Haystack
← Back to Jobs
Technology

Information Systems Security Engineer (ISSE) / Systems Security Analyst

Softthink Solutions, Inc.Sånta Rita-Sumai🇺🇸United StatesPosted 11 Aug 2026

Quick Overview

Work Type
On Site
Level
Mid Senior

Job Description

Information Systems Security Engineer (ISSE) / Systems Security Analyst

Location: Santa Rita, Guam

Travel: Local travel between Naval Base Guam, Camp Blaz, and Andersen Air Force Base

Position Overview

We are seeking an experienced Information Systems Security Engineer (ISSE) / Systems Security Analyst to support cybersecurity and Risk Management Framework (RMF) activities for Facility-Related Control Systems (FRCS) in a U.S. Navy environment.

The selected candidate will support the complete RMF lifecycle, Authority to Operate (ATO) activities, vulnerability and compliance assessments, continuous monitoring, incident response, security documentation, and cybersecurity reporting.

Key Responsibilities

  • Lead and execute the complete RMF lifecycle (Steps 1 6) in accordance with Department of the Navy and NAVFAC requirements.
  • Develop, review, validate, format, and upload RMF security artifacts into eMASS.
  • Support the attainment, maintenance, and tracking of Authority to Operate (ATO) for FRCS.
  • Conduct annual security reviews and prepare Memorandums for Record (MFRs).
  • Develop and maintain security policies, SOPs, implementation plans, and RMF documentation.
  • Map security requirements to applicable NIST SP 800-53 controls.
  • Perform vulnerability and compliance assessments using ACAS/Nessus, SCAP, Evaluate STIG, and manual STIG/SRG checklists.
  • Generate security and vulnerability reports and maintain POA&M records.
  • Perform continuous monitoring, vulnerability scanning, audit-log review, remediation tracking, and quarterly POA&M updates.
  • Support RMF Step 4 validation and testing by coordinating with system owners and independent validators.
  • Conduct security impact analyses and risk assessments for proposed system or baseline changes.
  • Support Configuration Control Board (CCB) activities.
  • Participate in the MAR Cyber Emergency Response Team (CERT) on-call rotation.
  • Support cybersecurity incident response, remediation, operational logging, and after-action reporting.
  • Prepare bi-weekly RMF status reports and monthly cybersecurity/program status reports.
  • Maintain applicable records in Maximo and/or eProjects.

Required Qualifications

  • U.S. citizenship required.
  • Active Tier 5 (T5) security clearance, or ability to obtain the T5 clearance before onboarding.
  • Foundational qualifications for DoDM 8140.03 Work Role 461 Systems Security Analyst at the intermediate or advanced proficiency level.
  • At least one approved DoDM 8140.03 qualifying certification.
  • Recommended 5+ years of RMF experience.
  • At least 1 year of specialized FRCS cybersecurity engineering/RMF experience.
  • Demonstrated ability to work independently with minimal government supervision.
  • Strong written and verbal communication skills.
  • Ability to prepare technical reports, security policies, procedures, risk assessments, and RMF documentation.
  • Ability to collaborate with government personnel, system owners, validators, technical teams, and ISSM personnel.
  • Ability to work 100% onsite in Guam.
  • Ability to participate in an incident-response on-call rotation.
  • Ability to travel locally between required military installations.
  • Ability to use a privately owned or company vehicle for required local travel.

Preferred Technical Experience

Experience with one or more of the following is highly desirable:

  • eMASS
  • VRAM
  • ACAS/Nessus
  • SCAP
  • Evaluate STIG
  • eMASSter
  • Security Center
  • Maximo
  • eProjects
  • NIST SP 800-53 controls
  • Department of Defense/Navy RMF processes
  • ATO packages
  • Security Control Assessments
  • POA&M management
  • Facility-Related Control Systems (FRCS)
  • Operational Technology (OT)
  • Industrial Control Systems (ICS)
  • Building Control Systems
  • Vulnerability remediation
  • Incident response
  • Security/log analysis
  • Configuration management
  • Change-control risk assessments
  • Configuration Control Board support

Approved Certifications

Intermediate level:

  • CCSP
  • Cloud+
  • GICSP
  • GISF
  • GSEC
  • Security+

Advanced level:

  • RCCE Level 1
  • CISSO
  • CISSP-ISSEP
  • CySA+
  • FITSP-O
  • GCLD
  • GCSA
  • GSNA

 

Similar jobs