Jobs · Information Technology · Virginia

Information Systems Security Engineer (ISSE) Edge

SAIC · Springfield, VA · Yesterday
Information Technology$120k–$160k/yrFull-time

About the role

SAIC is seeking two experienced Information Systems Security Engineers (ISSEs) to support the MAJESTIC Joint Program Office (JPO)—one serving as a traditional enterprise ISSE and one serving as a specialized Edge ISSE focused on tactical‑edge environments. Together, these engineers will lead advanced security engineering and architecture efforts for MAJESTIC’s mission‑critical systems, including those operating in distributed, low‑bandwidth, intermittently connected, and operationally constrained mission scenarios.

The Enterprise ISSE will design, develop, implement, and validate security architectures for MAJESTIC’s core systems and enterprise environments, ensuring security controls are integrated throughout the full engineering lifecycle—from requirements and high‑level architecture through deployment, sustainment, modernization, and ATO maintenance.

The Edge ISSE will engineer cybersecurity solutions tailored for MAJESTIC’s forward‑deployed systems, remote nodes, and tactical‑edge deployments. This includes designing architectures resilient to degraded communications, intermittent connectivity, and operational constraints while ensuring protection, monitoring, and defensive behaviors function reliably at the edge.

Both ISSEs will evaluate how mission and environmental conditions influence risk, threat exposure, data assurance, and defensive design to ensure resilient cybersecurity performance across MAJESTIC’s distributed system footprint—even in degraded or disconnected conditions. Working closely with program leadership, system owners, developers, ISSMs/ISSOs, enterprise architects, and cybersecurity operations teams, the ISSEs will align enterprise and edge architectures with federal security requirements—including NIST 800‑53, RMF, ICD 503, and DAAPM—and ensure secure, real‑time system operation throughout MAJESTIC’s mission landscape.

Responsibilities

  • Design and engineer secure edge system architectures optimized for distributed, low‑bandwidth, and intermittently connected environments.
  • Translate mission‑specific security requirements into edge‑focused technical specifications, models, and design artifacts.
  • Select, implement, and validate security controls and mitigations tailored to tactical edge systems, remote nodes, and constrained operating conditions.
  • Integrate security into edge data flows, system diagrams, and high‑/low‑level designs, ensuring resilience under degraded or disconnected scenarios.
  • Engineer core security capabilities—including boundary protections, encryption, IAM, auditing, and secure configurations—adapted for edge deployments.
  • Embed security across the entire edge system lifecycle, from requirements through field deployment, sustainment, and modernization.
  • Develop and maintain A&A engineering documentation, supporting ATO evidence for edge systems governed by RMF, ICD 503, and DAAPM.
  • Test and validate security control effectiveness across edge applications, platforms, networks, sensors, and compute nodes.
  • Perform edge‑specific risk assessments, threat modeling, and vulnerability analysis; recommend mitigations suitable for forward‑operating environments.
  • Evaluate the security implications of system changes, upgrades, integrations, and technology refreshes affecting edge nodes and data paths.
  • Apply DISA STIGs, CIS Benchmarks, and maintain hardened configuration baselines designed for edge hardware and software.
  • Design monitoring architectures enabling SIEM connectivity, detection rules, audit/log collection, and event correlation—even across intermittent or delayed data links.
  • Support incident response by providing edge‑architecture forensics, impact assessments, and mission‑sustaining remediation guidance.
  • Collaborate with developers, integrators, system administrators, and cyber teams to ensure secure deployment and integration of edge systems across MAJESTIC.
  • Present findings and recommendations on edge security engineering risks, architectures, and resilience strategies to senior leadership.
  • Produce edge‑focused technical documentation, diagrams, reports, SOPs, and design artifacts that support mission operations and accreditation.

Qualifications

  • Education
    • Bachelor’s degree in related field and 2–9+ years of experience; or
    • Master’s degree in related field and 0–7+ years of experience; or
    • High School diploma or equivalent and 6–13+ years of experience.
  • Certifications (CWF Requirements)

    Candidates must satisfy Cybersecurity Workforce Framework (CWF) ID 652 (Security Architect, Intermediate Level) or 633 (System Security Engineer, Intermediate Level) requirements, as outlined by Navy COOL. This requirement can be met by possessing one or more of the following qualifying certifications:

    • Certified Cloud Security Professional (CCSP)
    • Certified Information Systems Security Officer (C)ISSO-A)
    • Certified Secure Software Lifecycle Professional (CSSLP)
    • CompTIA Cloud+
    • CompTIA Security+ (formerly CASP+)
    • Federal IT Security Professional-Designer-NG (FITSP-D)
    • GIAC Cloud Security Automation (GCSA)
    • GIAC Continuous Monitoring Certification (GMON)
    • GIAC Security Essentials Certification (GSEC)

    OR

    A Bachelor’s Degree in Cybersecurity, Computer Science, IT, or a related field.

  • Experience
    • 2–5 years of professional experience managing and supporting enterprise‑level IT environments.
  • Technical Skills
    • Strong understanding of edge security architecture, secure system design, and engineering principles for distributed and intermittently connected environments.
    • Experience developing SSPs, security diagrams, interface documentation, and control implementation descriptions for edge‑deployed systems.
    • Proficiency with vulnerability scanning tools (Nessus, ACAS, Qualys) and analysis platforms, including assessment of remote nodes and field‑deployed assets.
    • Knowledge of DISA STIGs, CIS Benchmarks, and secure configuration/hardening standards, applied to resource‑constrained edge hardware and software.
    • Familiarity with SIEM platforms (Splunk, SolarWinds) and mission‑edge monitoring architectures, including delayed, disconnected, or low‑bandwidth event collection.
    • Understanding of Windows Server, Active Directory security, RHEL, and core network security concepts (TCP/IP, VLANs, IPsec, firewalls), including their application in distributed, tactical networks.
    • Experience conducting edge‑focused risk assessments, threat modeling, and architecture‑level recommendations that account for operational constraints and mission scenarios.
    • High‑quality technical writing and documentation skills for engineering artifacts, audit evidence, and mission‑specific edge system documentation.
  • Clearance Requirement

    Active TS/SCI clearance with the ability to obtain and maintain a TS/SCI with CI Poly.

Work Environment

All work must be conducted on-site in Springfield, VA. Supports on-premises enterprise IT environments, including virtualized Windows servers, MS SQL Server databases, and networking layers.

Similar jobs