CACI International Inc Logo

CACI International Inc

Information Systems Security Engineer

Posted 2 Days Ago
Be an Early Applicant
In-Office
Chantilly, VA
87K-182K Annually
Senior level
In-Office
Chantilly, VA
87K-182K Annually
Senior level
Leads security engineering and the full RMF and ATO lifecycle for mission-critical cloud and on-premises systems. Implements NIST controls, manages POA&Ms, vulnerability assessments, patching, continuous monitoring, contingency planning, and security inspections. Reviews technical changes, oversees AWS and Azure security, authors cybersecurity documentation, and briefs risks to stakeholders while coordinating with developers, systems engineers, SCAs, and DAOs.
The summary above was generated by AI
Job Title: Information Systems Security Engineer

Job Category: Information Technology

Time Type: Full time

Minimum Clearance Required to Start: TS/SCI with Polygraph

Employee Type: Regular

Percentage of Travel Required: None

Type of Travel: None

* * *

The Opportunity:

The Information Systems Security Engineer (ISSE) serves as the primary technical authority for the security and resilience of our mission-critical systems. This role is responsible for integrating security engineering principles into every phase of the Software Development Life Cycle to design and maintain secure architectures. You will collaborate with software developers, systems engineers, and government stakeholders to navigate the Risk Management Framework (RMF) lifecycle and maintain the Authority to Operate (ATO) for complex cloud and on-premise environments.
Responsibilities:

  • RMF & ATO Management: Lead the end-to-end Risk Management Framework (RMF) process, managing NIST 800-53/171 control sets and coordinating with cybersecurity entities (SCA/DAO) to secure and maintain Authority to Operate (ATO).

  • Security Engineering & Cloud Oversight: Drive "security by design" by reviewing technical change requests, evaluating new technologies, and providing security oversight for cloud-based platforms (AWS/Azure).

  • Vulnerability & Risk Mitigation: Conduct system inspections and vulnerability assessments to manage POA&Ms, prioritize system patching, and ensure robust disaster recovery and contingency planning.

  • Technical Compliance & Monitoring: Establish continuous monitoring protocols to track security posture, enforce cybersecurity policies, and brief complex technical risks to senior stakeholders.

Qualifications:

Required: 

Education and Experience:

  • Bachelor’s Degree in Computer Science, Information Technology, Cybersecurity, Engineering, or related degree.

  • Minimum of 5 years of progressive experience in Cybersecurity, Information Assurance, or related background.

Clearance & Certifications:

  • Active TS/SCI.

  • DoD 8570 IAT Level II Compliance (e.g., Security+, CCNA Security, or CySA+).

Risk Management & Compliance

  • Full RMF Lifecycle Mastery: Deep experience navigating the Risk Management Framework (NIST 800-37) to secure and maintain Authority to Operate (ATO).

  • Control Implementation: Expert knowledge of NIST 800-53 and 800-171 control sets, including managing control inheritance and applying overlays.

  • Governance & Documentation: Ability to author cybersecurity policies, manage POA&Ms, and develop Contingency/Disaster Recovery plans.

Engineering & Operations

  • Technical Oversight: Experience reviewing system changes for security impact and collaborating with dev teams to integrate new technologies securely.

  • Continuous Monitoring: Proficiency in conducting security inspections, audits, and vulnerability analysis to track patch effectiveness and system health.

  • Cloud Security: Functional understanding of security operations within AWS or Azure environments.

Communication & Professionalism

  • Stakeholder Engagement: Proven ability to brief complex technical risks to large groups and coordinate directly with SCAs and DAOs.

  • Resilience: Ability to manage high-pressure tasks and mission-critical deadlines both independently and in team settings.

Desired:

  • Basic understanding of the software development lifecycle (SDLC).

  • Experience working with governance risk and compliance tools (i.e. Xacta, SNOW, etc.).

  • Experience utilizing common industry tools (i.e. Nessus, Splunk, Anchore, etc.).

-

What You Can Expect:

 A culture of integrity.

At CACI, we place character and innovation at the center of everything we do. As a valued team member, you’ll be part of a high-performing group dedicated to our customer’s missions and driven by a higher purpose – to ensure the safety of our nation.

An environment of trust.

CACI values the unique contributions that every employee brings to our company and our customers - every day. You’ll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality.

A focus on continuous growth.

Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground — in your career and in our legacy.

Pay Range:

There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives. We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.

The proposed salary range for this position is:

$86,600 - $181,800

CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.

Similar Jobs

9 Days Ago
Hybrid
130K-222K Annually
Senior level
130K-222K Annually
Senior level
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Leads Authority to Operate activities and maintains information system security posture under RMF and ICD 503. Performs continuous monitoring, vulnerability and compliance auditing, security control validation, POA&M management, and security documentation. Coordinates remediation with technical teams, supports accreditation packages, analyzes logs and scan results, and provides security design guidance. The role also manages privileged-user nominations and serves as the primary contact for accreditation and continuous monitoring activities.
Top Skills: Access ControlAuthenticationAuthorizationAWSAws Cloud SecurityIcd 503Identity ManagementLinuxNessusNist 800-171 Risk Management FrameworkSecurity ControlsServicenowSIEMSplunkStigVulnerability ManagementWindows
5 Hours Ago
In-Office
Colorado Springs, CO, USA
82K-172K Annually
Senior level
82K-172K Annually
Senior level
Information Technology • Consulting • Defense
Designs and maintains secure IT services for a Defense Intelligence Agency customer. Responsibilities include implementing Zero Trust and ICAM capabilities, applying RMF security controls, developing cybersecurity test cases, preparing Assessment and Authorization documentation, overseeing security testing and evidence collection, supporting vulnerability remediation, and advising on information assurance, physical security, and special-program controls.
Top Skills: Cnssi 1253DcidsDod 8140Dod Directive 8570.01-MDod Instruction 8510.01Icd 503Identity Credential And Access ManagementItil 4Nist Sp 800-30Nist Sp 800-37Nist Sp 800-39Nist Sp 800-53Risk Management FrameworkSecurity+Zero Trust Architecture
2 Days Ago
In-Office
Expert/Leader
Expert/Leader
Computer Vision • Cybersecurity
Provide onsite information systems security engineering support at Fort Belvoir. Manage eMASS authorization packages, ATO documentation, POA&Ms, audit readiness, and DoD RMF compliance. Implement STIGs and security controls, perform system hardening, patching, and vulnerability remediation across Windows and Linux environments, and brief government and program stakeholders. Administer and secure systems using ACAS, ESS/HBSS, SCAP, virtualization platforms, and networking technologies.
Top Skills: AcasDisa StigsDnsEmassEssFirewallsHbssHyper-VLinuxNutanixRhelScapVMwareWindows Server

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account