Company Overview
Enterprise Horizon Consulting Group (EHCG) is a Woman-Owned Small Business specializing in IT Consulting which has successfully delivered key capabilities to the Navy, Army, and NASA over the past 20+ years. EHCG provides best in class services to its customers in the following areas: Business Systems Services; Business Intelligence; Data Analytics and Dashboarding; Enterprise Resource Planning (SAP) Implementation; Legacy System Optimization; Digital Transformation; Cloud Migration; Integration and Modernization; and Risk Management Framework Processes (RMF).
Job Description
Enterprise Horizon Consulting Group is seeking a highly motivated Information Systems Security Engineer (ISSE) to join our team in support of our DoD customer. The ISSE will be responsible for engineering, implementing, and maintaining cybersecurity controls to achieve and sustain an Authority to Operate (ATO) in accordance with DoD and federal requirements.
Key Responsibilities
- Engineer and implement security controls to support system ATO and ongoing authorization
- Lead and support Risk Management Framework (RMF) activities from system categorization through authorization and continuous monitoring
- Develop, review, and maintain ATO documentation including SSPs, SAPs, SARs, POA&Ms, and supporting artifacts
- Map and implement security controls in accordance with NIST SP 800-53, DoDI 8510.01, and DoD cybersecurity policies
- Support security control assessments and coordinate with Authorizing Officials (AOs) and assessors
- Perform security engineering analysis to ensure system designs meet confidentiality, integrity, and availability (CIA) requirements
- Conduct vulnerability assessments and support remediation efforts to reduce risk prior to and after ATO
- Analyze system changes and assess security impact to maintain ATO posture
- Support continuous monitoring activities, including vulnerability scanning, STIG compliance, and annual assessments
- Utilize eMASS to manage RMF artifacts, control status, and ATO packages
- Provide guidance on secure system configurations, hardening, and best practices
- Support audits, inspections, and compliance reviews