New

Information Systems Security Engineer (ISSE)

Chantilly, Virginia

At Two Six Technologies, we build, deploy, and implement innovative products that solve the world’s most complex challenges today. Through unrivaled collaboration and unwavering trust, we push the boundaries of what’s possible to empower our team and support our customers in building a safer global future.

Information Systems Security Engineer (ISSE)

Two Six Technologies is currently seeking an Information Systems Security Engineer (ISSE)

The ISSE will lead and execute security engineering activities across complex, enterprise-scale environments. This role requires deep technical expertise across infrastructure, platforms, and applications, combined with expert-level, hands-on experience implementing the NIST Risk Management Framework (RMF) within federal government environments. The ideal candidate is a technical practitioner, not just an advisor – someone who can design, implement, assess, and secure systems end-to-end while directly supporting system authorization, continuous monitoring, and risk-based decision-making. This role also serves as the technical focal point for all security incidents, leading triage, investigation, and resolution efforts in coordination with program and enterprise security teams.

Location: Chantilly, VA

What you will do:

  • Serve as the Cyber Security Engineer SME, providing hands-on security engineering across all system layers (infrastructure, platform, and application)
  • Engineer, implement, and validate security controls in accordance with NIST SP 800-53 and RMF requirements
  • Lead and support RMF lifecycle activities (Categorize, Select, Implement, Assess, Authorize, Monitor)
  • Perform security engineering for:
    • Network architectures and boundary protections
    • Windows and Linux operating systems
    • Storage and virtualization platforms
    • Databases and data platforms
    • Web services, APIs, and application stacks
    • Custom and COTS/GOTS software solutions
  • Provide technical input to RMF artifacts, including:
    • System Security Plans (SSP)
    • Security Control Assessments (SCA) support
    • POA&Ms
    • Risk assessments and security impact analyses
  • Collaborate with system owners, architects, developers, ad operations teams to embed security into system design and implementation
  • Support ATO, re-authorization, and continuous monitoring activities
  • Identify security risks and provide practical, technically sound mitigation strategies
  • Participate in security reviews, technical design reviews, and vulnerability remediation efforts
  • Serve as technical l point of contact for all security incidents affecting the program
  • Lead triage and analysis of new security alerts from SIEM, IDS/IPS, and other security monitoring tools
  • Drive remediation efforts for recurring security alerts, identifying root causes and implementing systemic fixes
  • Coordinate incident response activities between program stakeholders and enterprise security operations
  • Act as primary liaison between program teams and enterprise security for incident escalation, resolution, and reporting
  • Perform forensic analysis and technical investigations of security events
  • Document security incidents, response actions, and lessons learned
  • Develop and maintain runbooks and playbooks for common security incident types

What you will need (basic qualifications):

  • Minimum ten (10) years of related cyber security engineering experience
  • Proven hands-on Cyber Security Engineer SME, not policy-only or audit-only
  • Comfortable working across network, system, platform, and application layers
  • Deep understanding of how security controls are actually implemented and validated
  • Experience in federal RMF-driven environments
  • Able to bridge security, engineering, and compliance effectively
  • Experienced in managing security incidents from detection through resolution
  • Skilled at balancing immediate incident response needs with long-term security improvements
  • Effective collaborator across organizational boundaries during high-pressure security events
  • Operate independently as the technical authority for system security engineering
  • Demonstrate the ability to provide technical hands-on configuration, validation, and assessment of security controls
  • Translate RMF and NIST requirements into real-world technical implementations
  • Communicate complex technical security issues clearly to both technical and non-technical stakeholders
  • Maintain a strong balance between security compliance and operational practicality
  • Lead rapid response to security incidents with minimal guidance
  • Demonstrate strong analytical and troubleshooting skills under pressure during active security events
  • Effectively communicate incident status, impact, and remediation progress to technical and leadership audiences
  • Security & Compliance
  • Expert-level experience with NIST Risk Management Framework (RMF) in federal government environments
    • Strong knowledge of:
      • NIST SP 800-53
      • NIST SP 800-37
      • NIST SP 800-30
    • Direct involvement I ATO packages, control implementation, and assessments
    • Hands-on experience with Security Information and Event Management (SIEM) platforms (e.g., Splunk, ELK Stack, ArcSight, QRadar)
    • Demonstrated experience in security incident detection, analysis, and response
    • Proven ability to triage security alerts and determine criticality and impact
  • Infrastructure & Platforms (Hands-On)
    • Networking (e.g., routing, switching, firewalls, load balancers, network security controls)
    • Operating Systems:
      • Windows Server
      • Linux (RHEL, CentOS)
    • Virtualization and storage platforms
    • Databases (SQL and/or NoSQL)
    • Data platforms (e.g., HPCC, Hadoop/Cloudera)
    • Web services, APIs, and application architectures
    • Software development environments and CI/CD pipelines
    • Security tooling (e.g., vulnerability scanners, endpoint protection, SIEM)
  • Engineering Experience
    • Security engineering and system hardening
    • Vulnerability discovery and remediation
    • Secure system design and architecture reviews
    • Technical documentation supporting RMF compliance
    • Experience in cloud environments (AWS, Azure, GCP, CI) within federal RMF contexts
    • Experience with DevSecOps practices
  • Bachelor’s degree in computer science, IT, or a related technical discipline, or the equivalent combination of education, technical training, or work/military experience

Nice If You Have Experience with:

  • Hands-on experience with containerization and orchestration (Docker, Kubernetes)
  • Hands-on experience with infrastructure-as-code
  • Knowledge of federal overlays (e.g., DoD, FISMA High/Moderate)
  • Relevant certifications (preferred, not required):
    • CISSP
    • CAP
    • CISM
    • Security+
    • Cloud Security
    • Certified Ethical Hacker
  • Experience with guiding and directing junior engineers and information systems security officer (ISSO)
  • Experience with security orchestration, automation, and response (SOAR) platforms
  • Background in threat hunting and proactive security monitoring
  • Relevant incident response certifications

Clearance Requirement:

Active TS/SCI with Polygraph

#LI-JS

Two Six Technologies is committed to providing competitive and comprehensive compensation packages that reflect the value we place on our employees and their contributions. We believe in rewarding skills, experience, and performance. Our offerings include but are not limited to, medical, dental, and vision insurance, life and disability insurance, retirement benefits, paid leave, tuition assistance and professional development.

The projected salary range listed for this position is annualized. This is a general guideline and not a guarantee of salary. Salary is one component of our total compensation package and the specific salary offered is determined by various factors, including, but not limited to education, experience, knowledge, skills, geographic location, as well as contract specific affordability and organizational requirements.

Salary Range

$137,000 - $230,000 USD

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Education

Select...
Select...
Select...

Select...
Select...

For more information on clearances, review this document

Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Two Six Technologies’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.