Information Systems Security Engineer (ISSE)

Columbia, MD$114k–$171kPosted Aug 7, 2026

Overview

Information Systems Security Engineer (ISSE)

LOCATION: Columbia, MD

JOB STATUS: Full-time

CLEARANCE: Ability to obtain TS/SCI

CERTIFICATION: CAP, CISSM, or CISSP

TRAVEL: Less than 5%

SALARY RANGE: $114K - $171K

 

Astrion has an exciting opportunity for an experienced Information Systems Security Engineer (ISSE) to securely engineer classified information systems throughout their lifecycle. The ISSE serves as the primary architect for the technical design, integration, and implementation of security controls in support of classified information management systems under 32 CFR Part 117 (NISPOM Rule). Further, the ISSE will design the secure networks based on instructions, manuals and policies as outlined in guidance from the DoW, Navy, and MDA; this position is located in Columbia Maryland.

 

REQUIRED QUALIFICATIONS / SKILLS

  • Bachelor’s degree with 8-10 years of experience.
  • Minimum of 5 years of experience in Linux and Windows administration.
  • Experience in supporting U.S. Government clients.
  • Be able to apply systems engineering knowledge to develop, implement and maintain a secure network environment.
  • A CAP, CISM, or CISSP certification is required.
  • U.S. citizenship with active TS/SCI eligibility and the ability to maintain such eligibility.

PREFERRED QUALIFICATIONS / SKILLS 

  • Proficiency with Secure Internet Protocol Network establishment and maintenance.
  • Configuration management.
  • Vulnerability assessment and remediation.
  • Secure software development principles.
  • Risk analysis and technical writing.
  • Proficiency with various compute applications and testing tools (Word, Excel, PowerPoint, WASSP, MBSA).
  • Strong understanding of DCSA eMASS and DAAG processes.

RESPONSIBILITES:

  • Security Architecture and System Design – Integrate security requirements into system architecture during the planning and design phases.
  • Ensure system designs meet 32 CFR Part 117 (NISPOM Rule); and guidance as outlined in the DCSA Assessment and Authorization Guide (DAAG).
  • Research and recommend secure technologies and architectures to reduce risk.
  • Incorporate security engineering principles throughout the system development life cycle (SDLC).
  • Develop engineering artifacts required for Assessment & Authorization (A&A).
  • Assist with security control inheritance and control tailoring.
  • Support the development of Plans of Action and Milestones (POA&Ms).
  • Security Control Implementation - Design and implement technical security controls; ensure controls are implemented correctly and function as intended; validate implemented controls; work closely with system administrators to configure systems securely.
  • Vulnerability Management – Analyze vulnerabilities identified through tools such as; ACAS, SCAP, STIG Viewer Nessus, Security Assessments.
  • Recommend engineering solutions to mitigate identified risks.
  • Evaluate security impacts of hardware, software, and configuration changes.
  • Continuous Monitoring (ConMon) – Review security posture and system health.
  • Authorization Support – Develop technical documentation supporting system authorization.
  • Provide Engineering input for Security Plans, POA&Ms, and Configuration Management Plans.
  • Configuration and Change Management - Evaluate proposed system changes for security impact; Participate in Configuration Control Boards (CCBs).
  • Technical Advising - Advise program managers, system owners, and administrators on security implications of design decisions.
  • Collaboration – Work closely with ISSM, ISSO, Systems Administrators, DCSA Information System Security Professional (ISSP)

Want jobs like this matched to you?

SimpleCareer scores fresh postings against your résumé so you only see the matches that matter.

Get started free