Information System Security Officers (ISSO), Senior Security Engineers & Security Engineering Leads (CBP)
Agile Defense
Job details
- HYBRID
- UNKNOWN
- Reston
- United States
- Verified 2026-09-25
- Source: Agile Defense public LEVER source
Original job description
About Agile Defense At Agile Defense we know that action defines the outcome and new challenges require new solutions. That’s why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next. Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility—leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation’s vital interests.Title: Information System Security Officers (ISSO), Senior Security Engineers & Security Engineering Leads (CBP) Clearance: Active Top Secret with SCI eligibility, Ability to obtain and maintain a CBP Background Investigation (CBP BI) and EOD, active BI strongly preferred. We can begin processing for candidates who do not hold one. Citizenship: U.S. Citizenship required Location: Reston, VA - Hybrid 3 to 5 days Salary Range: $140,000-190,000 Signing Bonus: $10,000 for candidates with an active CBP BI. Payable after 90 days; standard terms apply. Required Certification(s): One or more of the following: CISSO, CISM, CCSP, CEH, or other relevent equivilant The Work U.S. Customs and Border Protection runs continuous operations across more than 300 land, air, and sea ports of entry, plus Border Patrol stations and the Air and Marine Operations Center. Security work here carries a cost that security work in a corporate environment does not. A control that blocks something at two in the morning at a remote checkpoint does not inconvenience an employee at a desk. It stops an officer from doing the thing they are standing there to do. Getting that judgment right, over and over, inside a federal authorization process, is most of the job. We are hiring on two tracks. Information system security officers own whether systems stay authorized and whether the paperwork describing them is true. Senior security engineers own how systems are hardened, monitored, and fixed. You will work with network engineers, cloud engineers, field deployment teams, and the government security staff who have to be persuaded rather than informed. One thing is worth knowing before you apply. There is more documentation and process in this work than either track usually wants. An engineer hoping to build tooling all day and an ISSO hoping to write packages undisturbed will both find the job wider than the title suggests. What Success Looks Like Objective 1: Close security findings at their cause rather than at the ticket
- Findings that get closed stay closed, instead of returning in the next scan under a new number.
- Remediation addresses why the condition existed, not only the instance a scanner happened to catch.
- Recurring finding types get traced back to the build, the process, or the standard that produced them.
- Where something cannot be fixed, the reason and the compensating control are written down and hold up when somebody challenges them.
- Engineers bring you in early because your answer saves them work, not because a gate makes them.
- Requirements arrive in time to change a decision rather than to document one already made.
- You can tell an engineer what will and will not pass, and be right often enough that they stop checking around you.
- Somebody can ask about the state of a system and get an answer that is current rather than an answer from the last assessment.
- What is recorded as implemented matches what is running.
- Risk that leadership needs to know about reaches them while there is still a decision to make.
- Information System Security Officer. You own whether your assigned systems stay authorized and stay honestly described. You decide what counts as an acceptable control implementation, what belongs on a POA&M, and when a change needs a security review before it proceeds.
- Senior Security Engineer. You own how systems get hardened, monitored, and remediated. You decide what the secure configuration is, what tooling the program runs, and which risks get engineered out rather than accepted and tracked.
- Security Engineering Lead. You own the security engineering function as a whole, including the standards other engineers build against. You are accountable when a design meets a threat or an audit finding it did not anticipate.
- One or more of the following certifications required:
- Active Certified Information Systems Security Professional (CISSP)
- Active Certified Information Security Manager (CISM)
- Other relevant certifications (e.g., CCSP, CEH) may be considered.
- Bachelor’s degree in computer science, Engineering, STEM, Information Technology, or Cybersecurity
- A minimum of eight (8) years of experience in information security, with at least 5 years specifically in a lead ISSO or similar leadership capacity on large complex USG programs.
- Active CISSP
- Active Project Management Professional (PMP) certification
- Active ISC2 Certified in Governance, Risk and Compliance (CGRC)
- Knowledge of FedRAMP
- Knowledge of A-123 audit Experience and Expertise with GRC tools such as CSAM
- You have carried a system through authorization and can say what the hard part actually was.
- You have worked inside RMF or an equivalent federal authorization framework, not only a private-sector control set.
- You have closed a class of findings rather than a list of them, and can describe what you changed to make that stick.
- You have written or reviewed security documentation that somebody else then had to defend in front of a government reviewer.
- You have run continuous monitoring where the data was incomplete and had to be made useful anyway.
- You hold an active CBP BI, a fitness determination at another DHS component, or an active DoD clearance. Any of these shortens your start date.
- Certifications such as CISSP, CISM, CAP, or Security+ are useful, but they are not a substitute for having done the work.
Related jobs
- Veterinarian Medical Director | Equity Available at Allianceanimalhealth
- Veterinarian Owner/Medical Director at Allianceanimalhealth
- Senior Member Technical Staff - Senior QA Engineer at Thenielsencompany
- Senior Linux & Infrastructure Automation Engineer at Rrdonnelley
- Senior Enterprise Platforms Professional I ( SAP HANA BODS Developer) at Thenielsencompany
- Product Engineer at Quadient1