Sr Systems Security Engineer

Sierra Nevada CorporationLone Tree, CO
$143,487 - $197,295Hybrid

About The Position

The Senior Systems Security Engineer / Information System Security Manager (ISSM) is a dual-mode technical SME and program security lead responsible for the end-to-end cybersecurity posture, compliance governance, and system accreditation of information systems within a complex defense program environment. This role combines active hands-on-keyboard technical security execution — vulnerability scanning, SIEM operations, STIG hardening, and system monitoring — with senior leadership accountability for ISSO team development, ATO lifecycle management, DCSA/DoW/IC compliance framework implementation, and direct representation of program security posture to government stakeholders and Authorizing Officials. The Senior Systems Security Engineer / ISSM operates with authority across both the technical and governance dimensions of information security. On the technical side, they execute and oversee vulnerability management, security monitoring, configuration hardening, and incident response with hands-on proficiency. On the governance and leadership side, they own the program's RMF/ATO strategy, develop and enforce the security policies and procedures that govern the program environment, train and mentor ISSOs/ISSEs, coordinate with DCSA/DOW/IC and government stakeholders, and brief program security status at formal USG reviews. Neither dimension is optional — this role demands both simultaneously.

Requirements

  • Bachelor's degree in Systems Security, Network Engineering, Information Technology, or related Engineering discipline.
  • 8+ years of experience in IT security or a related field.
  • Relevant experience can be considered as a substitute for the required educational qualifications. In the absence of a degree, a minimum of 16 years of related experience is required.
  • Higher level relevant degree may substitute for experience.
  • A minimum of 8 years in a formal ISSM role with direct ATO package ownership and government AO interface responsibility.
  • Deep expertise in cybersecurity principles and practices.
  • Experience with security frameworks and standards such as National Institute of Standards and Technology (NIST), ISO 27001.
  • Demonstrated experience to describe configuring scan policies, executing credentialed scans, interpreting results, and building Tenable dashboards from personal execution, not oversight.
  • Demonstrated hands-on Splunk SIEM experience — developing correlation searches, dashboards, and security use cases; triaging SIEM alerts; and managing Splunk forwarder deployments.
  • Active DISA STIG application experience — must have personally applied STIGs to live systems, not just reviewed or documented STIG compliance. Ability to describe specific STIG finding categories, compensating control documentation, and POA&M management.
  • Demonstrated experience presenting security posture to government stakeholders — has personally briefed at government security reviews, ARBs, or AO-level meetings. Not supported a presenter — led the brief.
  • Deep working knowledge of NIST 800-53 Rev 5 — can explain control families, tailoring rationale, control inheritance, and assessment procedures without reference material.
  • Demonstrated RMF/ATO lifecycle ownership — has personally developed SSPs, SARs, POA&Ms, and security assessment evidence packages and presented them to a government AO for authorization decision.
  • Working knowledge of DCSA DAAG requirements for classified IS accreditation — has operated within a DCSA-governed program environment and coordinated with DCSA field representatives.
  • Working knowledge of CMMC framework — understands Level 2/3 practice domains, assessment objectives, and CUI protection requirements.
  • Has authored or substantially contributed to PPSM documentation — understands port/protocol justification requirements, DoD PPSM registry process, and PPSM enforcement mechanisms.
  • Demonstrate hands on proficiency on the following areas: Nessus / Tenable.sc, Tenable Dashboard Creation ELK Stack (Elastic/Kibana), Splunk SIEM, DISA STIGs / SRGs, eMASS / XACTA, RHEL / Linux, vSphere/VMware, GitLab / GitHub, Bash Scripting, CPU / System Architecture, PKI / Certificate Mgmt, NIST 800-53 Rev 5, RMF / ATO Process, DCSA DAAPM, CMMC Level 2/3, TEMPEST Requirements, PPSM Creation
  • Current/Active Top Secret U.S. Security Clearance with SCI eligibility is required.
  • U.S. Citizenship status is required as this position needs an active U.S. Security Clearance for employment.

Nice To Haves

  • CISSP (Certified Information Systems Security Professional) — active certification preferred. CISM, CASP+, or equivalent senior-level security certification.
  • IAM Level III or IAT Level III baseline certification required per DoD 8570/8140.
  • GitLab Certified Associate or GitHub Advanced Security certification.
  • Red Hat Certified System Administrator (RHCSA) or equivalent Linux administration certification.
  • Experience with Tenable Security Center (SC) enterprise deployment — multi-scanner architecture, repository management, and organizational reporting hierarchy configuration.
  • Familiarity with cross-domain solutions (CDS) and data transfer guard administration in classified multi-domain environments.
  • Experience with Zero Trust architecture implementation — network segmentation, identity-based access enforcement, and micro-segmentation concepts applied in a DoD program context.
  • Proficient in IT project management practices with a solid understanding of PMI/PMP frameworks, including planning, monitoring, controlling, and risk management.
  • Working knowledge of JIRA to manage and track Earned Value tasks, including schedule performance, cost performance, and workflow status.
  • Experience managing multidisciplinary RMF teams and executing security assessments in accordance with DoDI 8510.01, NIST SP 800‑53A, CNSSI 1253, and program‑level authorization processes.

Responsibilities

  • Lead the design and implementation of security infrastructure.
  • Manage complex security projects.
  • Provide strategic direction for security practices.
  • Mentor junior engineers.
  • End-to-end cybersecurity posture, compliance governance, and system accreditation of information systems.
  • Vulnerability scanning, SIEM operations, STIG hardening, and system monitoring.
  • ISSO team development, ATO lifecycle management, DCSA/DoW/IC compliance framework implementation.
  • Direct representation of program security posture to government stakeholders and Authorizing Officials.
  • Execute and oversee vulnerability management, security monitoring, configuration hardening, and incident response with hands-on proficiency.
  • Own the program's RMF/ATO strategy.
  • Develop and enforce security policies and procedures.
  • Train and mentor ISSOs/ISSEs.
  • Coordinate with DCSA/DOW/IC and government stakeholders.
  • Brief program security status at formal USG reviews.

Benefits

  • medical
  • dental
  • vision plans
  • 401(k) with 150% match up to 6%
  • life insurance
  • 3 weeks paid time off
  • tuition reimbursement
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service