Quick Overview
Job Description
Job Description Everforth ECS is seeking an Information Systems Security Engineer to work in our Fort Meade, MD office. The Information Systems Security Engineer will lead security architecture hardening, vulnerability mitigation, and continuous accreditation for multi-tenant systems operating within a Combined Information Environment (CIE) and Mission Partner Environment (MPE).
In this role, you will be responsible for defining, implementing, and validating technical security controls across hybrid compute infrastructure composed of enterprise virtual machines, container orchestration clusters, and virtual desktop delivery pipelines.
You will interface directly with Five Eyes (FVEY) coalition partners, systems architects, ISSMs/ISSOs, and operational defense personnel to ensure that all data flows, boundary enforcement points, and identity federation services adhere to rigorous DoD security baselines, zero-trust principles, and Risk Management Framework (RMF) standards.
Primary Responsibilities
- Multi-Domain & Enclave Boundary Defense: Design, enforce, and audit boundary security mechanisms, network access control policies, and cross-domain controls isolating mission-specific enclaves while facilitating secure multilateral information sharing among FVEY mission partners.
- Virtualization & Hypervisor Security: Apply and validate DISA Security Technical Implementation Guides (STIGs) and hardening benchmarks across enterprise hypervisors (VMware vSphere/ESXi), virtual machines, management planes (vCenter), and software-defined storage backends.
- Linux & Endpoint System Hardening: Maintain baseline configuration compliance and host-based security across Red Hat Enterprise Linux (RHEL) server platforms, Windows infrastructure, and enterprise Virtual Desktop Infrastructure (VDI) (VMware Horizon / Citrix), mitigating vulnerabilities across shared and non-persistent virtual pools.
- Continuous Monitoring & Vulnerability Management: Execute automated vulnerability scanning (e.g., Trellix, ACAS), analyze Common Vulnerabilities and Exposures (CVEs), generate Plan of Action and Milestones (POA&Ms), and engineer automated or scripted remediation actions across VM and VDI fleets.
- Accreditation & Documentation: Translate complex infrastructure topologies and system data flows into comprehensive RMF accreditation artifacts (System Security Plans [SSPs], Security Assessment Reports [SARs], Interface Control Documents [ICDs]). Collaborate with Systems Architects to evaluate architectural models (Visio / Cameo SysML) for cybersecurity posture and zero-trust compliance.
- Other duties, as assigned. Salary 120,000-150,000
Required Skills
- U.S. Citizen.
- Active Secret security clearance.
- Bachelor's degree with 5+ years of progressive experience in cybersecurity engineering, systems security, or security architecture (Mid to Senior level). Alternatively, a Master's degree with 3+ years of experience.
- DoD 8570/8140 Baseline: Active IAT Level III or IAM Level II/III certification (e.g., CISSP, CASP+ CE, CISM, or equivalent).
- Linux & Server Security: Strong hands-on experience hardening and auditing Red Hat Enterprise Linux (RHEL) platforms via DISA STIGs, SCAP tools, OpenSCAP, and SELinux enforcement.
- Virtualization & VDI Security: Practical experience securing virtualized infrastructure (VMware ESXi, vCenter, vSAN) and enterprise VDI deployments supporting multi-classification or multi-tenant desktop access.
- Container Security Concepts: Working knowledge of securing containerized environments and Kubernetes (K8s) deployments (runtime security, image scanning, network policies, RBAC, and secrets management).
- Vulnerability Analysis: Demonstrated expertise with ACAS/Nessus, STIG Viewer, and CVE lifecycle management (triage, exploitation risk analysis, and patch remediation).
- Strong problem-solving and decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate solution.
- Highly developed interpersonal and oral/written communication skills, with the ability to effectively and professionally interact with a diverse set of stakeholders (from peers to end-users to executive management).
Desired Skills
- Prior direct security engineering experience within a Mission Partner Environment (MPE), Combined Information Environment (CIE), or coalition federation structure supporting FVEY partners.
- Experience interpreting and contributing security requirements into digital engineering and architecture tools (Microsoft Visio, Cameo Systems Modeler / SysML / UAF).
- Hands-on familiarity with Zero Trust Architecture (ZTA) implementation (NIST SP 800-207, OMB M-22-09), identity federation (SAML, OIDC), and PKI multi-realm * certificate management.
- Experience with automated configuration management and infrastructure-as-code hardening (Ansible, Terraform)
- Professional certifications:
- Systems/Virtualization: VMware Certified Professional (VCP) or VMware Certified
- Advanced Professional (VCAP). #EverforthECS1 ECS Federal LLC is an equal opportunity employer and does not discriminate or allow discrimination on the basis any characteristic protected by law. All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, or local jurisdiction law. is the federal segment of , a $4B global organization with over 10,000 employees. Our nearly 3,500 professionals deliver advanced technology solutions in data and AI, cybersecurity, and enterprise transformation, serving defense, intelligence, and federal civilian agencies. Our work powers mission-critical outcomes, strengthens technology partnerships, and creates meaningful opportunities for our people. We are defined by a commitment to excellence in delivery, a culture of innovation, and an environment where talent can thrive and grow. We value:
- Attracting and developing top talent and high-performing teams
- Fostering a culture that is engaging, accountable, and mission-driven Meet the challenge. Make a difference with Everforth ECS!
Similar jobs
- RT
Embedded Security Software Engineer II (Onsite) with Security Clearance
NewRTX
Tewksbury, MA🇺🇸$68.9k - $131.1k/yrHybrid20 hours agoScrumAgileC+++3Technology - NG
2027 - Associate Cyber Software Engineer - Cincinnati OH with Security Clearance
NewNorthrop Grumman
Cincinnati, OH🇺🇸$76.2k - $114.4k/yrHybrid20 hours agoMercurialShellTCP/IP+6Technology - KT
Security Engineer
NewKforce Technology Staffing
Salt Lake City, UT🇺🇸Hybrid20 hours agoMFALESSZero TrustTechnology - SS
Cyber Security Engineer with Security Clearance
NewSHINE Systems
Reston, VA🇺🇸$135k - $216k/yrHybrid20 hours agoTechnology - EC
Information System Security Officer (ISSO) with Security Clearance
NewECS
Fairfax, VA🇺🇸$140k - $160k/yrOn-site20 hours agoAWSKubernetesGrafana+1Technology - MS
Akamai Security Engineer
NewMarici Solutions
New York, NY🇺🇸On-site20 hours agoSQLOWASPDNS+2Technology - OT
Network Security Engineer
NewOctagon Talent
Fort Lauderdale, Florida🇺🇸Hybrid28 minutes agoAzurePrismaZero TrustTechnology - LE
Principal Network Security Engineer with Security Clearance
NewLeidos
Odenton, MD🇺🇸Hybrid20 hours agoEncryptionTCP/IPAnsible+4Technology - ME
SIEM Engineer
NewMerican Inc
Harrisburg, PA🇺🇸On-site20 hours agoSplunkTechnology - RT
Embedded Security Software Engineer I (Onsite) with Security Clearance
NewRTX
Tewksbury, MA🇺🇸Hybrid20 hours agoScrumAgileC+++3Technology - TS
Lead Vulnerability Researcher with Security Clearance
NewTwo Six Technologies
Arlington, VA🇺🇸$154.3k - $231.4k/yrOn-site20 hours agoC++PythonTechnology - IG
Cyber A&A Engineer with Security Clearance
Insight Global, Inc.
Schriever AFB, CO🇺🇸Hybrid5 weeks agoTechnology