCP, or higher).
  • Strong understanding of Risk Management Framework (RMF), ICD 503, and NIST 800-53 security controls.
  • Experience supporting systems through the ATO lifecycle, including accreditation and continuous monitoring activities.
  • Hands-on experience with Linux administration and security hardening in classified or enterprise environments.
  • Experience implementing and validating DISA STIG compliance.
  • Experience executing and interpreting DISA SCAP scans and vulnerability assessment results.
  • Proficiency with BASH, Python, or other scripting languages to automate security compliance and system administration tasks.
  • Strong understanding of system security principles, vulnerability management, and secure system configuration.
  • Excellent verbal and written communication skills with the ability to interact effectively with technical teams, management, and government stakeholders.
  • Bachelor's degree in Systems Engineering, Software Engineering, Electrical Engineering, Computer Science, Cybersecurity, or a related technical discipline. Equivalent education and relevant experience may be considered

Desired:

  • Experience working within Agile and DevSecOps environments.
  • Knowledge of Infrastructure-as-Code (IaC) tools such as Puppet or Ansible.
  • Experience supporting Cross Domain Solutions (CDS) or other highly secure mission systems.
  • Familiarity with Git, GitLab, GitHub, or other version control platforms.
  • Experience with automated compliance tools such as ACAS, Nessus, SCAP Compliance Checker, or HBSS/ePO.
  • Understanding of cloud security principles within AWS, Azure, or hybrid environments.
  • Experience developing security automation, compliance-as-code, or continuous compliance solutions.
  • CISSP, CASP+, GSLC, or other advanced cybersecurity certifications preferred.

-

What You Can Expect:

 A culture of integrity.

At CACI, we place character and innovation at the center of everything we do. As a valued team member, you’ll be part of a high-performing group dedicated to our customer’s missions and driven by a higher purpose – to ensure the safety of our nation.

An environment of trust.

CACI values the unique contributions that every employee brings to our company and our customers - every day. You’ll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.

A focus on continuous growth.

Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground — in your career and in our legacy.

Pay Range:

There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.

The proposed salary range for this position is:

$72,700 - $149,200

CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.

Skills Required

  • 5+ years of experience as an Information Systems Security Engineer, Information Assurance Engineer, Cybersecurity Engineer, or Linux Systems Administrator
  • Active Top Secret clearance with SCI eligibility
  • DoD 8570/8140 IAT Level II certification (Security+ CE, CySA+, SSCP, or higher)
  • Strong understanding of RMF, ICD 503, and NIST 800-53 security controls
  • Experience supporting systems through the ATO lifecycle, including accreditation and continuous monitoring
  • Hands-on Linux administration and security hardening experience
  • Experience implementing and validating DISA STIG compliance
  • Experience executing and interpreting DISA SCAP scans and vulnerability assessment results
  • Proficiency with BASH, Python, or other scripting languages to automate security and system administration tasks
  • Strong understanding of system security principles, vulnerability management, and secure configuration
  • Excellent verbal and written communication skills for interacting with technical teams and government stakeholders
  • Bachelor's degree in Systems Engineering, Software Engineering, Electrical Engineering, Computer Science, Cybersecurity, or related technical discipline (or equivalent experience)
  • Experience working within Agile and DevSecOps environments
  • Knowledge of Infrastructure-as-Code (IaC) tools such as Puppet or Ansible
  • Experience supporting Cross Domain Solutions (CDS) or other highly secure mission systems
  • Familiarity with Git, GitLab, GitHub, or other version control platforms
  • Experience with automated compliance tools such as ACAS, Nessus, SCAP Compliance Checker, or HBSS/ePO
  • Understanding of cloud security principles within AWS, Azure, or hybrid environments
  • Experience developing security automation, compliance-as-code, or continuous compliance solutions
  • Advanced certifications such as CISSP, CASP+, GSLC

CACI International Inc Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about CACI International Inc and has not been reviewed or approved by CACI International Inc.

  • Healthcare Strength Pay is supported by a broad set of health-plan options across multiple national carriers, with telemedicine and tax-advantaged accounts included. Dental and vision choices are also described as multi-option, which strengthens overall coverage breadth.
  • Leave & Time Off Breadth Flexible Time Off is available for many salaried-exempt roles, while hourly roles accrue PTO, creating multiple time-off pathways by employment class. Paid disability coverage, fixed holidays, and paid leave programs (including parental leave and other leave types) further round out time-off and leave coverage.
  • Retirement Support Retirement support includes a 401(k) match structure described as 50% up to 8% of pay (effective 4%) and an Employee Stock Purchase Plan with a discount. Tuition reimbursement and certification support also add to the overall rewards package that complements core retirement benefits.

CACI International Inc Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Reston, VA
17,673 Employees
Year Founded: 1962

What We Do

CACI’s approximately 23,000 talented employees are vigilant in providing the unique expertise and distinctive technology that address our customers’ greatest enterprise and mission challenges. Our culture of good character, innovation, and excellence drives our success and earns us recognition as a Fortune World's Most Admired Company. As a member of the Fortune 1000 Largest Companies, the Russell 1000 Index, and the S&P MidCap 400 Index, we consistently deliver strong shareholder value. Visit us at www.caci.com.

Similar Jobs

CACI International Inc Logo CACI International Inc

Security Engineer

Information Technology • Consulting • Defense
In-Office
Sterling, VA, USA
17673 Employees
121K-266K Annually

CACI International Inc Logo CACI International Inc

Security Engineer

Information Technology • Consulting • Defense
In-Office
Norfolk, VA, USA
17673 Employees
75K-158K Annually

Amentum Logo Amentum

Security Engineer

Security • Cybersecurity
In-Office
Chantilly, VA, USA
18261 Employees
190K-225K Annually

The Swift Group, LLC Logo The Swift Group, LLC

Security Engineer

Information Technology • Business Intelligence • Consulting • Defense
In-Office
Fort Belvoir, VA, USA
104 Employees
50K-290K Annually

Similar Companies Hiring

NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees
Outpost Space Thumbnail
Aerospace • Defense
US
24 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account