About The Position

The Information Systems Security Engineer (ISSE) provides critical cybersecurity engineering and Risk Management Framework (RMF) execution services for the Naval Facilities Engineering Systems Command (NAVFAC) Marianas CIO. Operating in a specialized Operational Technology (OT) and Facility-Related Control Systems (FRCS) environment, the ISSE plays an essential role in driving end-to-end RMF lifecycles, maintaining Authorities to Operate (ATOs), managing vulnerabilities, and safeguarding mission-critical physical infrastructure networks across military installations in Guam.

Requirements

  • Active Tier 5 (T5) Top Secret security clearance
  • Must be a United States citizen.
  • Recommended minimum of 5 years of hands-on Risk Management Framework (RMF) experience.
  • Minimum of 1 year of specialized experience working on Facility-Related Control Systems (FRCS) performing RMF and cybersecurity engineering tasks.
  • Demonstrated ability to operate independently with minimal government supervision.
  • A formal college degree
  • DoD Cyberspace Workforce (CWF) Certification (DoDM 8140.03 WRC 461)
  • Must possess at least one (1) active baseline commercial certification satisfying Work Role Code 461 (Systems Security Analyst) prior to onboarding: Intermediate Level (Minimum): Security+, CCSP, Cloud+, GICSP, GISF, or GSEC. Advanced Level (Automatically Qualifies): CISSP-ISSEP, CYSA+, RCCE Level 1, CISSO, FITSP-O, GCLD, GCSA, or GSNA.
  • Complete a minimum of 20 hours annually of Continuous Professional Development (CPD) to keep credentials active.
  • eMASS, VRAM, eMASSter, Maximo, eProjects.
  • ACAS (Nessus), SCAP Compliant Scanners, Evaluate STIG, .ckl/.cklb STIG Viewer checklists.
  • NIST SP 800-53 control families, NIST SP 800-82 (ICS/OT), DoN/NAVFAC Echelon II business rules, SRGs/STIGs.
  • Capable of physical exertion typical of industrial and FRCS sites: long periods of standing, walking over rough/uneven surfaces, bending, crouching, climbing ladders, and lifting IT equipment up to 25 lbs.
  • Must maintain a Privately Owned Vehicle (POV) or company vehicle for required local commuting between sites across Guam (expenses are non-reimbursable as a cost of doing business).

Responsibilities

  • Drive end-to-end Risk Management Framework (RMF) lifecycle execution (Steps 1–6) in strict alignment with DoN and NAVFAC Echelon II directives.
  • Format, verify, and upload system inventories, security controls, and compliance artifacts into the Enterprise Mission Assurance Support Service (eMASS).
  • Facilitate annual security reviews and author Memorandums for Record (MFRs) for system baseline modifications to attain and maintain Authorities to Operate (ATOs) for FRCS assets.
  • Develop and execute an overarching Vulnerability Management Strategy tailored to the FRCS operational environment.
  • Conduct automated scanning and compliance checks using DoN-approved tools (e.g., ACAS/Nessus, SCAP, Evaluate STIG).
  • Perform manual STIG and Security Requirements Guide (SRG) validations (.ckl / .cklb files), generate Security Center and eMASSter reports, and upload scan results to the Vulnerability Remediation Asset Management (VRAM) database.
  • Sustain System-Level Continuous Monitoring (SLCM) by analyzing audit logs, driving vulnerability mitigations, and updating quarterly Plan of Action and Milestones (POA&M) reports.
  • Serve as a technical representative and Configuration Management (CM) Officer on the Configuration Control Board (CCB), providing authoritative security impact analyses and risk assessments.
  • Provide on-site technical testing and validation support to satisfy RMF Step 4 requirements in coordination with independent validators.
  • Serve as an operational member of the MAR Cyber Emergency Response Team (CERT), participating in on-call rotation schedules and authoring After-Action Incident Response (IR) reports.
  • Provide bi-weekly RMF progress reports to the Information Systems Security Manager (ISSM) and update FRCS project records in Maximo and/or eProjects.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service