Information Security Systems Engineer (ISSE)
@ Accenture Federal ServicesInformation Security Systems Engineer (ISSE)
About the job
Accenture Federal Services supports US federal agencies, offering innovative tech solutions. The ISSE role focuses on security risk management, compliance, and collaboration with technical teams to enhance cybersecurity and safeguard critical systems.
Requirements
- 2-5 years configuring security systems
- Experience with risk management activities
- Knowledge of NIST frameworks
- Strong problem-solving skills
- Experience with vulnerability assessments
Qualifications
- Bachelor’s degree or equivalent
- Ability to communicate technical info
- Experience with A&A processes
- Understanding of SDLC
- Collaborative team player
Full job description
AFS is seeking a highly motivated, Mid-level Information System Security Engineer (ISSE) this role works with the portfolio they are tied to and internal CISO organization, this role is pivotal in bridging the gap between business objectives and cybersecurity strategies. The primary responsibility will be to collaborate with various teams in the organization to ensure the seamless integration of security practices into business operations (i.e. portfolios). The ideal candidate will have working knowledge of various NIST guidance and frameworks such as NIST’s Risk Management Framework (RMF), and NIST SP 800-171.
The work
To excel in this role, you will need a strong foundation in risk management and problem-solving, as these skills will be critical in identifying vulnerabilities and implementing effective countermeasures that project teams can use to supplement their security knowledge. Familiarity with tools and processes related to threat detection, vulnerability assessments, and supply chain risk management will be highly advantageous. Additionally, experience working in cross-functional teams and collaborating with technical experts in security engineering and architecture will help you navigate the complexities of this role. Your ability to communicate effectively with both technical and non-technical stakeholders will be essential in driving security initiatives forward and fostering a culture of cybersecurity awareness across the organization.
- Work with project teams to develop and maintain bodies of evidence (BOE) for information systems, custom application, services, and networks.
- Must be able to understand and implement Client Data Program (CDP) program with project teams
- Develop and disseminate system security policies, processes, and likewise governing products in service of maintaining a low operational risk posture.
- Work with project teams to conduct internal vulnerability assessments and facilitate external audits of security controls.
- Coordinate security-related tasks and activities across other functional areas E.g., Program Management, Engineering, Software Development, supply chain risk etc.
- Produce documentation in response to, and satisfaction of information security requirements.
- Work with project teams to develop Authorization to Operate (ATO) Packages and ATO supporting documentation. Examples are: SSPs, POA&Ms, SCTMs, Certification Test Reports, Briefings, Continuous Monitoring Plan and Training products.
- Conduct Security Impact Analyses (SIA) on System Change Requests for systems that have been authorized by CISO
- Must be able to manage multiple priorities and complex tasks in a dynamic work environment.
- Must have the ability to translate technical concepts to semi-technical clients.
What you need
- Bachelor’s degree in a related area or equivalent experience (4 years)
- 2-5 years of experience configuring and securing systems to achieve compliance with Security requirements (Controls, STIGS).
- 3+ years of experience conducting Assessment and Authorization (A&A) using Risk Management Framework (RMF) activities; across all 6 steps.
- 2-5 years expertise administering risk management in an enterprise or tactical environment.
- 5+ year’s experience and competency with the Microsoft Office Suite. E.g., Word, Excel, PowerPoint etc.
- 2+ years working with and understanding systems, and the Software Development Life Cycle (SDLC)
Bonus if you have
- Security Clearance: Active Secret
- Experience working with non-traditional IT (Example - Small, purpose-built computers and/or networked sensor equipment is a Plus)
- Cloud experience (vendor agnostic), FedRAMP knowledge
- CISSP or equivalent certification
As required by local law, Accenture Federal Services provides reasonable ranges of compensation for hired roles based on labor costs in the states of California, Colorado, Hawaii, Illinois, Maine, Maryland, Massachusetts, Minnesota, New Jersey, New York, Vermont, Virginia, Washington, and the District of Columbia, and the city of Cleveland. The base pay range for this position in these locations is shown below. Compensation for roles at Accenture Federal Services varies depending on a wide array of factors, including but not limited to office location, role, skill set, and level of experience. Accenture Federal Services offers a wide variety of benefits. You can find more information on benefits here. We accept applications on an on-going basis and there is no fixed deadline to apply.