Cybersecurity Engineer - ISSE/ISSO
Serco · Montgomery, AL
—
Jul 24, 2026
Montgomery, AL
Jul 27, 2026
What this job asks for AI summary
A hybrid security engineering and compliance role focused on identity, credential, and access management systems. The position is responsible for designing and operating Okta and SailPoint environments — covering single sign-on, lifecycle management, identity governance, and provisioning — while also serving as the ISSO of record, maintaining system authorizations and RMF documentation. Suits an experienced practitioner comfortable bridging hands-on IAM engineering with formal risk management and A&A responsibilities in a DoD context.
Senior level · 8+ years · San Antonio-New Braunfels, TX · Secret clearance · Full-time
“or” means any one of them counts — you don't need all of them.
Posted 2 times — it's one opening, so apply once.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $125,255 (middle half $101,678–$152,501).
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (10)
The role is a hybrid ISSE/ISSO — it blends hands-on security engineering (architecture, configuration, integration) with compliance/authorization officer duties (RMF A&A, ATO, POA&Ms). 15-1212 (Information Security Analysts) is the best fit given the primary day-to-day work; 15-1299 is noted as a runner-up because the ISSE engineering depth pushes toward a systems-security-engineer occupation that BLS does not cleanly separate.
The degree requirement is marked None because the JD offers multiple degree/experience substitution paths (Bachelor's+8 yrs, Associate's+10 yrs, Master's+6 yrs) — no single degree level is a hard gate.
Total years minimum is set to 8, reflecting the lowest qualifying combination (Bachelor's + 8 years). The 10-year and 6-year paths are alternatives tied to different degree levels.
The salary range referenced in the posting ('The range for this position can be found at the top of this posting') was not actually included in the provided text; no compensation figures could be extracted.
The role requires working Central Time Zone hours and travel up to 25% CONUS, with periodic travel to San Antonio, TX — it is not fully remote.
CISSP appears both as a qualifying DoD 8570 certification (required section) and as a desired/additional certification. It is captured as preferred here because the DoD 8570 gate is satisfied by Security+ or CySA+ alone; CISSP as a standalone credential is listed under 'Additional desired experience.'
Okta and SailPoint vendor certifications (Okta Certified Administrator, SailPoint IdentityNow Engineer) are listed under 'Additional desired experience' and are marked preferred.
Zero Trust Architecture familiarity is listed under 'Additional desired experience' and is marked preferred.
Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): NIST SP 800-53, Zero Trust Architecture.
Requires a Secret clearance — the cleared population is a small fraction of this occupation, so the real candidate pool is materially smaller than the estimate below, which does not model clearance.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.