Full-Time

Information System Security Engineer 2

Deadline 8/1/27
Ishpi Information Technologies

Ishpi Information Technologies

51-200 employees

Holistic cyber defense services and training

No salary listed

No H1B Sponsorship

Philadelphia, PA, USA

In Person

US Citizenship, US Top Secret Clearance Required

Bachelor's

Category
IT & Security (1)
Required Skills
Cybersecurity

Get referred to Ishpi Information Technologies

See people who can refer or advise you

Requirements
  • A Bachelor's degree in Computer Science, Information Technology, or an equivalent technical degree from an accredited college or university is required.
  • Three years of professional experience capturing and refining information security operational and security requirements and ensuring those requirements are addressed through architecting, design, development, and configuration is required.
  • Experience implementing security controls, configuration changes, software and hardware updates and patches, vulnerability scanning, and secure configurations is required.
  • One of the following certifications is required: CCNA-Security, CySA+, GICSP, GSEC, or Security+ CE.
  • U.S. citizenship and an active government security clearance are required.
Responsibilities
  • Provide cybersecurity support for the Code 104 Information Technology Operations Division as an Information System Security Engineer.
  • Perform Assessment and Authorization, cybersecurity compliance and audit readiness, Information Assurance Vulnerability Management, vulnerability scanning and remediation, and application and implementation of Security Technical Implementation Guides and Security Requirements Guides.
  • Develop, maintain, and track Risk Management Framework system security plans, including system categorization forms, Platform Information Technology determination checklists, Assess Only determination checklists, implementation plans, system-level continuous monitoring strategies, system-level policies, hardware and software lists, system diagrams, privacy impact assessments, and Plans of Action and Milestones.
  • Execute the Risk Management Framework process to support obtaining and maintaining Interim Authority to Test, Assessing Official approval, Authorization to Operate, and Denial of Authorization to Operate.
  • Identify and tailor Information Technology and cybersecurity security-control baselines based on Risk Management Framework guidelines and boundary categorization.
  • Perform Ports, Protocols, and Services Management and Information Technology and cybersecurity vulnerability-level risk assessments.
  • Execute security-control testing required by risk assessments or annual security reviews.
  • Mitigate and remediate Information Technology and cybersecurity system-level vulnerabilities for all assets within the boundary according to Security Technical Implementation Guide requirements.
  • Develop and maintain Plans of Action and Milestones in Enterprise Mission Assurance Support Service.
  • Develop and maintain system-level Information Technology and cybersecurity policies and procedures for assigned Risk Management Framework boundaries or command Information System Security Manager guidance.
  • Implement and assess Security Technical Implementation Guides and Security Requirements Guides.
  • Develop and perform vulnerability assessments using automated tools such as Assured Compliance Assessment Solution, Security Content Automation Protocol Compliance Check, and Evaluate STIG.
  • Deploy security updates to information-system components.
  • Perform routine audits of Information Technology system hardware and software components and maintain an inventory of information-system components.
  • Participate in Information Technology change-control and configuration-management processes.
  • Upload vulnerability data in Vulnerability Remediation Asset Manager.
  • Image or re-image assets within the assigned Risk Management Framework boundary.
  • Install software and troubleshoot software issues to support compliance of Risk Management Framework boundary assets.
  • Assist with removing solid-state drives, hard disk drives, and other critical asset components before destruction and removal from the Risk Management Framework boundary.
  • Provide cybersecurity patching of assets during Department of Defense and Department of the Navy task or fragmentary orders or when designated by command security management.
  • Support configuration-change documentation and control processes and maintain Department of Defense Security Technical Implementation Guide compliance.
  • Support cyber compliance for assets on an enterprise Information Technology network, including Windows servers and Cisco networking hardware, by assessing vulnerabilities, patching, and meeting hardware Security Technical Implementation Guide requirements.
  • Report network-hardware compliance issues to management to avoid operational impact to the network.
Ishpi Information Technologies

Ishpi Information Technologies

View

Ishpi Information Technologies provides cybersecurity, information operations, and engineering services to the U.S. Armed Forces and homeland security agencies. The company delivers these services through an integrated approach that combines secure software development, technical consulting, and training to protect every layer of a digital network. Unlike competitors that may focus only on software or hardware, Ishpi uses a "holistic" strategy that accounts for human input and high-level software quality standards to ensure systems are ready for both defense and active engagement. Their goal is to provide national defenders with a state of constant readiness to anticipate, defend against, and counter threats within the cyber domain.

Company Size

51-200

Company Stage

N/A

Total Funding

N/A

Headquarters

null

Founded

2006

Get referred to Ishpi Information Technologies

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • ISHPI won the Coast Guard PMSS task and OASIS+ selection in 2025.
  • The DOI cybersecurity order runs through September 30, 2027, extending revenue visibility.
  • HigherGov shows an open Cybersecurity Support Services order with $596.6K obligated as of March 2026.

What critics are saying

  • ISHPI's MAS contract expires August 18, 2026, risking a major sales channel.
  • HigherGov shows only $602K returning to market over 24 months, signaling thin backlog.
  • Federal protest losses or recompetes can erase revenue quickly; one bad award cycle hurts survival.

What makes Ishpi Information Technologies unique

  • ISHPI is an SDVOSB federal contractor with Coast Guard, Navy, and DOI relationships.
  • Active Defense JV with GoHPT won U.S. Coast Guard PMSS work in 2025.
  • ISHPI sells cybersecurity, software, and IT operations through GSA OASIS+ and MAS vehicles.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Company News

Ishpi Information Technologies, Inc.
Dec 16th, 2022
ISHPI AIS Division to Receive IEEE CS/SEI Humphrey Software Quality Award

Ishpi Information Technologies, Inc. is humbled to receive this Software Quality Award named in his honor.

Ishpi Information Technologies
Aug 3rd, 2021
Ishpi recognized as Virginia Values Veterans

Ishpi Information Technologies, Inc. (“ ISHPI ”) announced they have become certified as a Virginia Values Veterans (V3) company.