- Location
- Bloomington, IN
- Department
- Engineering
- Experience
- 5+ years
- Education
- Bachelor
- Visa
- Not sponsored
- Source
- Paylocity
Description
Description
We are seeking a skilled Information System Security Engineer II to join our dynamic team. The Information System Security Engineer (ISSE) II provides mid-level cybersecurity and systems security engineering support for Department of Defense (DoD) systems throughout the system development, integration, testing, deployment, and sustainment lifecycle. The ISSE is responsible for implementing secure system architectures and configurations, developing and maintaining Risk Management Framework (RMF) documentation, assessing security controls, identifying and remediating cybersecurity vulnerabilities, and ensuring systems remain compliant with applicable DoD cybersecurity requirements.
The ISSE II serves as a technical liaison between software development, systems engineering, network administration, cybersecurity, and Information System Security Manager (ISSM) personnel. The position requires the ability to translate cybersecurity requirements into practical engineering solutions and work collaboratively with technical teams to resolve security and compliance deficiencies.
Key Responsibilities
- Develop, update, maintain, and submit RMF security authorization packages within government repositories and tools, including eMASS.
- Support systems throughout the RMF lifecycle, including categorization, security control implementation, assessment, authorization, and continuous monitoring.
- Develop and maintain System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and other required cybersecurity artifacts.
- Conduct security control assessments and assist in identifying, documenting, tracking, and remediating security deficiencies.
- Develop and maintain continuous monitoring strategies to ensure systems remain compliant with established cybersecurity requirements.
- Perform automated and manual vulnerability assessments using tools such as ACAS/Nessus, SCAP, and other approved vulnerability and compliance assessment tools.
- Analyze vulnerability scan results and translate findings into actionable remediation requirements.
- Apply DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) to operating systems, applications, databases, network infrastructure, containers, and other system components as applicable.
- Troubleshoot and resolve cybersecurity compliance gaps, vulnerabilities, and configuration deficiencies.
- Support the development and implementation of secure system architectures, security configurations, access controls, boundary protections, and defense-in-depth solutions.
- Assist with the implementation and integration of security technologies, including ACAS, HBSS/ESS, Security Information and Event Management (SIEM) platforms, intrusion detection/prevention systems (IDS/IPS), firewalls, endpoint security tools, and other cybersecurity capabilities.
- Serve as a technical liaison between software development and systems engineering teams and the ISSM, ensuring cybersecurity requirements are incorporated throughout the system lifecycle.
- Participate in engineering change boards, configuration control boards, and technical reviews to evaluate proposed changes for potential cybersecurity impacts.
- Review system designs, configurations, interfaces, and proposed modifications to ensure changes do not negatively impact the system's security posture or authorization boundary.
- Provide cybersecurity engineering support during system integration, testing, deployment, and sustainment activities.
- Analyze security logs and system data to identify anomalous activity, potential vulnerabilities, and indicators of compromise.
- Provide technical support during cybersecurity incidents, investigations, and forensic activities as required.
- Assist with security-related troubleshooting and root-cause analysis of system and network issues.
- Coordinate with system administrators, network engineers, software developers, and other technical personnel to implement and verify security requirements.
- Maintain technical documentation related to system security configurations, vulnerabilities, assessments, remediation activities, and security controls.
- Monitor changes to applicable DoD cybersecurity policies, standards, and technical guidance and assist in incorporating new requirements into supported systems.
- Provide technical recommendations to engineering and cybersecurity leadership regarding system security risks, vulnerabilities, and remediation strategies.
- Support audits, inspections, assessments, and other cybersecurity compliance activities as required.
- Perform other cybersecurity engineering and systems security support duties as assigned.
Requirements
- 5–9 years of professional experience in cybersecurity engineering, systems engineering, network administration, information assurance, or a related technical discipline.
- Experience supporting DoD Risk Management Framework (RMF) activities and security authorization processes.
- Experience developing or maintaining RMF documentation and artifacts within eMASS or comparable government cybersecurity repositories.
- Experience performing vulnerability assessments using ACAS/Nessus, SCAP, or similar cybersecurity assessment tools.
- Working knowledge of DISA STIGs, SRGs, security controls, vulnerability remediation, and cybersecurity compliance requirements.
- Experience with security configuration, hardening, and assessment of Windows, Linux, network, application, database, or other enterprise systems.
- Understanding of system security engineering principles, secure configurations, defense-in-depth, access control, and network boundary protection.
- Ability to analyze technical security findings and develop practical remediation solutions.
- Strong written and verbal communication skills, with the ability to communicate technical cybersecurity requirements to both engineering and non-engineering personnel.
- Ability to work independently while coordinating effectively with government customers, ISSMs, system administrators, software developers, engineers, and other stakeholders.
- DoD 8570/8140 IASAE Level II or equivalent qualification.
- Experience supporting systems through the full RMF lifecycle from system development through authorization and sustainment.
- Experience with eMASS, Xacta, or other RMF/GRC platforms.
- Experience with ACAS/Nessus, SCAP Compliance Checker, HBSS/ESS, SIEM, IDS/IPS, endpoint security, and vulnerability management platforms.
- Experience applying DISA STIGs to Windows Server, RHEL/Linux, databases, applications, containers, network devices, and virtualized environments.
- Experience supporting cybersecurity incident response, security investigations, or digital forensics.
- Knowledge of DoD cybersecurity policies, including applicable DoD Instructions, DISA guidance, NIST publications, and RMF security control frameworks.
- Bachelor's degree in Computer Science, Information Assurance, Cybersecurity, Systems Engineering, Information Technology, or a related technical field. Equivalent relevant professional experience may be considered in lieu of the degree on a case-by-case basis.
- Must have or be able to obtain and present a CompTIA Security Plus certification prior to start date.
- Ability to obtain and maintain a security clearance.
- Must be a U.S. Citizen.
About TRISTAR
TRISTAR is an SBA certified Service-Disabled Veteran-Owned professional services company supporting the U.S. Department of Defense programs. Our core competencies include Electronic Warfare, Enterprise Management, Full Spectrum Cybersecurity, Information Technology, Digital Transformation, Software Engineering and Development, Maritime Modernization and Engineering, and Technical Solutions.
TRISTAR was founded in March 1995 and has built an employee-focused collaborative environment which enables our team of professionals to create and deliver customized solutions to meet our customers’ mission critical challenges. TRISTAR’s core capabilities support customers with end-to-end solutions.
For over 30 years, TRISTAR has demonstrated and perfected our ability to successfully manage any task, small or large no matter how difficult or complex.
TRISTAR is proud to serve the Department of Defense and other Federal Agencies.
TRISTAR provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.