We use essential cookies

Please Accept our Privacy Policy

Cybersecurity Engineer

Nortex Cyber Solutions

Fort Meade, MD 20755-7039 • 9/26/2026

Job Description

Job Description

CLEARANCE REQUIRED FOR START:Yes

CLEARANCE TYPE:Top Secret/SCI with CI Polygraph

LOCATION:Fort Meade, MD

Job Summary:

Nortex Cyber Solutions is seeking an experiencedCybersecurity Engineer / Information Systems Security Engineer (ISSE)to support the security authorization, assessment, and continuous monitoring of mission-critical information systems.

This position requires a strong technical understanding of the Risk Management Framework (RMF), security controls, system hardening, vulnerability management, and the development and maintenance of authorization packages. The ideal candidate can independently evaluate system security, identify and document risk, maintain traceable bodies of evidence, and work with engineering teams to implement practical security solutions throughout the system lifecycle.

The individual must be comfortable working within classified environments and accessing and maintaining security packages within NSA environments.

Duties/Responsibilities:

· Support the fullRisk Management Framework (RMF)lifecycle for information systems seeking or maintaining authorization.

· Develop, review, maintain, and update system security authorization packages and supporting bodies of evidence.

· Apply and interpret security controls and requirements in accordance withNIST SP 800-53andDoD Instruction 8510.01 (RMF for DoD IT).

· Use security package management and governance tools such aseMASSandXactato develop, maintain, track, and manage system authorization documentation.

· Scope security assessments and conduct assessments of information systems undergoing accreditation/authorization or maintaining an existing authorization.

· Support the preparation, coordination, and approval ofInterim Authorizations to Test (IATTs)for systems requiring testing prior to full authorization.

· Evaluate system configurations against applicableDISA Security Technical Implementation Guides (STIGs),CIS Benchmarks, and other security configuration standards.

· Conduct and analyze vulnerability assessments using tools such asACAS/SecurityCenter and Nessus.

· Review vulnerability scan results, determine applicability and risk, track remediation activities, and support the development and maintenance of Plans of Action and Milestones (POA&Ms), as applicable.

· Work closely with system engineers, developers, and other technical stakeholders to implement and validate security controls.

· Support the implementation of automated solutions forcontinuous monitoring of security controls, vulnerabilities, configurations, and other security requirements.

· Identify opportunities to improve RMF, assessment, evidence collection, and continuous monitoring processes through automation.

· Appropriately leverage AI-enabled tools when beneficial while maintaining sufficient cybersecurity and RMF expertise to independently understand, validate, and take responsibility for the intended outcome.

· Maintain organized, accurate, and traceable documentation demonstrating the relationship between security requirements, implemented controls, assessment results, findings, remediation activities, and supporting evidence.

· Participate in Agile development and engineering environments and work effectively withinSAFe Agileprocesses.

· Communicate security risks, findings, and requirements clearly to both cybersecurity and engineering stakeholders.

Require Qualifications

· ActiveTS/SCI clearance with CI Polygraphrequired at time of hire.

· Ability to access required classified environments and security packages within NSA systems.

· Strong working knowledge of theDoD Risk Management Framework (RMF)and the complete authorization lifecycle.

· Strong knowledge ofNIST SP 800-53security and privacy controls andDoDI 8510.01.

· Experience developing, reviewing, and maintaining RMF authorization packages and supporting bodies of evidence.

· Hands-on experience witheMASS and/or Xactafor security package and authorization management.

· Strong understanding ofDISA STIGs, CIS Benchmarks, system hardening, and security configuration requirements.

· Experience usingACAS/SecurityCenter and Nessusfor vulnerability scanning, analysis, and remediation support.

· Experience scoping and conducting security assessments for information systems undergoing or maintaining authorization.

· Knowledge of theIATT processand experience supporting systems requiring authorization for testing.

· Understanding of continuous monitoring requirements and approaches for validating security controls throughout the system lifecycle.

· Ability to work with technical teams to develop or implement automation supporting cybersecurity and continuous monitoring activities.

· Familiarity withSAFe Agileor similar Agile development environments.

· Strong written and verbal communication skills.

· Exceptional attention to detail, organization, documentation, and configuration management.

· Ability to maintain clear traceability across security requirements, implementation details, assessment procedures, findings, and supporting evidence.

Preferred Qualifcations

· Experience supporting NSA, DoD, or Intelligence Community information systems.

· Experience working directly with system owners, ISSMs, ISSOs, security control assessors, and Authorizing Official representatives.

· Experience with continuous monitoring and automated security control validation.

· Experience integrating security activities into CI/CD or DevSecOps environments.

· Experience developing scripts, workflows, or other automation to improve security assessment, evidence collection, vulnerability management, or compliance processes.

· Familiarity with AI-assisted cybersecurity or compliance workflows, with the technical expertise necessary to independently verify AI-generated outputs.

· Relevant cybersecurity certifications such as Security+, CISSP, CAP/CGRC, CASP+/SecurityX, or equivalent.

Education & Experience

· Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related technical field preferred.

· 10+ years of relevant cybersecurity, information assurance, RMF, or systems security engineering experience.

· Equivalent combinations of education, certifications, and directly relevant experience may be considered.

Physical Requirements

· Ability to remain seated and work at a computer for extended periods.

· Ability to occasionally lift up to 15 pounds.

· Ability to communicate effectively in person and through virtual collaboration tools.

Benefits & Perks

As an Employee First company, we offer a comprehensive and competitive total rewards package:

· 100% Company-paid medical insurance for employees

· 100% Company-paid dental and vision insurance

· Competitive salary

· Generous 401k employer contribution to your 401k with no required personal contribution with immediate vesting

· Generous PTO and parental leave

· Flexible work hours

This role requires use of technical data subject to U.S. Government contract restrictions; therefore, this posting is only for U.S. Citizens.

Nortex Cyber Solutions is an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity or expression, pregnancy, age, national origin, disability status, genetic information, protected veteran status, or any other characteristic protected by law.