Secure Infrastructure

Information System Security Engineer (ISSE) – TS/SCI Full Scope Poly – Annapolis Junction, MD

Information System Security Engineer (ISSE) – TS/SCI Full Scope Poly

📍 Location: Annapolis Junction, MD
🏢 Work Arrangement: 100% Onsite
💼 Employment Type: Full-Time
🔒 Security Clearance Required: Active TS/SCI with Full Scope Polygraph (NSA Preferred)
🇺🇸 Citizenship: U.S. Citizen Required
🎓 Certification Required: DoD 8570/8140 IASAE Level II Compliant Certification
🚫 Visa Sponsorship: Not Available
🚚 Relocation Assistance: Available
💰 Compensation: $100,000 – $200,000 Base Salary

Overview

A leading government technology contractor is seeking Information System Security Engineers (ISSEs) to support mission-critical classified government programs.

This role focuses on integrating cybersecurity engineering principles throughout the entire system lifecycle, including system design, implementation, accreditation, continuous monitoring, and sustainment. The ISSE will play a critical role in Risk Management Framework (RMF) execution, Assessment & Authorization (A&A) activities, security control validation, and ongoing cybersecurity compliance.

The ideal candidate will possess a strong blend of cybersecurity engineering, RMF expertise, technical security assessment experience, and security architecture knowledge within highly secure classified environments.

Key Responsibilities

Risk Management Framework (RMF)

  • Support the full RMF lifecycle for classified information systems.

  • Develop and maintain RMF documentation and security artifacts.

  • Assist with Authority to Operate (ATO) activities and sustainment.

  • Support Assessment & Authorization (A&A) efforts.

  • Maintain body-of-evidence packages for accreditation activities.

Security Engineering

  • Implement and validate security controls.

  • Perform Security Control Traceability and technical validation.

  • Support system boundary definition and security architecture development.

  • Conduct technical security assessments and risk analysis.

  • Recommend security improvements and mitigation strategies.

Compliance & Continuous Monitoring

  • Participate in Continuous Monitoring (ConMon) activities.

  • Conduct compliance assessments and security reviews.

  • Analyze vulnerability scan results and remediation efforts.

  • Verify remediation effectiveness and identify false positives.

  • Ensure ongoing compliance with cybersecurity requirements.

Vulnerability Management & Hardening

  • Support vulnerability management programs.

  • Implement and validate STIG compliance.

  • Support patch validation and security compliance efforts.

  • Assist with system hardening initiatives.

  • Coordinate remediation activities with technical teams.

Stakeholder Collaboration

  • Work closely with:

    • ISSOs

    • ISSMs

    • Security Control Assessors (SCAs)

    • System Owners

    • System Administrators

  • Support accreditation, compliance, and cybersecurity engineering efforts across mission systems.

Required Qualifications

Security Requirements

✔ Active TS/SCI Clearance

✔ Active Full Scope Polygraph (NSA Preferred)

✔ U.S. Citizenship Required

Certification Requirement

✔ DoD 8570/8140 IASAE Level II Compliant Certification

Examples include:

  • CISSP

  • CASP+

  • CCSP

  • CSSLP

Cybersecurity & RMF Experience

Strong experience with:

  • Risk Management Framework (RMF)

  • Assessment & Authorization (A&A)

  • Authority to Operate (ATO)

  • Security Control Implementation

  • Security Control Validation

  • Continuous Monitoring (ConMon)

NIST Knowledge

Strong familiarity with:

  • NIST SP 800-37

  • NIST SP 800-53 Rev. 3 and/or Rev. 5

  • Security Control Frameworks

  • RMF Compliance Processes

RMF & Compliance Tools

Experience with one or more of:

  • LATTEART

  • XACTA

  • BISCOTTI

  • WATCHCAT

  • STE

Additional experience with:

  • Compliance scanning tools

  • Configuration assessment tools

  • Vulnerability management platforms

Core ISSE Skill Areas

Security Engineering

  • Security Control Implementation

  • Security Control Validation

  • Security Architecture Support

  • System Boundary Definition

Compliance & Accreditation

  • Assessment & Authorization (A&A)

  • RMF Artifact Development

  • Accreditation Package Support

  • Body of Evidence Management

Vulnerability Management

  • Vulnerability Analysis

  • Remediation Tracking

  • Patch Validation

  • STIG Compliance

  • Security Hardening

Risk Management

  • Technical Risk Analysis

  • Compliance Validation

  • Continuous Monitoring (ConMon)

  • Security Assessment Support

Preferred Qualifications

Government & Classified Environment Experience

  • Classified Government cybersecurity programs.

  • Large-scale enterprise systems.

  • Mission-critical environments.

Technical Infrastructure Exposure

Experience supporting:

  • Enterprise Linux environments

  • Network infrastructure

  • Cloud environments

Stakeholder Coordination

Experience collaborating with:

  • ISSOs

  • ISSMs

  • Security Control Assessors

  • System Owners

  • Engineering Teams

Must-Have Requirements

Clearance

✅ Active TS/SCI Clearance

✅ Active Full Scope Polygraph

Certification

✅ IASAE Level II Certification

Cybersecurity

✅ RMF Experience

✅ A&A Experience

✅ ATO Experience

✅ Security Control Validation

Compliance

✅ Continuous Monitoring

✅ Vulnerability Management

✅ STIG Implementation

Documentation

✅ RMF Artifacts

✅ Accreditation Packages

✅ Security Documentation

Screening Questions

  1. Do you currently hold an active TS/SCI clearance with a Full Scope Polygraph?

  2. Was your Full Scope Polygraph issued by NSA?

  3. When was your most recent Full Scope Polygraph completed?

  4. Which IASAE Level II certification do you currently hold (CISSP, CASP+, CCSP, CSSLP, etc.)?

  5. How many years of ISSE or cybersecurity engineering experience do you have?

  6. Have you supported the full RMF lifecycle, including A&A and ATO activities?

  7. Which RMF tools have you used (XACTA, LATTEART, BISCOTTI, WATCHCAT, STE)?

  8. Do you have experience implementing and validating security controls?

  9. Have you supported STIG implementation, vulnerability remediation, and compliance validation?

  10. Do you have experience supporting classified government systems?

Ideal Candidate Profile

The ideal candidate will:

  • Hold an active TS/SCI Full Scope Polygraph.

  • Possess an active IASAE Level II certification.

  • Have strong cybersecurity engineering experience within classified environments.

  • Be highly knowledgeable in RMF, A&A, and ATO processes.

  • Understand security architecture, control implementation, and compliance validation.

  • Have experience supporting vulnerability management and STIG compliance.

  • Demonstrate excellent analytical, troubleshooting, and documentation skills.

  • Balance mission objectives with cybersecurity requirements and risk management practices.

Candidate Snapshot

Requirement

Details

Clearance

Active TS/SCI + Full Scope Poly

Citizenship

U.S. Citizen

Experience Level

Mid-Level to Senior

Certification

IASAE Level II Required

Frameworks

RMF, NIST 800-37, NIST 800-53

Compliance

A&A, ATO, ConMon

Security

Control Implementation & Validation

Documentation

RMF Artifacts & Accreditation Packages

Tools

XACTA, LATTEART, BISCOTTI, WATCHCAT, STE

Location

Annapolis Junction, MD

Work Arrangement

100% Onsite

Travel

None

Compensation

$100K – $200K

Relocation

Available

Why This Opportunity?

Mission Impact

Support highly classified systems that directly contribute to critical national security missions.

Cybersecurity Engineering Focus

Move beyond compliance into hands-on security engineering, architecture support, security control validation, and accreditation activities.

Technical Growth

Gain exposure to advanced RMF processes, security engineering practices, vulnerability management, and enterprise cybersecurity operations.

Strong Benefits Package

  • 3 Weeks PTO

  • 11 Federal Holidays

  • Medical & Dental Coverage

  • Life Insurance

  • STD & LTD Coverage

  • 401(k) with Company Match

  • Long-Term Career Development

This opportunity is ideal for an Information System Security Engineer (ISSE), Cybersecurity Engineer, RMF Engineer, Security Compliance Engineer, Cybersecurity Architect, A&A Specialist, or Security Controls Engineer with an active TS/SCI Full Scope Polygraph and IASAE Level II certification seeking to support highly sensitive government programs.

 

DevOps Engineer – Top Secret Clearance (Onsite, Huntsville AL)

DevOps Engineer (Top Secret Required)

💰 Salary: Up to $170,000
📍 Location: Huntsville, Alabama (100% Onsite)
🏢 Work Model: Fully Onsite
💼 Employment Type: Full-Time
🔐 Clearance: Active Top Secret (CI Poly required)
🎓 Education: Bachelor’s Degree Required
🚚 Relocation Assistance: Available (up to $10,000)

About the Role

We are seeking a DevOps Engineer to join a high-performing cyber team supporting a large SOC enterprise environment. This role is hands-on and mission-critical, focused on designing, deploying, operating, and securing DevSecOps infrastructure in a classified environment.

You’ll work across infrastructure, automation, and cybersecurity tooling—supporting everything from deployment and patching to troubleshooting complex interoperability issues.

Key Responsibilities

  • Design, deploy, test, certify, and operate DevSecOps infrastructure tools

  • Own operations and maintenance for multiple platform tools

  • Deploy and configure services using Infrastructure as a Service (IaaS)

  • Configure and manage Linux-based servers supporting dynamic applications

  • Debug cluster-based computing architectures

  • Use scripting or basic programming to solve operational issues

  • Install, configure, and manage open-source monitoring tools

  • Perform patching, upgrades, and sustainment activities

  • Address system interoperability and operational stability issues

Required Qualifications

  • Active Top Secret Security Clearance with willingness to sit for CI Poly

  • Bachelor’s degree (BS or BA)

  • 5+ years of DevOps-related experience

  • Strong experience administering Linux-based environments

  • Experience testing, deploying, maintaining, and administering cybersecurity infrastructure

  • Experience developing or modifying applications or utility programs for cybersecurity use

  • Comfortable operating in secure, enterprise SOC environments

Preferred Skills & Certifications

  • Red Hat Certified Systems Administrator (RHCSA)

  • AWS Certified Cloud Practitioner

  • AWS Certified DevOps Engineer – Associate

  • Experience with:

    • Splunk

    • Oracle / SQL-based platforms

    • Python scripting

  • Experience integrating third-party components and custom capabilities

  • Proven ability to automate operations and maintenance tasks

  • Strong troubleshooting and process-improvement mindset

Ideal Candidate Profile

  • Holds an active Top Secret clearance

  • Willing to complete a CI Polygraph

  • Has hands-on DevOps experience in secure cyber environments

  • Exposure to Splunk preferred

  • Willing to relocate to Huntsville, AL

  • Self-driven, technically curious, and operationally strong

Benefits

  • 3 weeks Paid Time Off

  • 2 weeks Holiday Pay

  • Medical, Dental, and Vision Insurance

  • Short--Term & Long-Term Disability

  • Life Insurance & AD&D

  • 401(k) with up to 4% match

  • Relocation assistance available (up to $10,000)

Additional Details

  • Security Clearance Required: Yes

  • Visa Sponsorship: Not available

  • Travel: None

 

Staff Product Security Engineer | Medical Devices | Limerick, Ireland | Onsite

🔐 Staff Product Security Engineer

📍 Location: Limerick City, Munster, Ireland (Onsite – minimum 4 days per week)
🏢 Industry: Medical Devices / Healthcare Technology
🧠 Level: Mid–Senior
💼 Employment Type: Full-Time
✈️ Travel: Occasional
🛂 Visa Sponsorship: Not available
💶 Salary Range: €85,000 – €95,000
🎁 Benefits: Full benefits package

🚀 The Opportunity

An innovative global medical technology organisation is seeking a Staff Product Security Engineer to play a critical role in shaping and strengthening product security across next-generation healthcare solutions.

This is a highly visible position offering the opportunity to:

  • Influence security strategy across product portfolios

  • Embed secure-by-design principles across the full product lifecycle

  • Lead security maturity improvements

  • Work cross-functionally with R&D, Quality, Regulatory, and IT

  • Protect products in an evolving threat landscape

If you're passionate about cybersecurity, product resilience, and impact-driven work in healthcare, this role offers both purpose and technical depth.

🎯 Key Responsibilities

  • Lead and develop a high-performing Product Security function

  • Define and guide product security strategy aligned with regulatory and enterprise cybersecurity objectives

  • Embed secure-by-design practices, threat modelling, and proactive vulnerability management

  • Partner with R&D, Quality, Regulatory, and IT teams to ensure security is integrated throughout the product lifecycle

  • Conduct product security risk assessments and support remediation strategies

  • Support product security documentation, including governance and compliance artefacts

  • Review technical designs and source code; provide clear, actionable recommendations

  • Support incident response and vulnerability management efforts

  • Implement best practices for:

    • Encryption & PKI

    • Authentication & access control

    • Audit logging

    • Secure hardening

    • Patch management

    • Vulnerability monitoring

  • Track and report security posture using meaningful metrics

  • Ensure adherence to development policies and quality management systems

🧠 Required Experience & Qualifications

  • Bachelor’s degree in Computer Science, Engineering, or related field (or equivalent experience)

  • 5+ years experience in:

    • Security architecture

    • Secure software development

    • Systems and architecture design

  • Experience working in regulated environments with strong QMS adherence

  • Proven experience leading or mentoring teams

  • Strong understanding of:

    • Encryption algorithms and PKI

    • Embedded device security

    • Networking and threat models

    • Dynamic and static code analysis tools

  • Excellent written and verbal communication skills

  • Strong collaboration and stakeholder management abilities

🧩 Technical Skills Snapshot

Domain

Experience

Product Security

Secure-by-design, threat modelling, vulnerability management

Cryptography

Encryption, PKI

AppSec

Static/Dynamic analysis, secure SDLC

Embedded Security

Yes

Networking

Security controls, common threats

Documentation

SAP, SharePoint, DocuSign or similar

Regulated Environments

Medical / highly regulated industries

Tools

Microsoft Office, security tooling

🏢 Work Style & Culture

  • Strong emphasis on onsite collaboration (minimum 4 days/week in office)

  • Cross-functional, high-impact environment

  • Focus on innovation, continuous improvement, and ownership

  • Opportunity to influence product direction at a strategic level

📌 Candidate Snapshot

Attribute

Details

Role

Staff Product Security Engineer

Location

Limerick, Ireland

Experience

10–15 years ideal

Leadership

Yes (influence & team leadership expected)

Domain

Medical device security

Environment

Regulated, high-compliance

Work Model

Onsite-first

🌍 Why This Role Matters

Your work will directly contribute to:

  • Protecting patient safety

  • Strengthening cybersecurity in healthcare systems

  • Ensuring regulatory compliance

  • Driving security maturity across critical medical technologies

This is a career-defining role for someone who wants both technical depth and meaningful impact.