{"schemaVersion":"jobsearcher.job.v1","id":"c7a5cc918706b92cba4e8dd3","url":"https://jobsearcher.com/jobs/c7a5cc918706b92cba4e8dd3","canonicalUrl":"https://jobsearcher.com/jobs/c7a5cc918706b92cba4e8dd3","title":"Information System Security Engineer","description":"Description:\nMarkon is building a talent pool of Information System Security Engineers (ISSEs) to support our IC client from Chantilly, VA. The ideal candidate will have in-depth knowledge and experience with secure systems engineering, firewall administration, and NIST/FISMA/RMF standards.\nResponsibilities:\nPerform Information System Security Engineering (ISSE) activities throughout the system development lifecycle in accordance with NIST SP 800-160, NRO RMF requirements, and applicable cybersecurity directives.\nCapture, refine, and document information protection requirements and ensure their integration into system acquisitions, engineering activities, and development efforts.\nIntegrate security functional requirements into acquisition lifecycle phases, program milestones, engineering documentation, and system development processes.\nAssess cybersecurity risks, identify mitigation strategies, evaluate residual risk, and provide risk-based recommendations to stakeholders.\nSupport Risk Management Framework (RMF) activities, including system categorization, control implementation, assessment support, authorization support, and continuous monitoring activities.\nDevelop and maintain cybersecurity documentation supporting RMF and Assessment & Authorization (A&A) activities, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), risk assessments, and related artifacts.\nEvaluate proposed system changes, technology integrations, and engineering solutions to determine cybersecurity impacts and recommend appropriate security requirements.\nSupport the design, development, implementation, integration, and sustainment of secure information systems and information assurance architectures.\nAnalyze system and network architectures to identify security requirements and recommend protections that support confidentiality, integrity, availability, authentication, and non-repudiation.\nRecommend security architectures and engineering solutions that align with mission objectives, performance requirements, and cybersecurity best practices.\nConduct technical assessments to identify vulnerabilities, threats, and risks affecting enterprise, cloud, network, and mission systems.\nSupport vulnerability management activities, including vulnerability analysis, remediation planning, risk evaluation, and implementation of corrective actions.\nAssess and recommend security controls, common controls, and compensating controls to address identified security requirements and risks.\nSupport the integration and implementation of Cross Domain Solutions (CDS) and coordinate with relevant stakeholders to ensure compliance with organizational processes and authorization requirements.\nApply Information Assurance (IA) and cybersecurity principles in support of enterprise IT systems, communications systems, cloud environments, and mission networks.\nSupport configuration management activities to maintain the security posture of hardware, software, operating systems, applications, and infrastructure components.\nParticipate in system testing, integration testing, security validation activities, and engineering reviews to verify security requirements have been properly implemented.\nCollaborate with system engineers, program managers, security control assessors, authorizing officials, and other stakeholders to support system authorization and cybersecurity objectives.\nResearch emerging cybersecurity threats, vulnerabilities, technologies, and countermeasures and provide recommendations to improve system security and resiliency.\nParticipate in Integrated Product Teams (IPTs), engineering working groups, cybersecurity reviews, and technical forums to support mission and program objectives.\nSupport resilient system design and cybersecurity best practices that enable systems to operate through disruption, degradation, or hostile activity.\nQualifications:\nMinimum Qualifications:\nAn Active TS/SCI with a Counter Intelligence Poly (highly preferred from this client)\nBachelor's degree in Computer Science, Cybersecurity, Information Assurance, Information Systems, Computer Engineering, or a related technical field.\nMinimum of three (3) years of experience supporting Information System Security Engineering (ISSE), cybersecurity engineering, information assurance, risk management, or related cybersecurity disciplines.\nCurrent Information Assurance Management (IAM) Level II or equivalent qualifying certification in accordance with contract requirements:\nCAP (Certified Authorization Professional)\nCASP+ (CompTIA Advanced Security Practitioner)\nCISM (Certified Information Security Manager)\nCISSP (Certified Information Systems Security Professional)\nGSLC (GIAC Security Leadership Certification)\nCCISO (Certified Chief Information Security Officer)\nExperience supporting cybersecurity activities throughout the system development lifecycle.\nKnowledge of Risk Management Framework (RMF), NIST cybersecurity guidance, and Assessment & Authorization (A&A) processes.\nKnowledge of cybersecurity principles, information assurance concepts, systems security engineering methodologies, and secure system design practices.\nExperience evaluating security requirements, implementing security controls, and supporting cybersecurity compliance efforts.\n\nDesired Qualifications:\nKnowledge of ICD 503 and Intelligence Community authorization processes.\nExperience supporting NRO, Intelligence Community, Department of Defense, or National Security systems.\nExperience developing RMF authorization packages and supporting Authority to Operate (ATO) efforts.\nExperience supporting cloud security, virtualization technologies, or enterprise infrastructure environments.\nExperience supporting Windows, Linux, Unix, and macOS operating environments.\nExperience integrating Commercial Off-The-Shelf (COTS) and Government Off-The-Shelf (GOTS) technologies.\nExperience supporting Cross Domain Solutions (CDS), ICS/SCADA systems, or space system cybersecurity activities.\nSalary Range: USD $150,000.00 - USD $180,000.00 /Yr.\n\nThe Markon pay range for this position is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law. Overview:\nEager to join a team where your skills are valued, your growth is nurtured, and your impact is profound? Look no further than Markon, a premier consulting firm deeply dedicated to advancing our nation's most critical missions.\n\nAt Markon, we don't just offer jobs – we offer opportunities for personal and professional transformation. Empowering our employees to lead, innovate, and excel, we foster an environment where new ideas are not just welcomed but celebrated. As a perennial Washington Post Top Workplace, we prioritize the well-being and success of our team members, ensuring they can bring their best selves to work.\n\nHeadquartered in Falls Church, Virginia, Markon has garnered national recognition for our unwavering dedication to excellence in serving the intelligence community, as well as federal civilian and defense agencies. Our growing reach extends across 17 states, 116 countries, and 5 continents, where our team of dynamic professionals collaborates to deliver unparalleled program and project management services.\n\nMarkon values people and the tremendous impact each individual can make – which is why we’re consistently recognized as one of the best places to work in federal government consulting. Here, you can help solve the nation’s most important challenges, surrounded by colleagues who help you grow, advance, and succeed. We are deeply dedicated to what matters – bringing out the best in each other to advance our clients’ missions.\n\nJoin us and make a meaningful impact.\n\nMarkon is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, national origin, age, protected veteran status, or disability status. This job posting will remain open until the position is filled.\n\nBenefits Offered: Medical, Dental, Vision, Life Insurance, Short-Term Disability, Long-Term Disability, 401(k) match, Flexible Spending Accounts, EAP, Training and Tuition Assistance, Paid Time Off, and Holidays","company":"Markon","rawCompany":"markon","city":"Gaithersburg","state":"MD","isRemote":false,"isActive":false,"createdAt":"2026-08-03T13:32:22.380Z","occupations":[{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541330","title":"Engineering Services","slug":"engineering-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Information System Security Engineer","description":"Description:\nMarkon is building a talent pool of Information System Security Engineers (ISSEs) to support our IC client from Chantilly, VA. The ideal candidate will have in-depth knowledge and experience with secure systems engineering, firewall administration, and NIST/FISMA/RMF standards.\nResponsibilities:\nPerform Information System Security Engineering (ISSE) activities throughout the system development lifecycle in accordance with NIST SP 800-160, NRO RMF requirements, and applicable cybersecurity directives.\nCapture, refine, and document information protection requirements and ensure their integration into system acquisitions, engineering activities, and development efforts.\nIntegrate security functional requirements into acquisition lifecycle phases, program milestones, engineering documentation, and system development processes.\nAssess cybersecurity risks, identify mitigation strategies, evaluate residual risk, and provide risk-based recommendations to stakeholders.\nSupport Risk Management Framework (RMF) activities, including system categorization, control implementation, assessment support, authorization support, and continuous monitoring activities.\nDevelop and maintain cybersecurity documentation supporting RMF and Assessment & Authorization (A&A) activities, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plans of Action and Milestones (POA&Ms), risk assessments, and related artifacts.\nEvaluate proposed system changes, technology integrations, and engineering solutions to determine cybersecurity impacts and recommend appropriate security requirements.\nSupport the design, development, implementation, integration, and sustainment of secure information systems and information assurance architectures.\nAnalyze system and network architectures to identify security requirements and recommend protections that support confidentiality, integrity, availability, authentication, and non-repudiation.\nRecommend security architectures and engineering solutions that align with mission objectives, performance requirements, and cybersecurity best practices.\nConduct technical assessments to identify vulnerabilities, threats, and risks affecting enterprise, cloud, network, and mission systems.\nSupport vulnerability management activities, including vulnerability analysis, remediation planning, risk evaluation, and implementation of corrective actions.\nAssess and recommend security controls, common controls, and compensating controls to address identified security requirements and risks.\nSupport the integration and implementation of Cross Domain Solutions (CDS) and coordinate with relevant stakeholders to ensure compliance with organizational processes and authorization requirements.\nApply Information Assurance (IA) and cybersecurity principles in support of enterprise IT systems, communications systems, cloud environments, and mission networks.\nSupport configuration management activities to maintain the security posture of hardware, software, operating systems, applications, and infrastructure components.\nParticipate in system testing, integration testing, security validation activities, and engineering reviews to verify security requirements have been properly implemented.\nCollaborate with system engineers, program managers, security control assessors, authorizing officials, and other stakeholders to support system authorization and cybersecurity objectives.\nResearch emerging cybersecurity threats, vulnerabilities, technologies, and countermeasures and provide recommendations to improve system security and resiliency.\nParticipate in Integrated Product Teams (IPTs), engineering working groups, cybersecurity reviews, and technical forums to support mission and program objectives.\nSupport resilient system design and cybersecurity best practices that enable systems to operate through disruption, degradation, or hostile activity.\nQualifications:\nMinimum Qualifications:\nAn Active TS/SCI with a Counter Intelligence Poly (highly preferred from this client)\nBachelor's degree in Computer Science, Cybersecurity, Information Assurance, Information Systems, Computer Engineering, or a related technical field.\nMinimum of three (3) years of experience supporting Information System Security Engineering (ISSE), cybersecurity engineering, information assurance, risk management, or related cybersecurity disciplines.\nCurrent Information Assurance Management (IAM) Level II or equivalent qualifying certification in accordance with contract requirements:\nCAP (Certified Authorization Professional)\nCASP+ (CompTIA Advanced Security Practitioner)\nCISM (Certified Information Security Manager)\nCISSP (Certified Information Systems Security Professional)\nGSLC (GIAC Security Leadership Certification)\nCCISO (Certified Chief Information Security Officer)\nExperience supporting cybersecurity activities throughout the system development lifecycle.\nKnowledge of Risk Management Framework (RMF), NIST cybersecurity guidance, and Assessment & Authorization (A&A) processes.\nKnowledge of cybersecurity principles, information assurance concepts, systems security engineering methodologies, and secure system design practices.\nExperience evaluating security requirements, implementing security controls, and supporting cybersecurity compliance efforts.\n\nDesired Qualifications:\nKnowledge of ICD 503 and Intelligence Community authorization processes.\nExperience supporting NRO, Intelligence Community, Department of Defense, or National Security systems.\nExperience developing RMF authorization packages and supporting Authority to Operate (ATO) efforts.\nExperience supporting cloud security, virtualization technologies, or enterprise infrastructure environments.\nExperience supporting Windows, Linux, Unix, and macOS operating environments.\nExperience integrating Commercial Off-The-Shelf (COTS) and Government Off-The-Shelf (GOTS) technologies.\nExperience supporting Cross Domain Solutions (CDS), ICS/SCADA systems, or space system cybersecurity activities.\nSalary Range: USD $150,000.00 - USD $180,000.00 /Yr.\n\nThe Markon pay range for this position is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law. Overview:\nEager to join a team where your skills are valued, your growth is nurtured, and your impact is profound? Look no further than Markon, a premier consulting firm deeply dedicated to advancing our nation's most critical missions.\n\nAt Markon, we don't just offer jobs – we offer opportunities for personal and professional transformation. Empowering our employees to lead, innovate, and excel, we foster an environment where new ideas are not just welcomed but celebrated. As a perennial Washington Post Top Workplace, we prioritize the well-being and success of our team members, ensuring they can bring their best selves to work.\n\nHeadquartered in Falls Church, Virginia, Markon has garnered national recognition for our unwavering dedication to excellence in serving the intelligence community, as well as federal civilian and defense agencies. Our growing reach extends across 17 states, 116 countries, and 5 continents, where our team of dynamic professionals collaborates to deliver unparalleled program and project management services.\n\nMarkon values people and the tremendous impact each individual can make – which is why we’re consistently recognized as one of the best places to work in federal government consulting. Here, you can help solve the nation’s most important challenges, surrounded by colleagues who help you grow, advance, and succeed. We are deeply dedicated to what matters – bringing out the best in each other to advance our clients’ missions.\n\nJoin us and make a meaningful impact.\n\nMarkon is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, national origin, age, protected veteran status, or disability status. This job posting will remain open until the position is filled.\n\nBenefits Offered: Medical, Dental, Vision, Life Insurance, Short-Term Disability, Long-Term Disability, 401(k) match, Flexible Spending Accounts, EAP, Training and Tuition Assistance, Paid Time Off, and Holidays","datePosted":"2026-08-03T13:32:22.380Z","dateModified":"2026-08-03T13:32:22.380Z","hiringOrganization":{"@type":"Organization","name":"Markon","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Gaithersburg","addressRegion":"MD","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"c7a5cc918706b92cba4e8dd3"},"url":"https://jobsearcher.com/jobs/c7a5cc918706b92cba4e8dd3"}}