Information Systems Security Engineer

Booz Allen HamiltonSpringfield, VA
$99,000 - $225,000Remote

About The Position

Security is most effective when it is part of system design from the beginning. As an Information Systems Security Engineer, you’ll help design, implement, and assess security controls that protect cloud-hosted information systems throughout their lifecycle. In this role, you’ll work across cloud architecture, cybersecurity, Risk Management Framework, assessment and authorization, and operational readiness. You’ll help translate system requirements, architectures, data flows, and mission needs into practical security designs and controls that can be implemented, tested, documented, and sustained. You’ll collaborate with cloud, network, application, database, cybersecurity, and customer stakeholders to identify risks, strengthen security protections, and support informed authorization decisions. If you’re motivated by solving complex security challenges and helping teams deliver systems that are both capable and trusted, we invite you to join us.

Requirements

  • 8+ years of experience in information systems security engineering, cloud security, or cybersecurity
  • Experience engineering, implementing, and assessing security controls for cloud-hosted information systems in accordance with RMF, ICD 503, NIST guidance, and assessment and authorization processes
  • Experience securing cloud environments across identity, network, compute, storage, database, logging, monitoring, encryption, secrets management, and privileged-access capabilities
  • Experience translating security requirements, system architectures, data flows, and mission use cases into implementable technical controls and documented security designs
  • Experience developing and maintaining A&A artifacts, including system security plans, control implementation statements, security assessment plans, POA&Ms, continuous-monitoring plans, and evidence packages
  • Experience applying Zero Trust, least privilege, defense in depth, segmentation, encryption, auditability, and secure configuration practices
  • Experience performing security engineering across the system lifecycle
  • Ability to assess control effectiveness, identify security gaps and residual risk, recommend remediation, and track corrective actions to closure
  • TS/SCI clearance; willingness to take a polygraph exam
  • Bachelor’s degree

Nice To Haves

  • Experience supporting classified, Government, or highly regulated information systems
  • Experience with vulnerability management, configuration compliance, SIEM, SOAR, endpoint security, or cloud security posture management tools
  • Experience with infrastructure as code and automated security configuration using Terraform, OCI Resource Manager, Ansible, APIs, or scripting
  • Experience supporting authorization packages, control validation, audit readiness, remediation tracking, or continuous monitoring in an agency environment
  • Possession of strong written and verbal communication skills
  • Associate or Professional level security, architecture, networking, or cloud operations Certification

Responsibilities

  • Engineer, implement, and assess security controls for cloud-hosted information systems in accordance with RMF, ICD 503, NIST guidance, and assessment and authorization requirements.
  • Translate security requirements, system architectures, data flows, and mission use cases into implementable technical controls and documented security designs.
  • Develop and maintain A&A artifacts, including system security plans, control implementation statements, architecture diagrams, security assessment plans and procedures, POA&Ms, continuous-monitoring plans, and evidence packages.
  • Assess control implementation and effectiveness, identify security gaps and residual risk, recommend remediation, and track corrective actions to closure.
  • Apply Zero Trust, least privilege, defense in depth, segmentation, encryption, auditability, and secure configuration practices.
  • Perform security engineering across requirements analysis, architecture reviews, implementation oversight, vulnerability remediation, testing, deployment, and operational transition.
  • Support security assessments, authorization decisions, control validation, audit readiness, and continuous-monitoring activities.
  • Communicate security risks, decisions, compliance status, remediation plans, and technical recommendations to program stakeholders.

Benefits

  • health
  • life
  • disability
  • financial
  • retirement benefits
  • paid leave
  • professional development
  • tuition assistance
  • work-life programs
  • dependent care
  • recognition awards program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service