Information Systems Security Engineer, TS//SCI with Counterintelligence Polygraph Required
at Accrete Ai
- Employment
- Full Time
- Location
- Alexandria, United States
- Posted
- 5d ago
at Accrete Ai
Location: Alexandria, VA Accrete is an agentic managed services company: an AI workforce that does high-stakes, judgement-heavy work for government and enterprise clients — at the economics of software, not labor. At the core is Accrete’s Knowledge Engine, a dynamic context graph that captures an organization’s tacit knowledge, resolves data across silos, and builds a living, auditable ground truth. Expert agents reason against that ground truth to act on complex, high-stakes decisions — not just answer questions about them. From national security to commercial operations, Accrete delivers the work on one platform, with unlimited expert agents and expert judgement. The Role As an Information Systems Security Engineer (ISSE) Mid, you will work at the intersection of software engineering, cybersecurity, systems architecture, and government security requirements . You will help ensure that Accrete's AI and data systems are designed, deployed, and operated securely in mission-critical environments. You will work closely with software engineers, DevOps, security teams, data scientists, product teams, and government stakeholders to identify security requirements, assess technical risks, implement security controls, and support authorization and accreditation activities. The ideal candidate is technically hands-on, understands modern software and cloud environments, and can translate security requirements into practical engineering solutions. What You'll Do Security Engineering Apply security engineering principles throughout the system development lifecycle Define and document system security requirements and technical security controls Analyze system architectures and identify security risks, vulnerabilities, and potential attack vectors Develop Authority to Operate (ATO)-ready security architectures for AI, data, cloud, and enterprise systems Work with engineering teams to incorporate security controls into system designs and implementations Support security assessments, risk assessments, vulnerability remediation, and continuous monitoring Develop and maintain system security documentation, diagrams, control implementations, and technical artifacts Evaluate proposed system changes for security impact Support security reviews of new technologies, integrations, APIs, infrastructure, and software components Ensure systems are designed according to applicable government security requirements and best practices RMF & Authorization Support Risk Management Framework (RMF) activities throughout the system lifecycle Assist with the end-to-end ATO preparation, vulnerability remediation, approval processes, and maintenance Develop and regularly update documentation supporting security authorization packages Support implementation and assessment of NIST 800-53 security controls Work with ISSOs, ISSMs, system owners, security teams, and government Authorizing Officials Track security findings and coordinate remediation with engineering teams Support Plan of Action and Milestones (POA&M) development and remediation Maintain evidence demonstrating security control implementation Support continuous monitoring and ongoing authorization activities Technical Security Assess application, infrastructure, network, cloud, and data security risks Work with engineering teams to implement secure configuration and deployment practices Support vulnerability management and remediation activities Evaluate authentication, authorization, identity, access control, encryption, logging, and monitoring mechanisms Review system and application configurations for security weaknesses Support secure software development and DevSecOps practices Help establish security requirements for APIs, integrations, data pipelines, and AI systems Analyze security implications of new AI/ML technologies and architectures Support security hardening of systems operating in classified or restricted environments Engineering & Automation Partner with software engineers, DevOps engineers, and platform teams to implement security solutions Automate security checks, compliance validation, configuration management, and reporting where possible Develop scripts and tooling to improve security operations and compliance workflows Integrate security requirements into CI/CD pipelines and infrastructure-as-code processes Help develop repeatable patterns for securely deploying Accrete capabilities across government security fabrics Execute CVE scans, identify code fixes, configuration changes, and exception documentation needs to comply with a continuous ATO cycle Troubleshoot complex technical and security issues across application and infrastructure layers Mission & Customer Support Work directly with government customers and technical stakeholders Translate government security requirements into actionable engineering requirements Support technical discussions, security reviews, demonstrations, and customer meetings Communicate security risks and recommendations to both technical and non-technical stakeholders Help customers understand the security architecture and controls supporting Accrete systems Support deployment and accreditation of systems in customer-specific environments What We're Looking For Active TS//SCI clearance and Counterintelligence or Lifestyle Polygraph 3+ years of experience in information systems security engineering, cybersecurity, systems engineering, software engineering, or a related technical field Bachelor's degree in Computer Science, Cybersecurity, Computer Engineering, Information Systems, or a related discipline Strong understanding of system and application security principles Experience with NIST security frameworks and NIST SP 800-53 Experience supporting RMF and/or ATO processes Understanding of secure software development and DevSecOps practices Experience evaluating technical architectures for security risks Experience with identity and access management, authentication, authorization, encryption, logging, and monitoring