Jobs and Careers
BY

Information System Security Engineer 2

By Light Professional IT Services LLC
United Statesfull_timeVerifiedPosted 24 Feb 2025

About the role

Company Overview

By Light Professional IT Services LLC readies warfighters and federal agencies with technology and systems engineered to connect, protect, and prepare individuals and teams for whatever comes next. Headquartered in McLean, VA, By Light supports defense, civilian, and commercial IT customers worldwide. 

 

Cole Engineering Services (CESI), a By Light company, is recognized as a premier provider of modeling and simulation (M&S) training solutions to the Federal Government and industry. Since 2004, CESI has been at the forefront of developing, maintaining, and integrating simulation-based training, serious gaming, technical services, training and other support in live, virtual, constructive, and gaming (LVCG) domains.  CESI also designs, builds and runs infrastructure, platforms, applications and processes that enable cyber training for the integrated multi-domain force. Our vision is to become a worldwide full spectrum LVCG and cyber training/analysis developer, integrator and services provider.

Position Overview

Cole Engineering (CESI) is looking for a technically proficient Information Systems Security Engineer II (ISSE) who will perform critical engineering tasks to develop and maintain the cybersecurity posture of Department of Defense (DoD) information systems. Candidates will work within a team to ensure the security and integrity of our systems through robust patch management processes and adherence to Security Technical Implementation Guides (STIG) checklists. Candidates will work closely with development teams to assess vulnerabilities, implement security patches, and maintain compliance with DoD security standards. 

Responsibilities

  • Develop creative technical and procedural solutions to effectively secure information systems without introducing significant operational overhead.
  • Perform technical implementation of security functionality to comply with NIST SP 800-53A controls and ensure the protection of computer systems, networks, and information.
  • Validate security components are operating efficiently and are providing the expected insight into the information system through continuous monitoring
  • Maintain the security posture of the information system through applying periodic DISA STIG configurations and vulnerability patch updates
  • Perform self-assessments of information systems using manual and automated compliance tools in support of obtaining or maintaining a DoD RMF ATO.
  • Propose justification and mitigating countermeasures to reduce or eliminate risk level of an identified vulnerability.
  • Minimum 5 years of experience working in Information Security or general IT areas related to risk management, controls assurance, compliance programs, cybersecurity and information security industry standards.
  • Systems administration skills, experience with security settings, services, hardening of systems (STIGs, security policies); any shell scripting a plus.
  • Formal technical documentation skills.

Required Experience/Qualifications

  • Develop creative technical and procedural solutions to effectively secure information systems without introducing significant operational overhead.
  • Perform technical implementation of security functionality to comply with NIST SP 800-53A controls and ensure the protection of computer systems, networks, and information.
  • Validate security components are operating efficiently and are providing the expected insight into the information system through continuous monitoring
  • Maintain the security posture of the information system through applying periodic DISA STIG configurations and vulnerability patch updates
  • Perform self-assessments of information systems using manual and automated compliance tools in support of obtaining or maintaining a DoD RMF ATO.
  • Propose justification and mitigating countermeasures to reduce or eliminate risk level of an identified vulnerability.
  • Minimum 5 years of experience working in Information Security or general IT areas related to risk management, controls assurance, compliance programs, cybersecurity and information security industry standards.
  • Systems administration skills, experience with security settings, services, hardening of systems (STIGs, security policies); any shell scripting a plus.
  • Formal technical documentation skills.

Required Certifications:

  • This position requires certifications necessary to meet IAT II in accordance with DoD 8570-01-M.
  • One or more of the following certifications are required within 90 days of hire date.GSEC; Security+ 
  • SSCP
  • CCNA Security 
  • CEH

Preferred Experience/Qualifications

  • Experience securing and managing containerized environments, including Kubernetes cluste

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

By Light Professional IT Services LLC

View company profile →