Back to Jobs
Sandy Mac Evolution LLC (SME)

Information Systems Security Engineer (ISSE) / Systems Security Analyst

Sandy Mac Evolution LLC (SME)
santa rita, GuamFull TimeMid-level140k–140k USDPosted Today
Information Systems Security Engineer (ISSE) / Systems Security Analyst

Location: Guam – NAVFAC Marianas Salary: $140,000 annually Employment Type: Full-Time Worksite: 100% On-Site Position Status: Contingent Upon Contract Award

Position Overview

Sandy Mac Evolution LLC is seeking a qualified Information Systems Security Engineer (ISSE) / Systems Security Analyst to support the Naval Facilities Engineering Systems Command (NAVFAC) Marianas Command Information Office (CIO) in Guam.

The selected candidate will provide cybersecurity and Risk Management Framework (RMF) support for NAVFAC Marianas information systems and Facility-Related Control Systems (FRCS). This position supports the confidentiality, integrity, and availability of systems, networks, and data through the planning, analysis, development, implementation, documentation, maintenance, and enhancement of information systems security programs, policies, procedures, and tools.

Key Responsibilities

  • Support all phases of the Department of Defense Risk Management Framework (RMF), including RMF Steps 1 through 6.
  • Develop, maintain, and manage RMF authorization packages within the Enterprise Mission Assurance Support Service (eMASS).
  • Support Authorization to Operate (ATO) activities for Facility-Related Control Systems (FRCS).
  • Conduct annual reviews and maintain required cybersecurity authorization documentation.
  • Develop and maintain FRCS cybersecurity policies, procedures, Standard Operating Procedures (SOPs), and supporting documentation.
  • Apply NIST SP 800-53 security controls and applicable Department of Defense cybersecurity requirements.
  • Conduct vulnerability assessments and analyze results using tools such as ACAS and Nessus.
  • Perform Security Technical Implementation Guide (STIG) assessments using SCAP, Evaluate-STIG, manual STIG checklists, and associated compliance tools.
  • Develop, maintain, and track Plans of Action and Milestones (POA&Ms).
  • Support continuous monitoring and Security Lifecycle Management activities.
  • Review vulnerability scan results, system logs, security configurations, and cybersecurity documentation.
  • Utilize Vulnerability Remediation Asset Manager (VRAM) and other DoD cybersecurity tools.
  • Perform on-site RMF validation activities and support RMF Step 4 security assessments.
  • Conduct security impact analyses associated with system configuration changes.
  • Participate in Configuration Management and Configuration Control Board activities.
  • Support cybersecurity incident response and CERT-related activities as required.
  • Participate in applicable cybersecurity on-call or incident-response rotations.
  • Prepare and maintain RMF status reports, cybersecurity documentation, briefings, and other required deliverables.
  • Coordinate with system owners, engineers, administrators, Government personnel, and other cybersecurity stakeholders.
  • Support cybersecurity requirements for industrial control systems, operational technology, and Facility-Related Control Systems throughout the NAVFAC Marianas environment.

Required Qualifications

  • Must be a United States citizen .
  • Must possess an active Tier 5 (T5) security clearance or be able to obtain the required T5 clearance prior to onboarding/hiring .
  • Must meet DoD Manual 8140.03 foundational qualification requirements for:
    • Work Role Code (WRC) 461 – Systems Security Analyst
    • Intermediate proficiency level or higher
  • Must possess and maintain at least one qualifying DoD 8140 certification appropriate to the required work role and proficiency level, including:
    • CompTIA Security+
    • Certified Cloud Security Professional (CCSP)
    • CompTIA Cloud+
    • GIAC Global Industrial Cyber Security Professional (GICSP)
    • GIAC Information Security Fundamentals (GISF)
    • GIAC Security Essentials (GSEC)
    • Or another approved certification meeting the applicable DoD 8140 qualification requirements
  • Demonstrated knowledge and experience supporting the Department of Defense Risk Management Framework.
  • Experience developing, maintaining, or supporting RMF authorization packages.
  • Experience with cybersecurity vulnerability assessment and compliance tools.
  • Knowledge of NIST security controls, DoD cybersecurity policies, STIGs, vulnerability management, and continuous monitoring.
  • Strong written and verbal communication skills.
  • Ability to develop professional cybersecurity documentation, reports, policies, procedures, and briefings.
  • Ability to work independently and effectively coordinate with Government personnel, technical teams, system owners, and other stakeholders.

Preferred Experience

  • Five or more years of experience supporting DoD Risk Management Framework activities is recommended.
  • One or more years of experience supporting Facility-Related Control Systems (FRCS), Industrial Control Systems (ICS), Operational Technology (OT), or related cybersecurity engineering activities is recommended.
  • Experience with:
    • eMASS
    • ATO packages
    • ACAS
    • Nessus
    • SCAP
    • Evaluate-STIG
    • STIG checklists
    • VRAM
    • POA&M development and management
    • Continuous monitoring
    • Configuration management
    • Cybersecurity engineering for FRCS, ICS, or OT environments
  • Previous experience supporting NAVFAC, the Department of the Navy, Department of Defense, or another federal agency is highly desirable.

Place of Performance

Work will be performed on-site in Guam in support of NAVFAC Marianas facilities and systems.

This position requires regular in-person support and is not a remote position .

Additional Information

The selected candidate will support a federal task order providing Information Systems Security Engineer and Systems Security Analyst services to NAVFAC Marianas.

Qualified candidates should submit a current resume clearly identifying relevant RMF, eMASS, ATO, FRCS/ICS/OT, vulnerability management, cybersecurity certification, and clearance experience .

Ready to apply? You'll be taken to Sandy Mac Evolution LLC (SME)'s application page.
Information Systems Security Engineer (ISSE) / Systems Security Analyst at Sandy Mac Evolution LLC (SME)