Agile Defense
Information Systems Security Engineer - SME
About this role
Senior security engineering role leading the Department of Justice's Security Assessment and Authorization program. The ISSE-SME provides expert technical guidance on NIST Risk Management Framework implementation, security control design, system authorization, and continuous monitoring across complex federal IT environments.
What you'll do
- Lead RMF lifecycle execution and mentor security professionals through SAA program implementation
- Direct system categorization and security control selection aligned with DOJ risk tolerance and compliance
- Oversee technical, operational, and management control implementation across system lifecycles
- Plan and validate comprehensive security control assessments for system authorization decisions
- Manage continuous monitoring activities and risk posture reporting to leadership
- Provide subject-matter expertise on cybersecurity risks, incident response, and audit support
What they're looking for
- NIST Risk Management Framework (RMF) and FISMA
- Federal security authorization processes and DOJ policy
- Security engineering and control architecture design
- Enterprise IT systems security across multiple lifecycle stages
- Risk-based decision making and executive advisory
- Continuous monitoring and compliance assessment
- Cybersecurity incident response and vulnerability remediation
- Leadership and technical mentoring
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Agile Defense
Agile Defense builds innovative technology solutions and infrastructure systems supporting critical national defense missions. The company is hiring DevOps engineers, data engineers, web developers, and systems engineers who work with advanced technologies and agile methodologies to deliver secure, scalable defense applications.
View all jobs at Agile DefenseLikely interview questions
- Walk us through your experience leading a complete RMF lifecycle for a complex federal IT system—what were the biggest challenges in the Prepare phase, and how did you ensure consistent execution across multiple teams?
- Describe your approach to system categorization under FISMA. How do you balance mission impact, data sensitivity, and regulatory requirements when advising leadership on risk tolerance?