Senior Information System Security Engineer
Job description
About the role
Redhorse Corporation presents a distinct opportunity for professionals seeking to apply their expertise within a mission-focused environment dedicated to delivering data insights and technology solutions that serve U.S. national interests. This specific search is for a Senior Information System Security Engineer (ISSE) who will act as a trusted strategic partner to complex, high-stakes mission sets, building technology-agnostic solutions that ensure operational continuity. The individual in this role will serve as the primary guardian of Information Assurance (IA) principles, responsible for bridging intricate technical specifications with the realities of business operations to maintain system integrity. You will ensure that innovation progresses in lockstep with robust security, strict compliance, and unwavering system resiliency, directly impacting the security posture of systems managing sensitive government data. This position demands a professional who thrives on securing the nation's most critical network and information systems through meticulous analysis and forward-thinking design. You will translate abstract policy language into concrete, executable technical controls that define the security perimeter before any configuration occurs. Success in this role requires the ability to operate effectively at the intersection of technology, process, and governance, ensuring that security is embedded into the fabric of every system lifecycle.
Key facts
What you'll do
- Conduct comprehensive intake procedures to accurately define security perimeters and trust boundaries prior to system initialization or modification.
- Establish definitive build standards and security baselines that translate high-level policy requirements into specific, measurable technical controls.
- Perform exhaustive reviews of existing access controls to validate the effectiveness of authentication and authorization mechanisms across the entire infrastructure.
- Coordinate deployment activities with precision, ensuring that system updates and patches uphold integrity and availability without interrupting essential mission services.
- Map complex partner requirements against existing infrastructure limitations to identify gaps and document risk acceptance decisions with clarity and precision.
- Evaluate and analyze monitoring tools specifically designed to scrutinize traffic patterns and identify sophisticated anomalies across logically segmented network environments.
- Execute systematic validation routines to confirm that all system configurations adhere strictly to established security baselines and hardening guides.
- Maintain comprehensive, auditable documentation of all security-related decisions, creating a clear lineage that influences long-term system resilience and future modification pathways.
- Interpret detailed architecture diagrams to identify potential vulnerabilities, trust boundaries, and data flow risks that may not be immediately apparent.
- Demonstrate knowledge of security guidance application throughout every phase of the system development lifecycle, from initial design through deployment and maintenance.
- Ensure continuous alignment with security frameworks by translating Risk Management Framework (RMF) steps into actionable, operational practices that mitigate emerging threats.
- Leverage a minimum of three years of hands-on technical security experience to proactively identify weaknesses and recommend robust remediation strategies.
- Exhibit proficiency when working directly with network components, operating systems, and application settings to implement security controls effectively.
- Act as a subject matter expert, providing technical leadership and guidance to cross-functional teams on matters of information assurance and compliance.
- Collaborate closely with engineering and operations teams to integrate security seamlessly into workflows without sacrificing efficiency or functionality.
Requirements
- Possess a baseline clearance suitable for accessing sensitive national security information, which is non-negotiable for this role.
- Demonstrate a deep, operational understanding of the Risk Management Framework steps, including implementation and validation of controls.
- Capability to interpret complex architecture diagrams to identify trust boundaries, data flows, and potential vulnerabilities within the infrastructure.
- Knowledge of security guidance application throughout the entire system development lifecycle, including initiation, development, implementation, and disposal stages.
- Minimum of three years of hands-on experience performing technical security tasks within a government or high-security environment.
- Proficiency working directly with network components such as routers, firewalls, and switches to enforce security policies.
- Expertise in configuring and managing operating systems to meet stringent security baselines and compliance standards.
- Ability to manipulate application settings to enforce security protocols, authentication, and data protection mechanisms.
- These qualifications form the absolute baseline for consideration; any deviation will result in immediate disqualification.
- The role requires a meticulous attention to detail and the ability to manage multiple priorities in a fast-paced, high-responsibility environment.
- Candidates must be capable of documenting technical processes clearly and concisely for audit and review purposes.
- A proven track record of maintaining system integrity while supporting evolving mission requirements is essential.
- The professional must be able to work independently with minimal supervision, exercising sound judgment in security-related decisions.
- Understanding of federal information security mandates and compliance regulations is mandatory for success in this position.