user avatar

Information Systems Security Engineer (ISSE)

Two Six Technologies

Posted today
Top Secret/SCI
$137,000 - $230,000
Polygraph
IT - Security
Chantilly, VA (On-Site/Office)

At Two Six Technologies, we build, deploy, and implement innovative products that solve the world's most complex challenges today. Through unrivaled collaboration and unwavering trust, we push the boundaries of what's possible to empower our team and support our customers in building a safer global future.

Information Systems Security Engineer (ISSE)

Two Six Technologies is currently seeking an Information Systems Security Engineer (ISSE)

The ISSE will lead and execute security engineering activities across complex, enterprise-scale environments. This role requires deep technical expertise across infrastructure, platforms, and applications, combined with expert-level, hands-on experience implementing the NIST Risk Management Framework (RMF) within federal government environments. The ideal candidate is a technical practitioner, not just an advisor - someone who can design, implement, assess, and secure systems end-to-end while directly supporting system authorization, continuous monitoring, and risk-based decision-making. This role also serves as the technical focal point for all security incidents, leading triage, investigation, and resolution efforts in coordination with program and enterprise security teams.

Location: Chantilly, VA

What you will do:
  • Serve as the Cyber Security Engineer SME, providing hands-on security engineering across all system layers (infrastructure, platform, and application)
  • Engineer, implement, and validate security controls in accordance with NIST SP 800-53 and RMF requirements
  • Lead and support RMF lifecycle activities (Categorize, Select, Implement, Assess, Authorize, Monitor)
  • Perform security engineering for:
    • Network architectures and boundary protections
    • Windows and Linux operating systems
    • Storage and virtualization platforms
    • Databases and data platforms
    • Web services, APIs, and application stacks
    • Custom and COTS/GOTS software solutions
  • Provide technical input to RMF artifacts, including:
    • System Security Plans (SSP)
    • Security Control Assessments (SCA) support
    • POA&Ms
    • Risk assessments and security impact analyses
  • Collaborate with system owners, architects, developers, ad operations teams to embed security into system design and implementation
  • Support ATO, re-authorization, and continuous monitoring activities
  • Identify security risks and provide practical, technically sound mitigation strategies
  • Participate in security reviews, technical design reviews, and vulnerability remediation efforts
  • Serve as technical l point of contact for all security incidents affecting the program
  • Lead triage and analysis of new security alerts from SIEM, IDS/IPS, and other security monitoring tools
  • Drive remediation efforts for recurring security alerts, identifying root causes and implementing systemic fixes
  • Coordinate incident response activities between program stakeholders and enterprise security operations
  • Act as primary liaison between program teams and enterprise security for incident escalation, resolution, and reporting
  • Perform forensic analysis and technical investigations of security events
  • Document security incidents, response actions, and lessons learned
  • Develop and maintain runbooks and playbooks for common security incident types

What you will need (basic qualifications):
  • Minimum ten (10) years of related cyber security engineering experience
  • Proven hands-on Cyber Security Engineer SME, not policy-only or audit-only
  • Comfortable working across network, system, platform, and application layers
  • Deep understanding of how security controls are actually implemented and validated
  • Experience in federal RMF-driven environments
  • Able to bridge security, engineering, and compliance effectively
  • Experienced in managing security incidents from detection through resolution
  • Skilled at balancing immediate incident response needs with long-term security improvements
  • Effective collaborator across organizational boundaries during high-pressure security events
  • Operate independently as the technical authority for system security engineering
  • Demonstrate the ability to provide technical hands-on configuration, validation, and assessment of security controls
  • Translate RMF and NIST requirements into real-world technical implementations
  • Communicate complex technical security issues clearly to both technical and non-technical stakeholders
  • Maintain a strong balance between security compliance and operational practicality
  • Lead rapid response to security incidents with minimal guidance
  • Demonstrate strong analytical and troubleshooting skills under pressure during active security events
  • Effectively communicate incident status, impact, and remediation progress to technical and leadership audiences
  • Security & Compliance
  • Expert-level experience with NIST Risk Management Framework (RMF) in federal government environments
    • Strong knowledge of:
      • NIST SP 800-53
      • NIST SP 800-37
      • NIST SP 800-30
    • Direct involvement I ATO packages, control implementation, and assessments
    • Hands-on experience with Security Information and Event Management (SIEM) platforms (e.g., Splunk, ELK Stack, ArcSight, QRadar)
    • Demonstrated experience in security incident detection, analysis, and response
    • Proven ability to triage security alerts and determine criticality and impact
  • Infrastructure & Platforms (Hands-On)
    • Networking (e.g., routing, switching, firewalls, load balancers, network security controls)
    • Operating Systems:
      • Windows Server
      • Linux (RHEL, CentOS)
    • Virtualization and storage platforms
    • Databases (SQL and/or NoSQL)
    • Data platforms (e.g., HPCC, Hadoop/Cloudera)
    • Web services, APIs, and application architectures
    • Software development environments and CI/CD pipelines
    • Security tooling (e.g., vulnerability scanners, endpoint protection, SIEM)
  • Engineering Experience
    • Security engineering and system hardening
    • Vulnerability discovery and remediation
    • Secure system design and architecture reviews
    • Technical documentation supporting RMF compliance
    • Experience in cloud environments (AWS, Azure, GCP, CI) within federal RMF contexts
    • Experience with DevSecOps practices
  • Bachelor's degree in computer science, IT, or a related technical discipline, or the equivalent combination of education, technical training, or work/military experience

Nice If You Have Experience with:
  • Hands-on experience with containerization and orchestration (Docker, Kubernetes)
  • Hands-on experience with infrastructure-as-code
  • Knowledge of federal overlays (e.g., DoD, FISMA High/Moderate)
  • Relevant certifications (preferred, not required):
    • CISSP
    • CAP
    • CISM
    • Security+
    • Cloud Security
    • Certified Ethical Hacker
  • Experience with guiding and directing junior engineers and information systems security officer (ISSO)
  • Experience with security orchestration, automation, and response (SOAR) platforms
  • Background in threat hunting and proactive security monitoring
  • Relevant incident response certifications

Clearance Requirement:

Active TS/SCI with Polygraph

#LI-JS

Two Six Technologies is committed to providing competitive and comprehensive compensation packages that reflect the value we place on our employees and their contributions. We believe in rewarding skills, experience, and performance. Our offerings include but are not limited to, medical, dental, and vision insurance, life and disability insurance, retirement benefits, paid leave, tuition assistance and professional development.

The projected salary range listed for this position is annualized. This is a general guideline and not a guarantee of salary. Salary is one component of our total compensation package and the specific salary offered is determined by various factors, including, but not limited to education, experience, knowledge, skills, geographic location, as well as contract specific affordability and organizational requirements.

Salary Range

$137,000 - $230,000 USD

Looking for other great opportunities? Check out Two Six Technologies Opportunities for all our Company's current openings!

Ready to make the first move towards growing your career? If so, check out the Two Six Technologies Candidate Journey ! This will give you step-by-step directions on applying, what to expect during the application process, information about our rich benefits and perks along with our most frequently asked questions. If you are undecided and would like to learn more about us and how we are contributing to essential missions, check out our Two Six Technologies News page! We share information about the tech world around us and how we are making an impact! Still have questions, no worries! You can reach us at Contact Two Six Technologies . We are happy to connect and cover the information needed to assist you in reaching your next career milestone.

Two Six Technologies is an Equal Opportunity Employer and does not discriminate in employment opportunities or practices based on race (including traits historically associated with race, such as hair texture, hair type and protective hair styles (e.g., braids, twists, locs and twists)), color, religion, national origin, sex (including pregnancy, childbirth or related medical conditions and lactation), sexual orientation, gender identity or expression, age (40 and over), marital status, disability, genetic information, and protected veteran status or any other characteristic protected by applicable federal, state, or local law.

If you are an individual with a disability and would like to request reasonable workplace accommodation for any part of our employment process, please send an email to accommodations@twosixtech.com . Information provided will be kept confidential and used only to the extent required to provide needed reasonable accommodations.

Additionally, please be advised that this business uses E-Verify in its hiring practices.

By submitting the following application, I hereby certify that to the best of my knowledge, the information provided is true and accurate.
group id: 91123695
N
Name Hidden

Two Six Technologies

job ad image
Find Two Six Technologies on Social Media
Network Employers
user avatar
About Us
Mission Focused. Impact Driven. At Two Six Technologies, we build, deploy, and implement innovative products that solve the world’s most complex challenges today. Through unrivaled collaboration and unwavering trust, we push the boundaries of what’s possible to empower our team and support our customers in building a safer global future. Through private R&D, relentless innovation, and deep technical expertise in cyber, information operations, data science, electronic systems, mobility, and user experience, we serve customers that include DARPA, the Department of State, U.S. Cyber Command, the Department of Homeland Security, and beyond.
job ad2 image

Two Six Technologies Jobs


Job Category
IT - Security
Clearance Level
Top Secret/SCI