Information System Security Engineer (ISSE) III
Required: Active, final Secret clearance with immediate eligibility for a favorable T5 investigation; 4-year STEM degree; Active IAT III or IAM III certification; ability to work onsite at NSWC-PD.
About the role
Constellation West is seeking an Information System Security Engineer (ISSE) III to support IT Operations at NSWC-PD. This role involves capturing and refining information security operational and security requirements, ensuring they are addressed through architecting, design, development, and configuration, as well as implementing security controls, configuration changes, software/hardware updates, vulnerability scanning, and securing configurations.
Responsibilities
- Develop, maintain, and track Risk Management Framework (RMF) system security plans, including System Categorization Forms, Platform Information Technology (PIT) Determination Checklists, Assess Only (AO) Determination Checklists, Implementation Plans, System Level Continuous Monitoring (SLCM) Strategies, System Level Policies, Hardware Lists, Software Lists, System Diagrams, Privacy Impact Assessments (PIA), and Plans of Action and Milestones (POA&M).
- Execute the RMF process to obtain and maintain Interim Authority to Test (IATT), AO approval, Authorization to Operate (ATO), and Denial of Authorization to Operate (DATO).
- Identify and tailor IT and cybersecurity (CS) security control baselines based on RMF guidelines and categorization of the RMF boundary.
- Perform Ports, Protocols, and Services Management (PPSM).
- Conduct IT and CS vulnerability-level risk assessments.
- Execute security control testing as required by risk assessments or annual security reviews (ASR).
- Mitigate and remediate IT and CS system-level vulnerabilities for all assets within the boundary per STIG requirements.
- Develop and maintain Plans of Actions and Milestones (POA&M) in Enterprise Mission Assurance Support Service (eMASS).
- Develop and maintain system-level IT and CS policies and procedures for respective RMF boundaries or as guided by command ISSMs.
- Implement and assess STIG and Security Requirements Guides (SRGs).
- Perform and develop vulnerability assessments using automated tools such as Assured Compliance Assessment Solution (ACAS), Security Content Automation Protocol (SCAP) Compliance Check (SCC), and Evaluate STIG.
- Deploy security updates to Information System components.
- Perform routine audits of IT system hardware and software components.
- Maintain inventory of Information System components.
- Participate in IT change control and configuration management processes.
- Upload vulnerability data in Vulnerability Remediation Asset Manager (VRAM).
- Image or re-image assets that are part of the assigned RMF boundary.
- Install software and troubleshoot software issues to support compliance of RMF boundaries’ assets.
- Assist with the removal of SSD, HDD, or other critical components of assets before destruction and removal from the RMF boundary.
- Provide cybersecurity patching of assets during DoD and DoN TASKORDs, FRAGORDs, or as designated by Command ISSM, ACIO, and/or Code 104 management.
- Support configuration change documentation and control processes and maintain DOD STIG compliance.
- Support cyber compliance of assets that are part of an enterprise IT network, including Windows servers and CISCO networking hardware, by assessing vulnerabilities, patching, and meeting STIG requirements.
- Report compliance issues of network hardware to management to avoid operational disruption of the network.
About Us
Constellation West is an award-winning, 29-year-old WOSB and Prime Federal Contractor delivering Information Technology (IT) engineering services and non-IT subject matter expertise worldwide. Established in 1997, we partner with key organizations such as the Department of Veteran Affairs, the Department of Defense, civilian agencies, and the national intelligence community. Many positions require security clearances. We provide fully integrated solutions covering all aspects of system and network engineering, administration, and management, and we strive to attract individuals ready to take on exciting challenges as part of a dynamic team.
Benefits
- Competitive 401(k) plan with employer matching
- Competitive health benefits with employer contributions
- 11 paid holidays per year
- 15 days starting PTO for new hires
- Tuition/Continuing Education reimbursement
- Relocation assistance
- Pre-tax commuter benefit accounts
- Short-term/Long-term disability and life insurance with buy-up options
- Veteran hiring preference
- Conversion to an Employee-owned firm (ESOP) in 2025