Cybersecurity Engineer II with Security Clearance
Indexed description
- Support the Risk Management Framework process across the system lifecycle.
- Prepare, update, and maintain authorization documentation, including System Security Plans, Standard Operating Procedures, Policies, and Plans of Action and Milestones.
- Conduct Security Impact Analysis by identifying control gaps, security risks, and compliance issues, then recommend remediation actions.
- Coordinate with system owners, engineers, ISSOs, assessors, and leadership to collect evidence and resolve findings.
- Track remediation activities and validate closure of security weaknesses.
- Support continuous monitoring activities, including control reviews, status reporting, and periodic updates.
- Review vulnerability scan results and help align remediation efforts with compliance requirements.
- Ensure systems meet applicable regulatory, contractual, and organizational security standards.
- Assist with audit preparation, responses to assessors, and recurring compliance reviews.
- Communicate risk posture, assessment results, and recommendations to stakeholders in clear business and technical terms. Why Work For ISS?
Secret Certifications (IAT Level II)
One of the following:
- Security+ CE
- GIAC Security Essentials Certification (GSEC)
- Security Certified Network Professional (SCNP)
- System Security Certified Practitioner (SSCP)
- SecurityX or CISSP (highly preferred) Education:
- Bachelor’s degree in Cybersecurity, Computer Science, Electrical or Electronics Engineering Required Skills:
- Three (3) years or more of experience, to include: A strong working knowledge of the Risk Management Framework (RMF), including relevant NIST requirements, and demonstrated experience developing and maintaining Assessment and Authorization (A&A) documentation. This includes System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Impact Analyses, and control traceability artifacts. The role requires solid familiarity with continuous monitoring, security assessment processes, authorization lifecycle activities, Governance Risk and Compliance (GRC) platforms, vulnerability management, security scanning tools (such as ACAS), regulatory requirements, secure configuration baselines, Security Technical Implementation Guides (STIGs), and remediation tracking. Candidates must also be able to evaluate technical implementations and effectively align security controls with operational, technical, and management requirements. Desired Skills:
- ACAS, eMASS or equivalent certification
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search