Demo

Information Systems Security Engineer

Diné Development Corporation
Rockville, MD Full Time
POSTED ON 4/12/2025
AVAILABLE BEFORE 5/9/2025
We are seeking an experienced Information Systems Security Officer to join our dynamic team. In this role , you will support our client's ISSO and Risk and Compliance teams, participating in activities related to risk management, compliance, and information system security. Your expertise in FedRAMP, RMF, and accreditation assessments will be crucial in ensuring our client's systems adhere to Federal standards.

Job Duties And Responsibilities

  • Support a real-time risk management system that fosters collaboration and enhances security practices within the organization.
  • Conduct regular security risk analyses for hospitals and healthcare systems to identify vulnerabilities and mitigate potential threats.
  • Stay abreast of Healthcare IT technologies and apply NIST 800 series methodologies to safeguard them effectively.
  • Provide technical analysis and support to accreditation assessors and ISSOs.
  • Conduct analysis of current environment and provide recommendations to align accreditation processes with NIST and RMF guidance
  • Create and maintain information security policies in compliance with NIST and HIPAA regulations.
  • Utilize Archer to develop and maintain system accreditation lifecycle workflows and ATO packet management processes.
  • Conduct comprehensive security control assessments following NIST, IHS, and CISA guidelines
  • Conduct security risk analyses for current and emerging systems
  • Conduct comprehensive assessments of security controls for IHS systems and sites, following NIST and CISA guidelines and ensuring adherence to risk management practices.
  • Thoroughly review system and site artifacts to verify compliance with NIST RMF requirements and identify potential areas for improvement.
  • Utilize network scanning and patching tools to mitigate vulnerabilities and enhance system security.
  • Prepare and present Approval to Operate (ATO) or Interim Approval to Test (IATT) documents, ensuring compliance with assessment requirements and CATOs.
  • Stay current with relevant NIST publications, NIST, CISA and IHS standards, and other guidelines.
  • Contribute to the development of policies, procedures, and methodologies that align with NIST RMF and support the organization's transition to these frameworks.
  • Utilize network scanning and patching tools to mitigate vulnerabilities and enhance system security.
  • Participate in staff assistance visits and annual FISMA security control assessments for DRSN sites, providing valuable insights and recommendations for improvement.
  • Provide expert advice and produce necessary artifacts to ensure ongoing compliance with NIST RMF requirements and maintain a robust security posture.
  • Ability to coordinate risk assessment and compliance activities between GRC and ISSO teams
  • Expert level knowledge of RMF process, accreditation assessments, and DISA-STIGs for both on premises and cloud environments
  • Excellent communication and briefing skills to communicate to client leadership
  • Conduct regular security risk analyses for healthcare systems to identify vulnerabilities and mitigate potential threats.
  • Ensure compliance with relevant regulations and standards to provide guidance to system owners on the selection and implementation of appropriate security controls.
  • Support vulnerability management through regular assessments and compliance reporting.
  • Experience with Tenable to request ad-hoc scans, review reports, and provide analysis to stakeholders.
  • Provide input to the design and delivery training programs to educate system owners and employees on risk management, compliance, and security best practices to foster and maintain a comprehensive and proactive security culture.

Job Requirements (Education/Skills/Experience)

  • Bachelor’s degree required
  • CISSP required.
  • 3-5 years of relevant experience.
  • Strong knowledge and understanding of HIPAA, PII, NIST, FISMA, and FedRAMP.
  • Proficiency with Nessus and Archer GRC (2 years desired).
  • Knowledge of RMF, NIST, accreditation assessments, and DISA-STIGs.
  • Excellent communication and briefing skills for client leadership.

Diné Development Corporation (DDC) is a Navajo Nation owned family of companies that delivers IT, professional, and environmental solutions to advance the missions of federal, state, and tribal government agencies. As thought leaders and innovators, our team of specialists build client-centric solutions that solve critical challenges faced by defense, civilian, and healthcare organizations. Employing a mission-focused approach, we deliver value that not only enhances current operations, but also drives future change. Closely aligned with this approach is our commitment to advancing the Navajo Nation and its People. Through economic development and community empowerment, we elevate the Navajo Nation to provide lasting impact and sustainable growth for future generations. DDC’s ability to unite legacy-inspired technologies, industry best practices, and proven methodologies has contributed to our success for twenty years.

This contractor and subcontractor shall abide by the requirements of 41 CFR 60-1.4(a), 60-300.5(a) and 60-741.5(a). These regulations prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities, and prohibit discrimination against all individuals based on their race, color, religion, sex, sexual orientation, gender identity, national origin, or for inquiring about, discussing, or disclosing information about compensation, or any other basis prohibited by law. We participate in E-Verify.

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Information Systems Security Engineer?

Sign up to receive alerts about other jobs on the Information Systems Security Engineer career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$164,835 - $201,088
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Diné Development Corporation

Diné Development Corporation
Hired Organization Address Dayton, OH Full Time
DDC IT Services is seeking a talented Application Engineer to join our team. Provide application and client support to A...
Diné Development Corporation
Hired Organization Address Fort Meade, MD Full Time
The Cybersecurity Professional (Level 3 )will support the Secure Cloud Computing Architecture (SCCA) Program Management ...
Diné Development Corporation
Hired Organization Address Fort Meade, MD Full Time
The Cybersecurity Systems Engineer (Level 3) will support the Secure Cloud Computing Architecture (SCCA) Program Managem...
Diné Development Corporation
Hired Organization Address Fort Meade, MD Full Time
The Cloud Architect (Level 3) will serve as a key contributor to the Engineering Future Operations team within the Secur...

Not the job you're looking for? Here are some other Information Systems Security Engineer jobs in the Rockville, MD area that may be a better fit.

Cyber Security Systems Engineer - Expert

iNovex Information Systems, Herndon, VA

Information Systems Security Engineer

The Intelligence & Security Academy, Arlington, VA

AI Assistant is available now!

Feel free to start your new journey!