Information System Security Engineer (ISSE)

PLEX Solutions•Annapolis Junction, MD
•Onsite

About The Position

PLEX Solutions, A Part of Markon is seeking an Information System Security Engineer in the Annapolis Junction, MD area. This role involves Security Engineering and Authorization, TECTIX Deployment, Maintenance and Sustainment, and RMF Tooling and Customer Support. The engineer will perform technical security assessments, validate system security requirements, build Information Assurance into systems, and assess and mitigate system security threats. They will also support security authorization activities in compliance with the DoD Risk Management Framework and NIST RMF process. Deployment responsibilities include installing, configuring, and validating TECTIX in various environments, provisioning supporting services, and executing installations against user guides. Maintenance involves applying platform updates, patches, and configuration changes, maintaining STIG compliance, monitoring system health, and managing vulnerability scans. Customer support includes assisting with RMF artifacts, eMASS integration, providing Tier 1 and Tier 2 support, delivering user training, and capturing enhancement requests.

Requirements

  • Active TS/SCI with a current CI polygraph.
  • Demonstrated depth in the RMF authorization lifecycle, including NIST 800-37, NIST 800-53, security control assessment, and certification and accreditation review.
  • System security engineering experience across networking, computing, and enclave environments, including environments with differing classification levels.
  • Solid IT engineering background, including Linux system administration, basic networking, and comfort operating in a command-line environment.
  • Working software aptitude sufficient to read logs, interpret configuration files, understand containerized applications, and troubleshoot deployment issues.
  • Strong customer service and communication skills, with the ability to translate between technical detail and customer stakeholders.
  • DoD 8140/8570 IAM or IAT baseline certification appropriate to the task order at time of hire (for example, Security+ at minimum).

Nice To Haves

  • CISSP, CGRC (formerly CAP), or equivalent RMF/GRC certification.
  • Hands-on experience with GRC or authorization tooling such as eMASS, Xacta, or similar.
  • AWS GovCloud experience, including ECS/Fargate, and container tooling such as Docker and Docker Compose.
  • PostgreSQL administration and general database troubleshooting.
  • STIG and SCAP experience, container hardening, and vulnerability management workflows.
  • Prior experience supporting an Intelligence Community or DoD customer in a classified environment.

Responsibilities

  • Perform and review technical security assessments of the computing environment to identify vulnerabilities and non-compliance with established Information Assurance standards, and recommend mitigation strategies.
  • Validate and verify system security requirements, and establish and maintain system security designs across networking, computing, and enclave environments, including enclaves with differing data protection and classification requirements.
  • Build Information Assurance into systems deployed to operational environments, and support the customer's security architecture and the trusted relationships among connected systems.
  • Assess and mitigate system security threats and risks throughout the program life cycle, and contribute to security planning, risk analysis, and risk management activities.
  • Support security authorization activities in compliance with the DoD Risk Management Framework and the NIST RMF process, and review certification and accreditation documentation for completeness and compliance.
  • Install, configure, and validate TECTIX in the customer environment across the supported deployment paths, including AWS GovCloud and on-premises or disconnected installations.
  • Provision and configure supporting services, including containers and required managed database resources.
  • Execute and verify installation against the user’s guide and industry best practices, and document environment-specific deviations back to the product team.
  • Apply platform updates, patches, and configuration changes on a defined cadence with minimal disruption to the customer, under disciplined configuration and change control.
  • Maintain STIG compliance for the deployment, including a workable STIG update approach for disconnected environments.
  • Monitor container, database, and application health, and remediate issues before they affect users.
  • Manage vulnerability scan results, software bill of materials (SBOM) validation, and integrity hash verification as part of ongoing security posture upkeep.
  • Support the customer's use of TECTIX to produce and maintain RMF artifacts, including System Security Plans, control implementation statements, POA&Ms, and assessment evidence.
  • Assist with eMASS integration and data flows between TECTIX and the customer's authorization tooling.
  • Provide Tier 1 and Tier 2 support to customer users, deliver user training, and maintain customer-facing operational documentation.
  • Capture enhancement requests and defects, and coordinate resolution with the TECTIX development team.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service