Centuria
Information System Security Engineer III
About this role
Centuria seeks an experienced Information System Security Engineer III to manage Risk Management Framework processes, security controls, and compliance for federal IT systems in Philadelphia. This role involves vulnerability assessments, STIG implementation, patch management, and continuous monitoring to maintain authorization and operational security across enterprise networks.
What you'll do
- Develop and maintain RMF security plans, including system categorization, implementation plans, and continuous monitoring strategies
- Execute RMF processes to obtain and maintain IATT, ATO, and related authorizations
- Perform vulnerability assessments using automated tools like ACAS and SCAP, and conduct security control testing
- Identify, mitigate, and remediate system vulnerabilities per STIG requirements and manage POA&Ms in eMASS
- Deploy security patches and updates in response to DoD/DoN directives and manage configuration changes
- Conduct routine audits of IT hardware and software, maintain system inventories, and support cyber compliance across Windows and CISCO infrastructure
What they're looking for
- Risk Management Framework (RMF) processes
- Vulnerability assessment and remediation
- STIG and SRG implementation and assessment
- Security control testing and evaluation
- Patch and configuration management
- Windows Server and CISCO networking administration
- eMASS and VRAM systems
- IT compliance and continuous monitoring
Opens the application — the Jobs AI extension fills it for you. Set up autofill
Opens the official application on the employer’s site. No login required.
Centuria
Centuria provides engineering support and technical infrastructure services for mission-critical federal and government systems, including weather operations and IT security frameworks. The company is hiring for systems engineers, security engineers, and DevOps/infrastructure automation specialists to manage complex infrastructure, maintain compliance, and optimize deployment pipelines.
View all jobs at CenturiaLikely interview questions
- Walk us through your experience with the Risk Management Framework (RMF) process—specifically, what's your hands-on experience obtaining and maintaining ATO/IATT authorizations?
- Describe your experience with vulnerability assessment tools like ACAS, SCAP SCC, and eMASS. How have you used these to identify and remediate vulnerabilities?