Information Systems Security Engineer (ISSE)
20 days ago
Colorado Springs
Job Description Information Systems Security Engineer (ISSE) Full-Time | On-Site • Location: Colorado Springs, CO, • Citizenship: United States citizenship required ExoAnalytic Solutions is a defense technology company developing cutting-edge sensor signal processing, algorithms, modeling, simulation, and analytics tools to support mission-critical defense and space systems. Our software and sensor technologies enhance the missile and space defense domains and enable faster, data-driven decision-making for national defense. As an employee-owned company, we combine deep technical expertise with a culture of innovation, autonomy, and shared success. Our engineers work at solving problems of global importance. ABOUT THE ROLE ExoAnalytic Solutions develops advanced algorithms, AI/ML solutions, and software tools for modeling, simulation, sensing, and decision support across space and missile defense systems. We are a recognized leader in algorithm development and applied artificial intelligence, delivering technically rigorous solutions to problems of national importance. ExoAnalytic Solutions is seeking an Information Systems Security Engineer (ISSE) to join a multidisciplinary team and be primarily responsible for conducting information system security engineering activities, with a focus on the full lifecycle of current systems and future requirements development. The ISSE applies best practices when implementing security requirements within information systems, including software engineering methodologies, system and security engineering principles, secure design, secure architecture, and secure coding techniques. This position primarily supports Special Access Programs (SAPs) for the Department of Defense (DoD) and Intelligence Community (IC). KEY RESPONSIBILITIES • Develops, documents, and implements cybersecurity architecture and security engineering solutions for classified systems., • Ensures system design aligns with DoD architecture frameworks, DoDI 5000-series systems engineering processes, and platform-specific security policies., • Applies security principles and technologies such as encryption, cross-domain solutions (CDS), Zero Trust, and endpoint security to system designs., • Supports all phases of the DoD RMF process, including:, • Categorize System, • Select & Implement Security Controls, • Assess Controls, • Authorize System, • Continuous Monitoring, • Develops RMF artifacts such as:, • System Security Plan (SSP), • Security Controls Traceability Matrix (SCTM), • Security Assessment Procedures, • POA&M entries and mitigation documentation, • Ensures compliance with DoDI 8510.01, JSIG, NIST SP 800‑37, NIST SP 800‑53, and CNSSI 1253., • Participates in Integrated Product Teams (IPTs) to embed security into requirements, design reviews, test planning, and deployment strategies., • Reviews engineering change proposals (ECPs) and configuration updates for security impacts., • Supports software development teams in DoD DevSecOps pipelines and secure coding practices., • Performs or supports security assessments, DISA STIG reviews, and vulnerability scans (ACAS/Nessus)., • Works with Security Control Assessors (SCAs), Authorizing Officials (AOs), and Assessment & Authorization (A&A) teams during security evaluations., • Reviews test results, mitigates vulnerabilities, and verifies closure of cybersecurity findings., • Provides security engineering expertise to system architects, infrastructure teams, program managers, and mission owners., • Develops and presents security briefings to leadership and accreditation authorities., • Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Systems, or a related technical field, or equivalent practical experience, • Experience cybersecurity engineering, information assurance, or information system security engineering supporting DoD or IC programs', • Hands-on experience supporting DoD Risk Management Framework (RMF) activities across one or more system lifecycles, • Strong problem-solving, documentation, and communication skills, • Top-Secret clearance with SCI eligibility., • 7-10+ years of cybersecurity engineering experience supporting DoD programs., • DoD 8570/8140 compliance (one of the following required/preferred):, • Security+ CE, • CASP+ CE, • CISSP / CISSP-ISSEP, • GSEC or similar, • Experience with DoD cloud environments, • Familiarity with Zero Trust architecture implementation, • Knowledge of DevSecOps pipelines (e.g., Platform One, GitLab, Jenkins, Kubernetes)., • Background in network security, PKI, endpoint protection, and identity management. $125,000 - $224,000 annually Actual level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, and years of experience. BENEFITS AND CULTURE ExoAnalytic Solutions is a technology and innovation leader providing world-class products and services to the U.S. federal government and commercial customers worldwide. As an employee-owned company, a competitive salary is only one part of your total rewards package. Our comprehensive benefits include: • Company-paid medical, vision, and dental coverage, • 401(k) Retirement Plan with a 6% company contribution (no employee match required), • Ample paid personal time off, including holidays, • Short- and long-term disability insurance and life insurance, • Additional discounts and perks to support your well-being EQUAL EMPLOYMENT OPPORTUNITY ExoAnalytic Solutions provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.