InfoSec Engineer, Journeyman

MAG AerospaceAberdeen Proving Ground, MD

About The Position

The INFOSEC Engineer plays a critical role in safeguarding and maintaining the cybersecurity posture of information systems that support mission‑essential operations. This position assists the Information System Security Manager (ISSM) in executing comprehensive information assurance and cybersecurity activities in alignment with the Risk Management Framework (RMF). The INFOSEC Engineer will support security authorization efforts, continuous monitoring, vulnerability analysis, configuration management, and incident response coordination. The ideal candidate combines strong technical expertise with a thorough understanding of cybersecurity policies, principles, and procedures to ensure the protection, integrity, and compliance of classified and unclassified systems. This role requires proactive engagement with government stakeholders, meticulous documentation practices, and the ability to identify and mitigate evolving cyber threats within complex system environments.

Requirements

  • Must hold active Security+, CISSP, CISA, or equivalent certifications (DoD 8570 IAM 2 equivalent)
  • A minimum of 5 years of experience as an IA/Security Specialist and OMB Information Security directives/policy compliance
  • At least 3 years of direct experience and in-depth working knowledge of FISMA and NIST Information Security Guides
  • Advanced written and verbal communication skills

Nice To Haves

  • 10 years of experience as an IA/Security Specialist and OMB Information Security directives/policy compliance
  • Experience with effective policy, instruction, and development for Federal or DoD Information Security Programs
  • Experience with performing Security Control Assessment in compliance with NIST SP 800- 37, NIST SP 800-53, NIST SP 800-53A, and other NIST 800 guides
  • Experience with risk analysis and assessment determinations
  • Experience with eMASS
  • Experience with Xacta
  • Current CI polygraph

Responsibilities

  • Perform tasks delegated by the ISSM in support of various information assurance /cybersecurity programs such as security authorization activities in compliance with Risk Management Framework (RMF) policies and procedures including System Security Plans (SSPs), Risk Assessment Reports, A&A packages, and Security Controls Traceability Matrix (SCTM)
  • Maintains operational security posture to ensure information systems (IS), security policies, standards, and procedures are established and followed
  • Performs vulnerability/risk assessment analysis to support Assessment & Authorization (A&A)
  • Review and analyze system audit logs to identify anomalous activity and potential threats to network resources
  • Conducting vulnerability scans and recognizing vulnerabilities in security systems
  • Ensure that cybersecurity-enabled products or other compensating security control technologies reduce identified risk to acceptable security levels
  • Apply a full range of Cybersecurity policies, principles, and techniques to maintain the security integrity of information systems processing classified information
  • Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk
  • Work with government customers to support computer security incidents and vulnerability compliance
  • Input and maintain system documentation into government record-keeping systems like Xacta and eMASS
  • Provide Configuration Management for security-relevant information system software, hardware, and firmware
  • Perform risk analysis whenever an application or system undergoes a major change
  • Provide input to the Risk Management Framework process activities and related documentation

Benefits

  • health
  • life
  • disability
  • financial
  • retirement benefits
  • paid leave
  • professional development
  • tuition assistance
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service