Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
C
CACI
Information Systems Security Engineer (ISSE)
Career Insights for Cyber Security Engineer
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Virginia data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Cyber Security Engineer designs systems that protect the security of large databases, including databases with customer information and patient files. Examines client computer systems, identifies weak points in security, develops and implements new systems, monitors and responds to security issues.
$113,393 / year median in Virginia
-3% projected decline
Job Description
Job Title:
Information Systems Security Engineer (ISSE)Job Category:
Security Time Type:
Full time Minimum Clearance Required toStart:
TS/SCI Employee Type:
Regular Percentage of Travel Required:
Up to 25%Type of Travel:
Continental US •The Opportunity:
We are seeking a highly motivated Information Systems Security Engineer (ISSE) to support the security, accreditation, and continuous monitoring of advanced mission-critical collection systems operating within complex classified environments. This role offers the opportunity to influence both current and next-generation system architectures by integrating security throughout the system development lifecycle and ensuring compliance with evolving cybersecurity requirements. As part of a collaborative team of engineers, cybersecurity professionals, and software developers, you will play a critical role in designing, implementing, assessing, and maintaining secure solutions that support our customer's mission. We are looking for an individual who embraces continuous learning, process improvement, and innovation while helping shape the future security posture of our systems. This position provides opportunities to work with cutting-edge technologies, engage directly with customer security stakeholders, and contribute to high-impact national security programs. This position requires onsite support 100% of the time in Sterling, VA. Domestic and international travel opportunities may be available.Responsibilities:
- Collaborate with software, systems, network, and DevOps engineers to integrate cybersecurity requirements throughout the System Development Life Cycle (SDLC).
- Lead and support Assessment and Authorization (A&A) activities to achieve and maintain Authorization to Operate (ATO) under the Risk Management Framework (RMF).
- Partner directly with customer Information System Security Officers (ISSOs), Information System Security Managers (ISSMs), and Authorizing Officials (AOs) to navigate accreditation efforts and resolve compliance-related findings.
- Develop, maintain, and update RMF security documentation, including:
- System Security Plans (SSPs)
- Security Assessment Reports (SARs)
- Security Control Traceability Matrices (SCTMs)
- Plan of Action and Milestones (POA&Ms)
- Security Test Plans and Procedures
- Conduct security control assessments and validation activities aligned with
ICD 503, NIST
800-53, CNSSI, and DoD cybersecurity requirements.- Perform system hardening and security baseline implementation using DISA STIGs, Security Technical Implementation Guides, and industry best practices.
- Execute and analyze
DISA SCAP
scans, vulnerability assessments, and compliance audits to identify security gaps and remediation requirements.- Coordinate remediation efforts with development and infrastructure teams to address vulnerabilities, configuration deficiencies, and compliance findings.
- Monitor system security posture and support Continuous Monitoring (ConMon) activities, including vulnerability management, patch compliance, and security reporting.
- Evaluate system architectures, network designs, and software solutions to identify potential security risks and recommend mitigations.
- Support security incident response activities, forensic investigations, and root-cause analysis efforts when required.
- Review system changes, software releases, and infrastructure modifications for security impacts and RMF compliance.
- Assist in developing cybersecurity strategies, security engineering plans, and risk management approaches for future system capabilities.
- Automate compliance validation, system auditing, and security reporting through scripting and security tooling.
- Support secure configuration management processes and Infrastructure-as-Code (IaC) initiatives to improve consistency, repeatability, and compliance.
- Participate in Agile development ceremonies and provide cybersecurity guidance throughout sprint planning, design reviews, and release cycles.
- Stay current on emerging cybersecurity threats, DoD policies, security technologies, and industry best practices to continuously improve security posture.
Qualifications:
Required:
- 5+ years of experience as an Information Systems Security Engineer (ISSE), Information Assurance Engineer, Cybersecurity Engineer, and/or Linux Systems Administrator.
- Active Top Secret clearance with SCI eligibility.
- DoD 8570/8140 IAT Level II certification (Security+ CE, CySA+, SSCP, or higher).
- Strong understanding of Risk Management Framework (RMF), ICD 503, and
NIST 800-53
security controls.- Experience supporting systems through the ATO lifecycle, including accreditation and continuous monitoring activities.
- Hands-on experience with Linux administration and security hardening in classified or enterprise environments.
- Experience implementing and validating
DISA STIG
compliance.- Experience executing and interpreting
DISA SCAP
scans and vulnerability assessment results.- Proficiency with BASH, Python, or other scripting languages to automate security compliance and system administration tasks.
- Strong understanding of system security principles, vulnerability management, and secure system configuration.
- Excellent verbal and written communication skills with the ability to interact effectively with technical teams, management, and government stakeholders.
- Bachelor's degree in Systems Engineering, Software Engineering, Electrical Engineering, Computer Science, Cybersecurity, or a related technical discipline.
Desired:
- Experience working within Agile and DevSecOps environments.
- Knowledge of Infrastructure-as-Code (IaC) tools such as Puppet or Ansible.
- Experience supporting Cross Domain Solutions (CDS) or other highly secure mission systems.
- Familiarity with Git, GitLab, GitHub, or other version control platforms.
- Experience with automated compliance tools such as ACAS, Nessus, SCAP Compliance Checker, or HBSS/ePO.
- Understanding of cloud security principles within AWS, Azure, or hybrid environments.
- Experience developing security automation, compliance-as-code, or continuous compliance solutions.
- CISSP, CASP+, GSLC, or other advanced cybersecurity certifications preferred.