Information Systems Security Engineer-RMF (ISSE II) (Government) at AT&T

Columbia, Maryland, United States

AT&T Logo
Not SpecifiedCompensation
Mid-level (3 to 4 years), Senior (5 to 8 years)Experience Level
Full TimeJob Type
NoVisa
Government, Defense, TelecommunicationsIndustries

Requirements

  • Required Clearance: TS/SCI with polygraph
  • Fourteen (14) years’ experience as an ISSE on programs and contracts of similar scope, type, and complexity within the Federal Government
  • Bachelor’s degree in Computer Science (or related field, as implied)
  • Knowledge of servers, virtualization, routers, switches, and firewalls as well as VLANs, routing, and network segmentation
  • Demonstrated experience authoring and maintaining System Security Plans (SSPs), SCTMs, and POA&Ms
  • Solid understanding of continuous monitoring, reauthorization, and configuration management processes
  • Hands-on familiarity with Tenable, Splunk, STIG Viewer, and customer security compliance management tools
  • Knowledge of Windows, Linux, and network security controls implementation
  • Excellent communication and teamwork skills
  • Results oriented, high energy, self-motivated
  • Willingness to train junior team members
  • Office presence a minimum of 5 days per week (no relocation offered)
  • Ability to respond to after-hours requests in a 24x7 environment

Responsibilities

  • Serve as the technical security engineer for assigned systems and System Security Plans (SSPs), ensuring full lifecycle RMF compliance
  • Provide technical input for Authorization to Operate (ATO) packages, risk acceptance decisions, and continuous monitoring efforts
  • Implement and validate security controls from NIST SP 800-53 and serve as technical security liaison with technology frameworks
  • Ensure all controls are properly mapped, implemented, and tested within the Security Control Traceability Matrix (SCTM) and respond to Security Assessment Report (SAR)
  • Collaborate with the vulnerability scanning team (e.g., Tenable operators) to ensure scan compliance, findings are addressed, retested, and reflected accurately in the system’s risk posture
  • Support continuous monitoring activities, including vulnerability tracking, control reassessments, and serve as technical security liaison with technology frameworks
  • Coordinate with ISSOs and system administrators to document and remediate vulnerabilities, control deficiencies, and Plan of Action & Milestones (POA&M) items
  • Lead or support reauthorization efforts, ensuring all system technical artifacts are updated, validated, and submitted on schedule
  • Evaluate and document security-relevant changes, assessing configuration updates, patches, or system modifications for RMF impact
  • Interface with Security Architect to ensure designs, configurations, and security mitigations align with approved architectures and customer mandates
  • Work with Technology Framework teams to complete all system documentation
  • Test and evaluate configurations in a lab environment
  • Perform or review technical security assessments of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations, and recommend mitigation strategies
  • Provide security operations support as needed

Skills

Key technologies and capabilities for this role

RMFNIST SP 800-53System Security PlansATOSecurity ControlsSCTMSARVulnerability ScanningTenable

Questions & Answers

Common questions about this position

Is this position remote or does it require office presence?

This position requires office presence a minimum of 5 days per week and is only located in the location(s) posted.

What are the main responsibilities of the Information Systems Security Engineer?

The role involves serving as the technical security engineer for assigned systems and SSPs, ensuring RMF compliance, providing input for ATO packages, implementing NIST SP 800-53 controls, collaborating on vulnerability scanning, and supporting continuous monitoring and reauthorization efforts.

What salary or compensation is offered for this role?

This information is not specified in the job description.

What is the company culture like at AT&T Global Public Sector?

AT&T Global Public Sector is dedicated to recruiting, developing and empowering a diverse, high-performing workforce that is passionate about what they do, committed to shared values, and dedicated to customers’ missions.

What makes a strong candidate for this Information Systems Security Engineer position?

Strong candidates will have expertise in RMF compliance, NIST SP 800-53 security controls, vulnerability scanning and remediation, continuous monitoring, and knowledge of servers, virtualization, routers, and switches, along with experience supporting ATO packages and collaborating with ISSOs and technology teams.

AT&T

Telecommunications services including wireless and broadband

About AT&T

AT&T provides telecommunications services, including wireless communications, broadband internet, and digital television, primarily in the United States. Its 5G network offers faster data speeds and more reliable connections, although availability can vary. The company caters to both individual consumers and businesses, offering various subscription plans that include options for unlimited data and bundled services that combine internet, TV, and phone. AT&T generates revenue mainly through subscription fees, device sales, and its streaming service, DIRECTV STREAM, which adds to its diverse offerings. In a competitive market, AT&T distinguishes itself with its extensive service range and strong brand presence.

Dallas, TexasHeadquarters
1876Year Founded
$43.3MTotal Funding
IPOCompany Stage
Consumer Software, EntertainmentIndustries
10,001+Employees

Benefits

Health Insurance
Dental Insurance
Vision Insurance
401(k) Retirement Plan
401(k) Company Match
Paid Vacation
Paid Sick Leave
Paid Holidays
Paid Parental Leave
Adoption Assistance
Disability Insurance
Life Insurance
Employee Assistance Programs
Wellness Program
Employee Discounts

Risks

The customer service guarantee may increase financial liabilities due to compensation for outages.
A recent data breach could damage AT&T's reputation and lead to customer churn.
Resistance to replacing landlines may impact customer retention and satisfaction.

Differentiation

AT&T offers a unique customer service guarantee, setting it apart from competitors.
The company is expanding its fiber network, enhancing broadband offerings in underserved areas.
AT&T's 'Phone-Advanced' device aligns with the trend of replacing traditional landlines.

Upsides

AT&T's fiber network expansion could provide a competitive edge in broadband services.
The new customer service guarantee may attract customers from competitors lacking similar assurances.
Collaboration with The Arc enhances AT&T's brand image through corporate social responsibility.

Land your dream remote job 3x faster with AI