Senior Information Security Engineer

ASRC Federal - Reston, VA

Hiring: Senior Information Security Engineer Company: ASRC Federal Location: Reston, VA Job Posted Time: 2026-09-11 12:12:01 Employment Type: Remote Target Skills & Keywords : Configuration Management, Risk Management About the job Experience: •7 years of experience supporting information assurance, cybersecurity, RMF, or information system security, or an equivalent combination of education and experience. Required Skills: •Serve as the primary cybersecurity and privacy advisor to System Owners for assigned systems. •Lead RMF activities, including development and maintenance of System Security and Privacy Plans (SSPPs), authorization packages, risk documentation, and supporting artifacts. •Ensure systems maintain Authorization to Operate (ATO) through assessment support, continuous monitoring, and compliance with NIST RMF, FISMA, and federal security requirements. •Assess security risks, validate security controls, and coordinate remediation of vulnerabilities and Plans of Action and Milestones (POA&Ms). •Maintain system inventories, security documentation, contingency plans, configuration management plans, and privacy documentation. •Partner cross-functionally with ISSMs, System Owners, Security Control Assessors, and technical teams to integrate security throughout the system lifecycle. •Monitor system security posture, review vulnerability and compliance scan results, and support continuous authorization initiatives. •Provide cybersecurity guidance, develop security policies and procedures, and deliver security awareness training. Qualifications: •Bachelor's degree in Cybersecurity, Information Assurance, Computer Science, Information Technology, or a related field. •Minimum 5–7 years of experience supporting information assurance, cybersecurity, RMF, or information system security, or an equivalent combination of education and experience. •Strong knowledge of NIST SP 800-37, NIST SP 800-53, FISMA, FIPS 199, and federal privacy requirements. •Strong analytical, communication, documentation, and stakeholder engagement skills. •Certified Information Systems Security Professional (CISSP) •Certified in Governance, Risk and Compliance (CGRC) or Certified Cloud Security Professional (CCSP) •Operational familiarity with cloud security, DevSecOps, and continuous authorization initiatives. •Knowledge of privacy compliance activities, including Privacy Threshold Assessments (PTAs), Privacy Impact Assessments (PIAs), and System of Records Notices (SORNs). •We invest in the lives of our employees, both in and out of the workplace, by providing competitive pay and benefits packages. Benefits offered may include health care, dental, vision, life insurance; 401(k); education assistance; paid time off including PTO, holidays, and any other paid leave required by law. Compensation: •Flexible work environment (work from home / hybrid options) •Federal civilian agencies, preferably the USPTO Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!