user avatar

Information System Security Engineer (ISSE)

Kentro

Posted today

Job Requirements

washington, WA
Public Trust Polygraph Unspecified
Career Level not specified
$150,000 - $180,000

Job Description

Overview

Thank you for considering IT Concepts dba Kentro, where innovation drives opportunity and collaboration leads to success. Our dynamic community of experts is fully committed to advancing our customers' missions, fostering professional growth, and making a positive impact on our communities.

By joining our supportive community, you will find that Kentro is dedicated to your personal and professional development. Together, we can drive meaningful change, spark innovation, and achieve extraordinary milestones.

Kentro is hiring for an Information System Security Engineer (ISSE) in support of a multi-workstream comprehensive Artificial intelligence (AI) enabled cybersecurity modernization project for a U.S. Government program that includes automation, cybersecurity engineering, defense operations, continuous monitoring, Risk Management, security assessments and compliance, and cybersecurity automation platforms. This modernization effort encompasses the security tools, processes, and workflows that support the client's full cybersecurity mission - transitioning from legacy manual approaches to an integrated, automated, AI-enabled operating model that streamlines cybersecurity processes and workflows while reducing the operational burden and improving the overall cybersecurity posture of the client's enterprise systems.

In this role, the ISSE will design and implement automated compliance workflows using eGRC platforms and automation tools to move the client from manual, document-heavy compliance processes to an automated, data-driven Risk Management Framework (RMF) program. The ISSE will use machine-readable standards such as OSCAL and apply automation and AI-enabled tools to speed up security documentation, control assessment, and continuous monitoring. The ISSE will work with system owners, ISSOs, engineers, assessors, and Authorizing Officials to get to Authority to Operate (ATO) faster and to sustain continuous ATO (cATO) without compromising security.

Compensation Range: The pay range for this position is $150,000-180,000 annually. Kentro determines compensation by evaluating current government contracting and commercial market conditions, as well as the role's specific requirements. Final salary placement within this range will be based on the candidate's relevant skills, experience, education, certifications, location, and security clearance level, where applicable.

This Job Description reflects the primary duties of the role; however, it is not intended to be all-inclusive. Team members may be asked to take on additional responsibilities in alignment with customer expectations, business needs, and Kentro's culture of collaboration and adaptability.

Responsibilities

RMF Engineering and Authorization Support
  • Lead security engineering across all seven steps of the RMF lifecycle (NIST SP 800-37 Rev. 2), from categorization through continuous monitoring, for complex on-premises, cloud, and hybrid systems.
  • Build security and privacy requirements into system architecture and design reviews, applying NIST SP 800-53 Rev. 5 controls, tailored baselines, and applicable overlays.
  • Support to develop, review, and maintain authorization packages. These include System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), and supporting artifacts.
  • Advise Authorizing Officials and stakeholders on risk posture, residual risk, and risk acceptance decisions.

Compliance Automation and Architecture
  • Architect, configure, and administer GRC platforms (i.e. ServiceNow) and automated tools (i.e. RegScale, etc.) to automate control implementation tracking, evidence collection, assessments, and POA&M management.
  • Design a compliance-as-code approach using OSCAL to create machine-readable SSPs, component definitions, assessment plans, and results.
  • Integrate the eGRC platform and automated tools (i.e. RegScale) with enterprise tools through APIs. Examples include vulnerability scanners (Tenable, Qualys), SIEM (Splunk, Elastic), configuration management, CI/CD pipelines, and asset inventories. The aim is near-real-time compliance visibility.
  • Where applicable, build data exchanges with authoritative government systems of record such as ServiceNow, eMASS, CSAM, or Xacta.
  • Establish reusable control inheritance models, common control providers, and standardized component libraries across the client's system portfolio.

AI-Enabled Security and Compliance
  • Evaluate, pilot, and put into operation automated/AI tools that support compliance work. Uses include drafting control implementation narratives, mapping controls across frameworks, analyzing evidence, identifying gaps, and prioritizing POA&M items.
  • Set up human-in-the-loop review processes, validation criteria, and quality controls so that AI-generated content is accurate, traceable, and defensible to assessors.
  • Assess AI tools and systems against relevant security and governance requirements, including the NIST AI Risk Management Framework (AI RMF 1.0), applicable OMB AI guidance, and agency AI policies. Address data handling, model risk, and supply chain concerns.
  • Ensure AI tool use complies with data classification, CUI handling, and FedRAMP authorization requirements.

Continuous Monitoring and Modernization
  • Design and implement Information Security Continuous Monitoring (ISCM) strategies that support ongoing authorization and cATO objectives.
  • Support Zero Trust Architecture initiatives aligned with federal and DoD Zero Trust strategies, and map ZT capabilities to control requirements.
  • Develop dashboards and metrics that give leadership clear, current views of compliance status, risk trends, and program maturity.
  • Oversee secure configuration baselines and hardening using DISA STIGs, SRGs, and CIS Benchmarks, and automate compliance verification where possible.

Technical Leadership and Collaboration
  • Serve as a technical advisor to government leadership on RMF modernization and automation strategy, tool selection, and process improvement.
  • Develop standard operating procedures, playbooks, and training so ISSOs and system teams can use the new automated workflows.
  • Mentor junior security engineers and compliance analysts.
  • Communicate complex technical and risk concepts clearly to technical and non-technical audiences.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, Engineering, or a related field. Equivalent experience may substitute.
  • 8+ years of experience in information security, with at least 5 years of hands-on RMF implementation and ATO support for federal or DoD systems.
  • Deep working knowledge of NIST SP 800-37, 800-53 Rev. 5, 800-53A, 800-137, and FIPS 199/200.
  • Demonstrated experience with eGRC or compliance automation platforms, preferably ServiceNow and RegScale.
  • Experience integrating security tools through REST APIs and working with structured data formats (JSON, XML, YAML).
  • Scripting or automation skills in Python, PowerShell, or similar languages for compliance data processing and tool integration.
  • DoD 8140 / 8570 IAT Level III or IAM Level II-III compliant certification, such as CISSP, CISM, or CGRC (formerly CAP).
  • Excellent written communication skills, with a track record of producing high-quality security documentation.

Preferred Qualifications:
  • Hands-on experience authoring or consuming OSCAL content.
  • Experience applying generative AI or LLM tools in a regulated environment, including prompt design, output validation, and governance.
  • Familiarity with FedRAMP authorization processes, including FedRAMP 20x modernization efforts.
  • Knowledge of cloud security architecture in AWS GovCloud, Azure Government, or Google Cloud for Government.
  • Experience with DevSecOps pipelines and embedding security gates into CI/CD workflows.
  • Knowledge of CMMC, NIST SP 800-171, or the DoD Cybersecurity Reference Architecture.
  • Additional certifications such as CCSP, CISSP-ISSEP, CISA, AWS/Azure security specialty, or ServiceNow/RegScale platform training/certification.

Clearance Requirement:
  • Must be able to obtain and maintain a Public Trust clearance.
  • US Citizen or Lawful Permanent Resident (Green Card)

Benefits

The Company

We believe in generating success collaboratively, enabling long-term mission success, and building trust for the next challenge. With you as our partner, let's solve challenges, think innovatively, and maximize impact. As a valued member of our team, you have the unique opportunity to work in a diverse range of technology and business career paths, all while supporting our nation and delivering innovative technology solutions. We are a close community of experts that pride ourselves on creating an environment defined by teamwork, dedication, and excellence.

We hold three ISO certifications (27001:2013, 20000-1:2011, 9001:2015), two CMMI ML 3 ratings (DEV and SVC) and CMMC Level 2 Certification.

Industry Recognition

Growth | Inc 5000's Fastest Growing Private Companies, DC Metro List Fastest Growing; Washington Business Journal: Fastest Growing Companies, Top Performing Small Technology Companies in Greater D.C.

Culture | Northern Virginia Technology Council Tech 100 Honoree; Virginia Best Place to Work; Washington Business Journal: Best Places to Work, Corporate Diversity Index Winner - Mid-Size Companies, Companies Owned by People of Color; Department of Labor's HireVets for our work helping veterans transition; SECAF Award of Excellence finalist; Victory Military Friendly Brand; Virginia Values Veterans (V3); Cystic Fibrosis Foundation Corporate Breath Award

Benefits

We offer competitive benefits package including paid time off, healthcare benefits, supplemental benefits, 401k including an employer match, discount perks, rewards, and more. We invest in our employees - Every employee is eligible for education reimbursement for certifications, degrees, or professional development. Reimbursement amounts may fluctuate due to IRS limitations. We want you to grow as an expert and a leader and offer flexibility for you to take a course, complete a certification, or other professional growth and networking. We are committed to supporting your curiosity and sustaining a culture that prioritizes commitment to continuous professional development.

We work hard; we play hard. Kentro is committed to incorporating fun into every day. We dedicate funds for activities - virtual and in-person - e.g., we host happy hours, holiday events, fitness & wellness events, and annual celebrations. In alignment with our commitment to our communities, we also host and attend charity galas/events. We believe in appreciating your commitment and building a positive workspace for you to be creative, innovative, and happy.

Commitment Equal Opportunity Employment & VEVRAA

Kentro is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state or local law.

Kentro is strongly committed to compliance with VEVRAA and other applicable federal, state, and local laws governing equal employment opportunity. We have developed comprehensive policies and procedures to ensure our hiring practices align with these requirements.

As part of our VEVRAA compliance efforts, Kentro has established an equal opportunity plan outlining our commitment to recruiting, hiring, and advancing protected veterans. This plan is regularly reviewed and updated to ensure its effectiveness.

We encourage protected veterans to self-identify during the application process. This information is strictly confidential and will only be used for reporting and compliance purposes as required by law. Providing this information is voluntary and will not impact your employment eligibility.

Our commitment to equal employment opportunity extends beyond legal compliance. We are dedicated to fostering an inclusive workplace where all employees, including protected veterans, are treated with dignity, respect, and fairness.

How to Apply

To apply to Kentro Positions- Please click on the job link and then click the blue "Apply" button at the top right of Job Description. Please upload your resume and complete all the application steps. You must fully submit the application for Kentro to consider you for a position. If you need alternative application methods, please email careers@kentro.us and request assistance.

Accommodations

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable Accommodations may be made to enable qualified individuals with disabilities to perform the essential functions. If you need to discuss reasonable accommodations, please email careers@kentro.us .

#LI-
group id: 10484831

Similar Jobs


Job Category
IT - Software
Clearance Level
Public Trust
Employer
Kentro