Information System Security Engineer (ISSE)
About this role
Company Description
Founded in 1989 and headquartered in Reston, Virginia, SOSi is a private defense and government solutions business specializing in advanced technology systems and mission support. Its capabilities include data science, software development, network engineering, intelligence, surveillance, and reconnaissance (ISR), and logistics.
Job Description
Defend the systems that power the Pacific mission 🌴
SOSi is seeking a talented Information System Security Engineer (ISSE) to lead cybersecurity engineering efforts supporting critical operations at Joint Base Pearl Harbor-Hickam. In this high-impact role, you'll drive RMF compliance, architect secure solutions, and help safeguard mission systems across a dynamic and evolving threat landscape. Join a collaborative cyber team where your expertise directly contributes to national security and operational readiness throughout the Indo-Pacific region.
Essential Job Duties:
- Design, review, and implement cybersecurity architecture and engineering solutions supporting enterprise and mission systems.
- Integrate security requirements into system design, development, testing, implementation, and sustainment activities.
- Support and lead RMF activities throughout the authorization lifecycle, including categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
- Develop, review, and maintain RMF documentation including System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), Security Assessment Reports (SARs), and Plans of Action & Milestones (POA&Ms).
- Evaluate system changes, upgrades, and new capabilities to determine cybersecurity impacts and authorization requirements.
- Validate implementation of NIST SP 800-53 security controls and DISA Security Technical Implementation Guides (STIGs).
- Conduct cybersecurity architecture reviews, security engineering analyses, and technical risk assessments.
- Analyze ACAS, Tenable, Nessus, and SCAP assessment results and coordinate remediation efforts with system administrators and engineering teams.
- Develop and implement continuous monitoring strategies to maintain cybersecurity compliance and authorization status.
- Participate in Configuration Control Boards (CCBs), Technical Review Boards (TRBs), and engineering working groups.
- Provide technical guidance and cybersecurity recommendations to system owners, ISSOs, ISSMs, and senior leadership.
- Support cybersecurity inspections, Security Control Assessor (SCA) assessments, and Command Cyber Readiness Inspections.
- Evaluate interconnections, data flows, and system architectures to identify security risks and recommend mitigations.
- Track vulnerability remediation efforts and maintain POA&M activities to meet organizational and regulatory requirements.
- Support implementation and adoption of Zero Trust principles and cybersecurity modernization initiatives.
- Prepare technical reports, executive summaries, and briefing materials for leadership decision-making.
Qualifications
Minimum Requirements:
- Active Secret clearance with the ability to obtain and maintain a Top-Secret clearance.
- Must meet DoD 8140 qualification requirements for DCWF 652 Security Architect Intermediate (Primary)
- Bachelors Degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering // OR // GMON, SecurityX, CCSP, CISSO, Cloud+, CSSLP, FITSP-D, GCSA, or GSEC.
- DCWF 461 Systems Security Analyst Intermediate (Secondary)
- Bachelors Degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering // OR // CCSP, Cloud+, GICSP, GISF, GSEC, or Security+.
- Six (6) years of experience supporting cybersecurity, information assurance, systems engineering, or RMF-related activities.
- Experience supporting DoD Assessment and Authorization (A&A) or RMF processes.
- Experience with eMASS and maintenance of RMF authorization packages.
- Experience implementing and assessing NIST SP 800-53 security controls.
- Experience with ACAS, Tenable Security Center, Nessus, SCAP, and vulnerability management processes.
- Working knowledge of Windows, Linux, networking, virtualization, and enterprise information systems.
- Strong communication skills with the ability to engage both technical and non-technical stakeholders.
Preferred Qualifications:
- Active Top Secret clearance with SCI eligibility.
- CISSP certification.
- CISSP-ISSEP, CCSP, CGRC, SecurityX (formerly CASP+), or CSSLP certification.
- Experience supporting Combatant Command, Navy, or Joint operational environments.
- Experience with Zero Trust Architecture implementation.
- Knowledge of Cross Domain Solutions (CDS) and Commercial Solutions for Classified (CSfC).
- Experience with cloud security technologies and hybrid cloud environments.
- Experience conducting cybersecurity architecture reviews and secure design assessments.
- Experience using JIRA, Confluence, ServiceNow, or similar collaboration and workflow platforms.
- Experience supporting Security Control Assessor reviews and ATO renewals.
Additional Information
Work Environment:
- Working conditions are normal for an office environment.
- Fast paced, deadline-oriented environment.
- May require periods of non-traditional working hours including consecutive nights or weekends.
Working at SOSi:
All interested individuals will receive consideration and will not be discriminated against for any reason.
Company at a glance
Founded in 1989 and headquartered in Reston, Virginia, SOSi is a private, founder-led defense and government solutions firm specializing in advanced technology systems and mission support. Our capabilities span data science, software development, network engineering, intelligence, surveillance and reconnaissance (ISR), language services, and logistics—delivered across 16+ countries to the customers who need them most.
We lead with technology. From the DoW's largest data-centric, Zero Trust mission partner network to AI-powered intelligence platforms and cloud-native solutions, SOSi engineers the systems that enable U.S. and allied forces to operate, decide, and win. More than 25% of our workforce are veterans—because this mission is personal.
Where others see the size of the challenge, we say #ChallengeAccepted
--
Fraud Alert
Recruitment fraud is a growing trend where fraudsters impersonate SOSi and its employees to deceive job seekers with fake employment opportunities. These scams typically involve fake job postings, unauthorized email accounts, or forged documents claiming to be from SOSi. The intent is to gain access to your personal information, including banking details, credit card numbers, or social security numbers.
Please be aware that all legitimate SOSi communications come from official @sosi.com or @sosi.us email addresses, and we never request personal information during initial contact. Our official careers site can be found at sosi.com/careers and our corporate site at sosi.com.
If you receive a suspicious job offer claiming to be from SOSi, contact us directly at [email protected] to verify its legitimacy.
Tired of cold applications?
Sign up with Clera and we'll reach out the moment a role actually fits you — no more spraying applications into the void.
Know someone who'd be great for this?