We are seeking a dedicated Information System Security Engineer III to join our team. The Information System Security Engineer (ISSE) III provides expert-level cybersecurity engineering, security architecture, and systems security engineering support for complex and mission-critical Department of War networks and information systems. Aligned with the DoD 8570/8140 IASAE Level III (Information Assurance System Architecture and Engineering) category, the ISSE III serves as a senior technical Subject Matter Expert (SME) responsible for integrating cybersecurity requirements throughout the complete system lifecycle.
The ISSE III applies advanced systems engineering and cybersecurity principles to the design, development, integration, assessment, authorization, and sustainment of secure systems. This position provides technical leadership in addressing complex cybersecurity challenges, developing resilient security architectures, mitigating sophisticated threats, and ensuring systems maintain an acceptable security posture throughout their operational lifecycle.
The ISSE III serves as a primary technical security advisor to Government stakeholders, program managers, system architects, engineers, cybersecurity personnel, and other technical teams. The position requires significant independent judgment, technical leadership, and the ability to translate mission requirements and evolving cybersecurity threats into practical, secure engineering solutions.
Key Responsibilities
- Serve as a senior cybersecurity engineering and Information Assurance System Architecture and Engineering (IASAE) Subject Matter Expert for complex DoD systems and networks.
- Integrate cybersecurity and security functional requirements throughout the system acquisition, architecture, engineering, development, integration, testing, deployment, and sustainment lifecycle.
- Develop and evaluate secure system architectures that address mission requirements, cybersecurity threats, vulnerabilities, and applicable DoD security requirements.
- Design and implement end-to-end security solutions for enterprise networks, applications, databases, cloud environments, infrastructure, and other mission-critical systems.
- Apply systems engineering methodologies to identify and mitigate cybersecurity risks throughout the system lifecycle.
- Harden application interfaces, data repositories, operating environments, cloud infrastructure, and system components in accordance with applicable security requirements and best practices.
- Incorporate Zero Trust Architecture principles, defense-in-depth, boundary protection, network segmentation, firewalls, access controls, identity management, and cryptographic protections into system designs.
- Evaluate system architectures, interfaces, and security boundaries to identify potential attack paths, weaknesses, and opportunities for improved protection.
- Lead or support threat modeling, attack-surface analysis, vulnerability assessments, risk assessments, and security architecture reviews.
- Analyze security vulnerabilities and threat intelligence to develop and implement proactive defensive measures against sophisticated adversaries.
- Develop, review, and maintain comprehensive Risk Management Framework (RMF) documentation, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and other authorization artifacts.
- Provide technical leadership and support for RMF authorization activities, including preparation for and maintenance of Interim Authority to Test (IATT) and Authority to Operate (ATO).
- Support the development and execution of security control assessment strategies and provide technical responses to assessment findings.
- Evaluate proposed system changes, engineering designs, interfaces, and configuration modifications for cybersecurity impacts.
- Participate in Configuration Control Boards, Engineering Change Boards, architecture reviews, technical interchange meetings, and security working groups.
- Lead technical walkthroughs, security design reviews, architecture assessments, and cybersecurity technical exchanges with Government and contractor personnel.
- Serve as the primary technical cybersecurity advisor to Government stakeholders, program managers, system engineers, software developers, system administrators, and cybersecurity leadership.
- Provide authoritative technical recommendations regarding cybersecurity risks, system vulnerabilities, security controls, architecture decisions, and remediation strategies.
- Analyze system and security logs to identify anomalous activity, indicators of compromise, and emerging security threats.
- Provide senior-level technical expertise during cybersecurity incident response, containment, mitigation, and recovery activities.
- Assist with forensic investigations and root-cause analysis involving suspected or confirmed cybersecurity incidents.
- Develop and implement technical solutions to address complex cybersecurity vulnerabilities and compliance deficiencies.
- Evaluate the integration and effectiveness of security technologies, including SIEM, IDS/IPS, firewalls, endpoint security, vulnerability management, identity and access management, encryption, and other defensive cybersecurity capabilities.
- Provide technical oversight and mentorship to junior cybersecurity engineers and other technical personnel.
- Participate in intelligence-community, DoD, industry, and technical working groups to evaluate emerging cybersecurity technologies, threats, standards, and engineering practices.
- Translate evolving cybersecurity policies, standards, threat information, and mission requirements into actionable engineering requirements.
- Support cybersecurity assessments, audits, inspections, accreditation activities, and other Government compliance requirements.
- Maintain current knowledge of DoD cybersecurity policies, NIST standards, DISA guidance, RMF requirements, Zero Trust principles, and emerging cybersecurity threats.
- Perform other related cybersecurity engineering and systems security duties as assigned.
- Bachelor's or Master's degree in Computer Science, Cybersecurity, Information Security, Information Assurance, Systems Engineering, or a related technical field.
- Must have or be able to obtain a CASP or CISSP prior to start date.
- 10+ years of progressively responsible experience in systems engineering, cybersecurity engineering, information assurance, security architecture, or a related technical discipline.
- Four years of directly relevant ISSE experience may be considered in lieu of the degree requirement, subject to applicable contract and IASAE Level III baseline qualification requirements.
- Must meet applicable DoD 8570/8140 IASAE Level III baseline qualification requirements.
- Demonstrated experience designing, engineering, implementing, or assessing security architectures for complex information systems and networks.
- Extensive experience supporting the DoD Risk Management Framework (RMF) and system authorization process.
- Demonstrated experience developing, reviewing, and maintaining RMF security authorization documentation, including SSPs, SAPs, SARs, POA&Ms, IATT, and ATO documentation.
- Extensive knowledge of cybersecurity controls, security architecture principles, vulnerability management, system hardening, and defense-in-depth.
- Experience conducting threat modeling, security assessments, vulnerability assessments, risk assessments, and security architecture reviews.
- Experience designing and implementing security solutions for networks, applications, databases, cloud environments, and enterprise infrastructure.
- Strong understanding of network security architecture, boundary protection, firewalls, segmentation, access controls, identity management, encryption, and cryptographic controls.
- Demonstrated understanding of Zero Trust security principles and architectures.
- Experience analyzing security logs, identifying anomalous activity, and supporting cybersecurity incident response and mitigation.
- Ability to independently analyze complex technical and cybersecurity problems and develop effective solutions.
- Excellent written and verbal communication skills with the ability to brief technical and non-technical Government stakeholders.
- Demonstrated ability to lead technical discussions, security reviews, engineering teams, and cross-functional working groups.
- Active DoD 8570/8140 IASAE Level III qualification or equivalent.
- Advanced cybersecurity certifications such as CISSP, CISSP-ISSAP, CISSP-ISSEP, CISM, CCSP, or equivalent.
- Extensive experience with eMASS or other RMF Governance, Risk, and Compliance (GRC) platforms.
- Experience with ACAS/Nessus, SCAP, vulnerability management, SIEM, HBSS/ESS, endpoint detection and response (EDR), IDS/IPS, and security monitoring technologies.
- Experience applying DISA STIGs/SRGs and NIST security controls to complex enterprise environments.
- Experience implementing or assessing Zero Trust Architecture in DoD environments.
- Experience supporting systems with high mission impact or highly sensitive/classified information.
- Experience working directly with DoD, Intelligence Community, or other Federal Government customers.
- Experience leading cybersecurity architecture reviews, technical working groups, and engineering change processes.
- Experience mentoring and providing technical direction to junior and mid-level cybersecurity engineers.
- Familiarity with emerging cybersecurity technologies, advanced persistent threats (APTs), threat intelligence, and modern defensive cyber operations.
- Ability to obtain and maintain a security clearance.
- Must be a U.S. Citizen.
About TRISTAR
TRISTAR is an SBA certified Service-Disabled Veteran-Owned professional services company supporting the U.S. Department of Defense programs. Our core competencies include Electronic Warfare, Enterprise Management, Full Spectrum Cybersecurity, Information Technology, Digital Transformation, Software Engineering and Development, Maritime Modernization and Engineering, and Technical Solutions.
TRISTAR was founded in March 1995 and has built an employee-focused collaborative environment which enables our team of professionals to create and deliver customized solutions to meet our customers’ mission critical challenges. TRISTAR’s core capabilities support customers with end-to-end solutions.
For over 30 years, TRISTAR has demonstrated and perfected our ability to successfully manage any task, small or large no matter how difficult or complex.
TRISTAR is proud to serve the Department of Defense and other Federal Agencies.
TRISTAR provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.