Principal Information System Security Engineer (ISSE)
Job description
Redhorse transforms the way government uses data and technology. To support this mission, we are seeking a Principal Information System Security Engineer (ISSE) who is a recognized authority in the field. This is a high-impact role where you will tackle unusually complex technical problems and deliver highly innovative solutions. As a recognized expert, you will not only ensure the security of our nation's most sensitive information systems but also lead efforts to capture new business opportunities through technical excellence and capability briefings. You will be instrumental in designing and researching advanced applications that shape the future of Redhorse’s digital transformation services.
- Act as a recognized authority within the company, providing technical and programmatic Information Assurance (IA) services for complex network and information security systems.
- Work on unusually complex technical problems, providing highly innovative solutions that align with mission goals.
- Lead efforts to capture new business through high-level technical work, research, and capability briefings to prospective clients.
- Design, research, and develop highly advanced applications that may result in new product or business opportunities for Redhorse.
- Determine and pursue courses of action necessary to obtain desired security and business results with minimal supervision.
- Design, develop, and implement security requirements within an organization’s business processes.
- Prepare documentation using accepted guidelines such as DITSCAP, DIACAP, NIACAP, NIST SP 800-37, and DCID 6/3 frameworks.
- Prepare and execute Security Test and Evaluation (ST&E) plans.
- Provide certification and accreditation (C&A) support and conduct complex risk and vulnerability assessments.
- Analyze policies and procedures against Federal laws and regulations, providing recommendations to close critical security gaps.
- Develop and complete system security plans, contingency plans, and risk mitigation strategies.
- Recommend and implement system enhancements to improve security deficiencies.
- Develop, test, and integrate computer and network security tools.
- Secure system configurations, install security tools, and scan systems to determine and report compliance results.
- Conduct security program audits and develop solutions to lessen identified risks.
- Develop strategies to comply with privacy, risk management, and e-authentication requirements.
- Provide IA support for the development and implementation of security architectures to meet evolving security requirements.
- Provide expert assistance in computer incident investigations and vulnerability assessments.
- Must have an active TS/SCI with FS Poly security clearance.
- Bachelor’s degree (or equivalent) with 12+ years of experience OR a Master’s degree with 10+ years of experience.
- Recognized expertise in performing a wide variety of information assurance and information systems security engineering duties.
- Extensive experience in the certification and accreditation of information systems using DIACAP, NIACAP, NIST SP 800-37, and/or DCID 6/3 frameworks.
- Proven track record of solving unusually complex technical problems with innovative solutions.
- Demonstrated ability to lead technical briefings and support business development/capture efforts.
We encourage all candidates who meet the basic requirements to apply, even if you do not have any of the following experience:
- Advanced security certifications such as CISSP-ISSEP or CISM.
- Experience with Cloud Service Provider (CSP) security architectures (AWS, Azure, or Google Cloud).
- Familiarity with DataBricks, GitLab, Spark, or Jira in a secure government environment.
- Experience with automated compliance-as-code and DevSecOps practices.
- Previous experience in a consulting or advisory role for high-level government stakeholders.