Cleared On Site Information Systems Security Engineer (ISSE) (5362)
SMX
| Company | SMX |
| Category | Engineering |
| Location | Washington |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Not stated |
| Salary | Not stated by the employer |
| Posted | 18 Jun 2026 |
| Last verified | 11 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
SMX is seeking a highly motivated Information Systems Security Engineer (ISSE) – Mid to support a mission-critical federal program in Washington, DC. This individual will support the design, implementation, assessment, and continuous improvement of security controls across enterprise information systems and technology environments. The selected candidate will work closely with system owners, cybersecurity personnel, engineers, architects, and government stakeholders to ensure systems meet federal cybersecurity requirements while supporting mission objectives. The ideal candidate will possess experience supporting Risk Management Framework (RMF) activities, security engineering, vulnerability management, security testing, and system authorization efforts within complex federal environments. This role requires strong technical and analytical skills with the ability to evaluate security risks, implement mitigation strategies, and contribute to the secure operation of mission-critical systems. This position is on site in Washington, DC and requires an active TS/SCI clearance.
Essential Duties & Responsibilities:
Support the design, implementation, and maintenance of security controls for enterprise information systems and applications
Develop, maintain, and update security documentation including System Security Plans (SSPs), security control implementation documentation, mitigation plans, and supporting RMF artifacts
Assist with system categorization, authorization boundary development, and security architecture documentation
Create and maintain security test plans, procedures, and supporting documentation to validate implementation of security controls
Perform security assessments, control validations, vulnerability analyses, and risk evaluations to identify security weaknesses and recommend corrective actions
Support vulnerability remediation activities and validate effectiveness of implemented mitigations
Analyze security findings and recommend technical solutions to reduce risk and improve security posture
Support audit preparation, compliance assessments, and continuous monitoring activities
Review system configurations, software inventories, hardware inventories, and user access controls to ensure compliance with security requirements
Assist in the development and maintenance of business impact analyses, continuity of operations documentation, and security-related operational procedures
Monitor security alerts, vulnerability reports, and threat information to identify potential risks to information systems
Collaborate with system administrators, developers, cybersecurity personnel, and government stakeholders to address security requirements throughout the system lifecycle
Participate in security engineering reviews, architecture discussions, and technical planning activities
Support implementation of security best practices and contribute to program cybersecurity initiatives
Required Skills & Experience
Active TS/SCI clearance required
Minimum of 5 years of professional experience supporting cybersecurity, information assurance, security engineering, or related disciplines
Experience supporting Risk Management Framework (RMF) activities and NIST-based security compliance programs
Experience developing and maintaining SSPs, POA&Ms, security control documentation, and related authorization artifacts
Experience conducting vulnerability assessments, security testing, and risk analysis activities
Experience evaluating and implementing security controls in accordance with federal cybersecurity requirements
Familiarity with NIST 800-53, NIST 800-37, and federal information security requirements
Experience supporting Authorization to Operate (ATO) activities and continuous monitoring programs
Experience reviewing system architectures, boundary definitions, access controls, and security configurations
Knowledge of vulnerability ma