Systems Engineer

Entegrasystems•Laurel, MD

About The Position

Responsible for the research, development, implementation, testing and review of an organization’s information security to protect information and prevent unauthorized access. Ensure systems are operated, maintained, and disposed of in accordance with internal security policies and practices outlined in the security plan. Ensures that the appropriate operational security posture is maintained in accordance with government Risk Management Framework (RMF). Responsible for day-to-day security operations of systems including Security Control Validation Visits, Secure Configuration and Change Management, Event Management, Account Management, Vulnerability Management, Security Incident Management, POA&M Management, Reauthorization and Decommissioning. Ensure that all users have authorization and the need-to-know to access specific Information Systems. Report all security-related incidents to the Information Systems Security Manager (ISSM). Initiate, with the approval of the ISSM, protective or corrective measures when a security incident or vulnerability is discovered. Develop and maintain 5+ System Security Plans (SSP); Manage and control changes to systems and assessing the security impacts of those changes; and ensure that self-testing is completed throughout the RMF process. Monitor security systems for and ensure compliance with the SSP. Ensure that system recovery processes are monitored to ensure that security features and procedures are properly restored. Ensure all Information System security-related documentation is current. Notify the ISSM and Authorizing Official when changes occur that might affect accreditation. Ensure that system security requirements are addressed during all phases of the system life cycle. Follow procedures developed by the ISSM, authorizing software, hardware, and firmware use before implementation on the system. Notify the ISSM and Authorizing Official when a system no longer processes intelligence or Special Access Program (SAP) information.

Requirements

  • B.S., degree in a Qualified Engineering Field plus fifteen (15) years of systems engineering experience.
  • M.S., degree in a Qualified Engineering Field or a related discipline from an accredited college or university plus thirteen (13) years of systems engineering experience.
  • A PhD in a Qualified Engineering Field or a related discipline from an accredited college or university plus thirteen (13) years of systems engineering experience.
  • A High School Diploma or GED plus nineteen (19) years of general system engineering experience.
  • Demonstrated experience with tools, practices and policies used in the Risk Management Framework (RMF).
  • Experience with submitting, tracking & closing Computer Security Incident Reports (CSIR).
  • Experience with Password Management Software.
  • Experience with writing, tracking and closing Plan Of Actions & Milestones (POA&Ms).
  • Experience with centralized audit logging management and how to review logs for vulnerabilities.
  • Experience with monitoring, tracking and closing IAVAs.
  • Experience with the Secure the Enterprise (STE) requirements.
  • Ability to work independently and also collaborating with application developers, engineers and others.
  • Must be motivated and results oriented.
  • Effective written and oral communication skills.

Nice To Haves

  • CISSP Certification highly preferred.

Responsibilities

  • Research, development, implementation, testing and review of an organization’s information security to protect information and prevent unauthorized access.
  • Ensure systems are operated, maintained, and disposed of in accordance with internal security policies and practices outlined in the security plan.
  • Ensure that the appropriate operational security posture is maintained in accordance with government Risk Management Framework (RMF).
  • Day-to-day security operations of systems including Security Control Validation Visits, Secure Configuration and Change Management, Event Management, Account Management, Vulnerability Management, Security Incident Management, POA&M Management, Reauthorization and Decommissioning.
  • Ensure that all users have authorization and the need-to-know to access specific Information Systems.
  • Report all security-related incidents to the Information Systems Security Manager (ISSM).
  • Initiate, with the approval of the ISSM, protective or corrective measures when a security incident or vulnerability is discovered.
  • Develop and maintain 5+ System Security Plans (SSP).
  • Manage and control changes to systems and assessing the security impacts of those changes.
  • Ensure that self-testing is completed throughout the RMF process.
  • Monitor security systems for and ensure compliance with the SSP.
  • Ensure that system recovery processes are monitored to ensure that security features and procedures are properly restored.
  • Ensure all Information System security-related documentation is current.
  • Notify the ISSM and Authorizing Official when changes occur that might affect accreditation.
  • Ensure that system security requirements are addressed during all phases of the system life cycle.
  • Follow procedures developed by the ISSM, authorizing software, hardware, and firmware use before implementation on the system.
  • Notify the ISSM and Authorizing Official when a system no longer processes intelligence or Special Access Program (SAP) information.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service