Cybersecurity Engineer (ISSE)-EN
CAE’s Defense and Security business unit focuses on helping prepare military customers to develop and maintain the highest levels of mission readiness. We empower employees through innovation, excellence, integrity, and collaboration, striving to make a difference in the world while helping each other succeed.
We offer a comprehensive and competitive benefits package, a work environment that values respect and safety, and opportunities for professional development, advancement, and recognition.
This position is contingent on Contract Award.
About the role
The Information Systems Security Engineer (ISSE) will provide ISSE/DevSecOps support to the C-17 program, ensuring traceability of security controls to system security requirements, supporting the acquisition process, and integrating cybersecurity requirements into the full ATS architecture through disciplined security engineering practices. This role requires expert knowledge of DoD cybersecurity systems engineering guidance, RMF processes, acquisition security requirements, and integration activities across multiple enclaves and system architectures.
Responsibilities
- Provide ISSE support in accordance with contract requirements, ensuring cybersecurity principles and controls are integrated into architecture, development, configuration, and operational processes.
- Trace cybersecurity controls to system security requirements documented in the acquisition process, ensuring proper alignment and verification.
- Capture, refine, and document information security requirements and integrate those requirements across the entire ATS through secure architecture, development, and configuration.
- Apply systems engineering processes and cybersecurity design principles referencing RMF, DoDI 5000.02, DoDI 5000.83, DoD TPP Guidebook, and NIST SP 800-160.
C-17 Program Cybersecurity Support
- Support the C-17 Lead ISSO and C-17 TS Cybersecurity Program by planning, documenting, and implementing required cybersecurity controls and security engineering activities.
- Collaborate with ISSOs to perform vulnerability analyses, update and maintain RMF artifacts, and support ongoing compliance activities across C-17 systems.
- Assist in audit log reviews, ACAS scans, STIG assessments, and implementation of endpoint protection, host-based security, and data-loss prevention measures.
- Collaborate with network administrators to create and maintain PPSM entries for assigned systems in accordance with DISA requirements.
- Maintain authorized hardware and software baselines, working closely with configuration management teams across multiple enclaves.
- Assist with vulnerability scanning utilizing DoD-approved tools such as Nessus Security Center and take part in supply-chain evaluations of products and services integrated into the operational environment.
Requirements
- Education: AAS, BA, or BS in Engineering, Computer Science, Information Systems, or a related technical discipline.
- Certifications: Completion and maintenance of certifications and training in accordance with AFI 17-303 and DAFMAN 17-1305. Qualification per DoDD 8140.01, DoDD 8140.02, and DoD 8140.03 required. Acceptable baseline certifications: CISSP, CISM, CASP, CEH, CHFI, or DoD IAM-II/III equivalents.
- Clearance: Active Secret Clearance is required.
- Experience: 2 to 7 years performing ISSE duties within DoD or equivalent regulated environments.
- Training: DISA ESS Administrator 201/301 and ePO 5.10 are preferred.
Preferred Qualifications
- Experience with eMASS, Trellix ePO, ACAS, SCAP/STIG tools, Evaluate-STIG or similar tools.
Security Responsibilities
- Must comply with all company security and data protection/usage policies and procedures.
- Personally responsible for proper marking and handling of all information and materials, in any form.
- Shall not divulge any information, or afford access, to other employees not having a need-to-know.
- Shall not divulge information outside company without management approval.
- All government and proprietary information will be accessed and stored electronically on company-provided resources.
- Incumbent must be eligible for DoD Personal Security Clearance.
Due to U.S. Government contract requirements, only U.S. citizens are eligible for this role.
Work Environment
This job operates in a professional office environment. This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets, and fax machines. Travel is occasional (1-2 times per year).
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for their job. Duties, responsibilities, and activities may change at any time with or without notice.