Information Systems Security Engineer III - (W2PE)
at Trace3
- Work model
- Hybrid
- Location
- Colorado Springs, CO
- Posted
- 5d ago
at Trace3
<div class="content-intro"><p><img src="https://i.postimg.cc/Wb1SdDgC/Join-the.png" alt="" width="649" style="max-width: 100%;"></p> <hr> <p>Who is <strong>Trace3</strong>?</p> <p>Trace3 is a leading Transformative IT Authority, providing unique technology solutions and consulting services to our clients. Equipped with elite engineering and dynamic innovation, we empower IT executives and their organizations to achieve competitive advantage through a process of Integrate, Automate, Innovate.</p> <p>Our culture at Trace3 embodies the spirit of a startup with the advantage of a scalable business. Employees can grow their career and have fun while doing it!</p> <p>Trace3 is headquartered in Irvine, California. We employ more than 1,200 people all over the United States. Our major field office locations include Denver, Indianapolis, Grand Rapids, Lexington, Los Angeles, Louisville, Texas, San Francisco. </p> <p><strong>Ready to discover the possibilities that live in technology?</strong></p> <p> </p> <p><strong>Come Join Us!</strong></p> <p><strong>Street-Smart</strong> <strong>- <em>Thriving in Dynamic Times</em></strong></p> <p>We are flexible and resilient in a fast-changing environment. We continuously innovate and drive constructive change while keeping a focus on the “big picture.” We exercise sound business judgment in making high-quality decisions in a timely and cost-effective manner. We are highly creative and can dig deep within ourselves to find positive solutions to different problems.</p> <p><strong>Juice - <em>The “Stuff” it takes to be a Needle Mover </em></strong></p> <p>We get things done and drive results. We lead without a title, empowering others through a can-do attitude. We look forward to the goal, mentally mapping out every checkpoint on the pathway to success, and visualizing what the final destination looks and feels like.</p> <p><strong>Teamwork - <em>Humble, Hungry and Smart</em></strong></p> <p>We are humble individuals who understand how our job impacts the company's mission. We treat others with respect, admit mistakes, give credit where it’s due and demonstrate transparency. We “bring the weather” by exhibiting positive leadership and solution-focused thinking. We hug people in their trials, struggles, and failures – not just their success. We appreciate the individuality of the people around us.</p> <hr> <p> </p></div><p><strong>*This position will be hybrid remote, with 1-3 days on-site in Colorado Springs, CO required, some travel to client sites may be required | Active (or active within 24months) Secret Security Clearance required, can hold TS</strong></p> <p><strong>JOB SUMMARY:</strong></p> <p>The Information System Security Engineer III (ISSE III) serves as a key technical leader responsible for integrating cybersecurity across the full lifecycle of complex information systems. This role acts as the primary liaison between systems engineering teams and security compliance stakeholders, ensuring security requirements are effectively implemented without compromising mission or operational objectives.</p> <p>This position supports a Department of Defense (DoD) program focused on enhancing the cybersecurity posture of mission-critical systems operating within <strong>Amazon Web Services (AWS) classified environments</strong>. The role is heavily centered on executing the <strong>Risk Management Framework (RMF)</strong>, driving system hardening efforts, conducting vulnerability assessments, and developing the documentation required to achieve and maintain <strong>Authority to Operate (ATO)</strong>.</p> <p><strong> </strong></p> <p><strong>SUMMARY OF ESSENTIAL JOB FUNCTIONS:</strong></p> <p><strong>Security Architecture & Engineering</strong></p> <ul> <li>Design, develop, and implement secure architectures across multi-level systems, cloud environments (AWS), and on-premise networks</li> <li>Integrate security controls into system design aligned with <strong>NIST 800-53</strong> and DoD requirements</li> </ul> <p><strong>Risk Management Framework (RMF) Leadership</strong></p> <ul> <li>Lead RMF lifecycle activities, including system categorization, control selection, implementation, and continuous monitoring</li> <li>Tailor security controls based on system risk, mission needs, and operational constraints</li> </ul> <p><strong>Assessment & Authorization (A&A)</strong></p> <ul> <li>Develop and maintain Body of Evidence (BoE) documentation, including:</li> <ul> <li>System Security Plans (SSP)</li> <li>Security Assessment Reports (SAR)</li> <li>Plan of Action & Milestones (POA&M)</li> </ul> <li>Support assessment activities and coordinate with Authorizing Officials and assessors</li> </ul> <p><strong>Vulnerability Management & System Hardening</strong></p> <ul> <li>Conduct vulnerability scans using tools such as Nessus, ACAS, and SCAP</li> <li>Analyze findings, prioritize risks, and drive remediation efforts with engineering teams</li> <li>Implement and validate system hardening in accordance with DoD and industry standards</li> </ul> <p><strong>Stakeholder Engagement & Security Advisory</strong></p> <ul> <li>Serve as a trusted advisor to engineering teams and leadership on cybersecurity risks and mitigation strategies</li> <li>Translate technical vulnerabilities into mission and business risk for senior stakeholders</li> <li>Provide security guidance on system changes, architecture decisions, and engineering trade-offs</li> </ul> <p><strong> </strong></p> <p><strong>REQUIRED QUALIFICATIONS:</strong></p> <ul> <li>Minimum of 5 years of experience in cybersecurity, systems engineering, or information assurance</li> <li>Experience implementing the <strong>DoD Risk Management Framework (RMF)</strong> in regulated or classified environments</li> <li>Active certification meeting <strong>DoD 8570 / 8140 requirements</strong> (e.g., CISSP, CASP+, or equivalent)</li> <li>Strong un