System Security Engineer
AmentumAbout the role
Your Impact:
Amentum is seeking a highly skilled System Security Engineer to support the design, implementation, and ongoing operations of enterprise security tools—including ACAS (Nessus/Tenable.sc), Trellix ePO (formerly McAfee ePolicy Orchestrator), and Microsoft Endpoint Configuration Manager (MECM/SCCM)—in a Department of Defense (DoD) environment. The successful candidate will play a critical role in enhancing cybersecurity posture, ensuring system compliance, and supporting vulnerability management and endpoint protection initiatives across a large-scale enterprise network as part of a team prototyping a next-generation collaboration capability for the Department of Defense
We value candidates who are detail-oriented while also being able to think and react quickly to emerging and unique problem sets. You’ll be expected to work onsite, have a strong work ethic, and possess the ability to work as a critical member of our team.
Responsibilities:
- Design and Architect Security Tool Deployments:
- Develop and maintain secure, scalable architecture for ACAS, Trellix, and MECM solutions in classified and unclassified DoD environments.
- Ensure tool integration with existing enterprise systems and SIEMs (e.g., Splunk, ArcSight).
- Implementation and Configuration:
- Configure and deploy ACAS (Tenable.sc and Nessus) for automated vulnerability scans and compliance assessments.
- Install, configure, and optimize Trellix ePO and associated modules (DLP, ENS, HIPS).
- Set up and manage MECM infrastructure for patch management, endpoint deployment, and compliance monitoring.
- Operations and Monitoring:
- Perform regular vulnerability scans, analyze findings, and generate risk-based remediation reports.
- Monitor endpoint security posture, respond to alerts, and maintain up-to-date AV/AM/EDR policies.
- Support patching cycles, software deployments, and inventory tracking via MECM.
- Security Compliance and Documentation:
- Ensure systems are compliant with DoD STIGs, RMF/NIST 800-53 requirements, and DISA mandates.
- Maintain documentation for configurations, processes, POA&Ms, and system security plans (SSPs).
- Assist with audit preparation, system hardening, and control implementation.
- Cross-Team Collaboration:
- Work closely with cybersecurity, systems, and network teams to identify threats and improve security posture.
- Use JIRA and Confluence tools to track assigned tasks and update progress and completion status
- Implement and maintain Government standards for system security
- Liaise with vendors and other IT personnel for problem resolution
Here's What You'll Need:
Requirements:
- IAT Level II or higher certification (e.g., Security+ CE, CySA+, CASP+, CISSP, or equivalent)
- 7-10+ years of experience supporting security tools in DoD or Federal IT environments
- Proven hands-on experience with:
- ACAS (Tenable.sc, Nessus)
- Trellix ePO (formerly McAfee) and its endpoint protection modules
- MECM/SCCM for patching, imaging, and software deployment
- Familiarity with DoD cybersecurity policies, STIGs, and RMF processes
- Experience with Microsoft Office applications such as Excel, Word, Outlook, and SharePoint
- Exceptional attention to detail; excellent verbal and written communication skills; strong organizational skills; critical thinking and problem-solving skills
- Ability to work both independently and as part of a team in a dynamic environment.
- Ability to travel up to 25%
Clearance Required:
- Active TS clearance with SCI eligibility
Minimum E
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s