Information Security Engineer
ISF, Inc. · United States · 2 days ago
RemoteRemoteInformation TechnologyFull-time
ISF, inc is hiring a Senior Information Systems Security Engineer (Sr. ISSE) on Behalf of ARRO Systems.Company: ARRO Systems, LLCOrganization: Office of the Chief Information Security OfficerDepartment: Cybersecurity, Governance, Risk, and Compliance (C-GRC)Reports To: Director of Cybersecurity, Governance, Risk, and Compliance (C-GRC) / Chief Information Security Officer (CISO)Direct Reports: None unless subsequently assignedEmployment Classification: Full-Time, ExemptPosition Type: Individual ContributorLocation: Remote Status Position SummaryThe Senior Information Systems Security Engineer serves as ARRO Systems’ primary technical cybersecurity resource. The Sr. ISSE translates federal, Department of Defense, state, and commercial cybersecurity requirements into practical and sustainable engineering solutions.Working across software development, cloud engineering, DevSecOps, system architecture, IT operations, and GRC, the Sr. ISSE integrates security throughout the system development lifecycle and validates that documented security controls are effectively implemented, tested, and supported by objective evidence.Primary ResponsibilitiesDesign and review secure application, cloud, network, identity, and data architectures using defense-in-depth, least privilege, zero-trust, and secure-by-design principles.Translate NIST, DoD, FedRAMP, CMMC, StateRAMP/GovRAMP, and SOC 2 requirements into implementable technical specifications and security controls.Implement and validate security controls, configuration baselines, hardening requirements, system diagrams, technical procedures, and assessment evidence.Integrate application security testing and control validation into DevSecOps and CI/CD processes, including code analysis, dependency scanning, secret detection, and software composition analysis.Analyze vulnerability scans, penetration tests, configuration assessments, and code-review findings; recommend and validate corrective actions.Support DoD RMF, ATO, FedRAMP, CMMC, SOC 2, independent assessments, and continuous-monitoring activities.Evaluate system and software changes for security, compliance, and authorization impact before implementation.Communicate technical deficiencies and residual risks to engineering teams, the ISSO, GRC leadership, assessors, and other stakeholders Qualifications / CertificationsRequired QualificationsBachelor’s degree in cybersecurity, computer science, information systems, engineering, or a related discipline; equivalent relevant experience may be considered.Five or more years of experience in cybersecurity engineering, cloud security, systems engineering, application security, or a related technical role.Experience implementing or assessing NIST SP 800-53 controls and applying the NIST Risk Management Framework.Experience securing cloud-hosted systems, analyzing technical vulnerabilities, producing assessment-ready evidence, and communicating technical risk.Preferred QualificationsExperience with Azure Government, GCC High, Microsoft Entra ID, Microsoft Defender, Microsoft Sentinel, or comparable cloud-security technologies.Experience supporting DoD RMF, eMASS, DISA authorization, FedRAMP, CMMC, StateRAMP/GovRAMP, or SOC 2.Experience with DevSecOps, CI/CD pipelines, infrastructure as code, container security, and secure code-review tools such as Snyk, SonarQube, GitHub Advanced Security, Checkmarx, Veracode, or Fortify.Experience protecting CUI or other regulated and mission-sensitive information.Preferred CertificationsRelevant certifications may include CISSP, CCSP, Security+, CySA+, SecurityX, CISA, CISM, Microsoft Azure Security Engineer Associate, GIAC certifications, or a DoD 8140-aligned certification.