Back to search
HRUCKUS Linkedin · Posted 18d ago

Information System Security Engineer

Annapolis Junction

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Veteran-Owned Firm Seeking an Information Systems Security Engineer (ISSE) with TS/SCI for a role in Annapolis Junction, MD


My name is Stephen Hrutka. I lead a Veteran-Owned management consulting firm in Washington, DC. We specialize in Technical and Cleared Recruiting for the Department of Defense (DoD), the Intelligence Community (IC), and other advanced defense agencies.


At HRUCKUS, we support fellow Veteran-Owned businesses by helping them recruit for positions across organizations such as the VA, SBA, HHS, DARPA, and other leading-edge R&D-focused defense agencies.


We seek to fill an Information Systems Security Engineer (ISSE) position in Annapolis Junction, MD.


The ideal candidate is a Annapolis Junction resident with an active TS SCI clearance, DoD 8570.1-M 8140 IAT Level III certification, and a strong background in networking, cloud security, and DevSecOps.


If you’re interested, I'll gladly provide more details about the role and discuss your qualifications further.


Thanks,

Stephen M Hrutka

Principal Consultant

HRUCKUS LLC


Executive Summary: HRUCKUS is looking for an experienced Information System Security Engineer to design, develop, implement, and integrate DoD IA architectures, systems, or system components for use within computing, network, and enclave environments..


Position Description: The Information System Security Engineer will perform security engineering activities across the SDLC, maintain enterprise security architecture aligned with NIST RMF, and evaluate cybersecurity tools to improve the system security posture and threat detection capabilities.


Position Job Duties:

  • Design, implement, and maintain enterprise security architecture aligned with NIST RMF, DoD STIGs, CIS benchmarks, and organizational cybersecurity policies.
  • Perform security engineering activities across system development lifecycle (SDLC), including requirements analysis, system design reviews, security testing, and accreditation support.
  • Implement vulnerability management processes utilizing Tenable Nessus, ACAS, and Qualys to identify, assess, and remediate system vulnerabilities.
  • Integrate cybersecurity requirements into Windows and Linux server environments, cloud infrastructure, virtualization platforms, and containerized applications.
  • Support incident response and forensic investigations by analyzing security logs, SIEM alerts, network traffic, and endpoint telemetry using Splunk Enterprise.
  • Develop automation scripts using PowerShell, Bash, and Python to streamline vulnerability remediation, account auditing, compliance reporting, and security monitoring tasks.
  • Collaborate with system administrators, network engineers, ISSOs, and application teams to remediate security findings and implement secure configuration baselines.
  • Perform security impact analysis for system changes, software deployments, and infrastructure upgrades to ensure continued compliance and operational security.
  • Engineer endpoint protection and hardening solutions utilizing Trellix ePO – On-prem, host-based firewalls, and application whitelisting technologies.
  • Evaluate and implement cybersecurity tools and technologies to improve system security posture, continuous monitoring, and threat detection capabilities.
  • Produce technical security documentation, architecture diagrams, standard operating procedures (SOPs), and executive-level risk assessment reports.
  • Experience administrating, configuring, and troubleshooting core modules such as Enterprise Password Vault (EPV), Password Vault Web Access (PVWA), Central Policy Manager (CPM), and Privileged Session Manager (PSM) in CyberArk.
  • Monitors, analyzes, and detects cyber events and incidents within information systems and networks under general supervision.
  • Assists with integrated, dynamic cyber defense, coordinates and maintains security toolsets to support organizations’ continuous monitoring and ongoing authorization programs.
  • Establishes a framework by which cyber risk can be measured and quantified in the marketplace.
  • Determines security requirements by evaluating business strategies and requirements; researching information security standards; conducting system security and vulnerability analyses and risk assessments; studying architecture platform; identifying integration issues; preparing cost estimates.
  • Implements security systems by specifying intrusion detection methodologies and equipment; directing equipment and software installation and calibration; preparing preventive and reactive measures; creating, transmitting, and maintaining keys; providing technical support; completing documentation. Verifies security systems by developing and implementing test scripts.
  • Maintains security by monitoring and ensuring compliance to standards, policies, and procedures; conducting incident response analyses; developing and conducting training programs.
  • Responsible for the design, development, implementation, and integration of a DoD IA architectures, systems, or system components for use within computing, network, and enclave environments.
  • Ensures that the architecture and design of development and operational systems are functional and secure.
  • This includes designs for program of record systems and special purpose processing nodes with platform IT interconnectivity.


Position Qualifications:

  • Current/active TS/SCI level clearance is required
  • BS Degree in IT or Related Field
  • Must be DoD 8570.1-M 8140 IAT Level III certification (SecurityX (CASP), GCIH, CISA, CISSP) compliant
  • Strong background in networking (TCP IP, firewalls, VPNs), cloud security (AWS Azure), Kubernetes, and DevSecOps.
  • Deep understanding of NIST SP 800-161, NIST RMF, FedRAMP, Common Criteria, ATO package development, and cybersecurity compliance (STIGs).
  • Hands-on experience managing and deploying Tenable Nessus, CyberArk, Trellix, Splunk Enterprise, VMware vSphere, GitLab, Microsoft Windows Server, Red Hat Enterprise Linux and Ubuntu Linux
  • Experience with scripting and automation with Powershell, Python, Bash and Ansible
  • Proven experience in leading projects and mentoring junior ISSEs.
  • Present technical briefings to leadership.
  • Level 2 Requirement: BS BA Degree with 2 to 5 years experience, or MS MA MBA with 0 to 2 years experience, or 8 to 10 years experience with no degree.
  • Level 3 Requirement: BS BA Degree with 5 to 8 years experience, or MS MA with 3 to 5 years experience, or PhD with 0 to 2 years experience.


Details:

  • Job Title: Information Systems Security Engineer (ISSE)
  • Location: Annapolis Junction, MD (Primary)
  • Security Clearance Requirement: TS/SCI
  • Salary range: 116,000 - 140,000


Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search