Cybersecurity Engineer II
Information Systems Solutions, Inc. · Charleston, SC · 1 mo ago
On-siteInformation TechnologyFull-time
About the role
Cybersecurity Engineer II position supporting ATC Division Programs (NPP). Occasional travel to onsite locations in Antarctica may be required.
Responsibilities
- Support the Risk Management Framework process across the system lifecycle.
- Prepare, update, and maintain authorization documentation, including System Security Plans, Standard Operating Procedures, Policies, and Plans of Action and Milestones.
- Conduct Security Impact Analysis by identifying control gaps, security risks, and compliance issues, then recommend remediation actions.
- Coordinate with system owners, engineers, ISSOs, assessors, and leadership to collect evidence and resolve findings.
- Track remediation activities and validate closure of security weaknesses.
- Support continuous monitoring activities, including control reviews, status reporting, and periodic updates.
- Review vulnerability scan results and help align remediation efforts with compliance requirements.
- Ensure systems meet applicable regulatory, contractual, and organizational security standards.
- Assist with audit preparation, responses to assessors, and recurring compliance reviews.
- Communicate risk posture, assessment results, and recommendations to stakeholders in clear business and technical terms.
Requirements
- Active Secret clearance.
- One of the following certifications (IAT Level II):
- Security+ CE
- GIAC Security Essentials Certification (GSEC)
- Security Certified Network Professional (SCNP)
- System Security Certified Practitioner (SSCP)
- SecurityX or CISSP (highly preferred)
- Bachelor’s degree in Cybersecurity, Computer Science, Electrical or Electronics Engineering.
Skills
- Five (5) years or more of experience, including:
- A strong working knowledge of the Risk Management Framework (RMF) and relevant NIST requirements.
- Demonstrated experience developing and maintaining Assessment and Authorization (A&A) documentation, such as System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), Security Impact Analyses, and control traceability artifacts.
- Familiarity with continuous monitoring, security assessment processes, authorization lifecycle activities, Governance Risk and Compliance (GRC) platforms, vulnerability management, and security scanning tools (such as ACAS).
- Knowledge of regulatory requirements, secure configuration baselines, Security Technical Implementation Guides (STIGs), and remediation tracking.
- Ability to evaluate technical implementations and align security controls with operational, technical, and management requirements.
- Desired skills: ACAS, eMASS, or equivalent certification.
Benefits
- Fully vested 401(k) matching program.
- Coverage of family medical deductibles.
- Spot bonuses.
- Educational assistance to further your career.
- Employee-focused and family-first environment.
- Regular social gatherings to foster camaraderie.