Job Requirements
Bolling Air Force Base, DC
Top Secret/SCI CI Polygraph
Career Level not specified
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Job Description
BOAB Ventures is seeking an experienced Information Systems Security Engineer (ISSE) to support mission-critical systems within a highly secure Department of Defense and Intelligence Community environment.
This is a hands-on security engineering position for someone who can go beyond documenting compliance requirements and actively design, implement, integrate, harden, and validate security controls within complex classified systems.
The ideal candidate understands the intent behind cybersecurity requirements and can work directly with system administrators, software engineers, infrastructure teams, and government stakeholders to develop secure technical solutions that satisfy both mission and compliance objectives.
What You'll Do
Required Skills
Desired Skills
BOAB Ventures is seeking an experienced Information Systems Security Engineer (ISSE) to support mission-critical systems within a highly secure Department of Defense and Intelligence Community environment.
This is a hands-on security engineering position for someone who can go beyond documenting compliance requirements and actively design, implement, integrate, harden, and validate security controls within complex classified systems.
The ideal candidate understands the intent behind cybersecurity requirements and can work directly with system administrators, software engineers, infrastructure teams, and government stakeholders to develop secure technical solutions that satisfy both mission and compliance objectives.
What You'll Do
- Engineer and integrate cybersecurity controls throughout the system development lifecycle.
- Translate RMF, ICD 503, CNSSI 1253, and NIST SP 800-53 requirements into implemented and testable technical controls.
- Support systems through the ATO lifecycle, including development and validation of technical security evidence.
- Implement and validate DISA STIGs and Intelligence Community security baselines across Windows, Linux, network, and infrastructure environments.
- Conduct vulnerability assessment and remediation using tools such as ACAS, Nessus, SCAP, and related security technologies.
- Analyze STIG and security-control requirements to understand the underlying vulnerability and develop appropriate technical solutions, alternative implementations, or compensating controls when standard configurations conflict with mission requirements.
- Work directly with engineering and development teams to incorporate security into system architecture, infrastructure, applications, and deployment processes.
- Integrate cybersecurity requirements into DevSecOps and CI/CD environments where applicable.
- Engineer and validate security monitoring, logging, auditing, and continuous-monitoring capabilities.
- Assess proposed system changes for security impact and recommend appropriate technical controls or remediation.
- Support secure cloud, on-premises, containerized, and classified computing environments.
- Assist with incident response, vulnerability remediation, configuration management, and technical security investigations.
- Collaborate with ISSMs, ISSOs, system owners, engineers, developers, and government stakeholders throughout authorization and operational activities.
Required Skills
- Active TS/SCI security clearance.
- Ability and willingness to obtain a polygraph.
- Demonstrated hands-on experience implementing cybersecurity controls within classified DoD or Intelligence Community environments.
- Strong understanding of RMF, NIST SP 800-53, ICD 503, and CNSSI 1253.
- Experience engineering or supporting systems through ATO.
- Hands-on experience with DISA STIG implementation and system hardening.
- Experience with vulnerability-management and compliance tools such as ACAS, Nessus, SCAP, or equivalent technologies.
- Experience securing and troubleshooting Windows and/or Linux environments.
- Ability to translate cybersecurity requirements into actionable technical solutions.
- Strong understanding of vulnerability, risk, compensating controls, and security-control implementation.
- Ability to communicate effectively with both technical engineering teams and government/customer stakeholders.
- DoD 8570/8140 IASAE Level II certification or equivalent qualification.
Desired Skills
- IASAE Level III qualification.
- Experience supporting JWICS, SAP, or similar highly classified environments.
- Experience with AWS GovCloud, Azure Government, or other secure cloud environments.
- Experience with DevSecOps, CI/CD pipelines, containers, Kubernetes, or Infrastructure as Code.
- Experience automating security or system-hardening activities using PowerShell, Bash, Python, Ansible, or similar technologies.
- Experience with cross-domain solutions or complex classified network architectures.
- Experience securing AI/ML platforms, data pipelines, or emerging technologies.
- Prior Military Intelligence, DoD, or Intelligence Community experience.
group id: 91165268