What are the responsibilities and job description for the Information System Security Engineer position at Cruz Associates, Inc.?
We are seeking an Information Assurance (IA) professional to serve as a primary technical liaison, specifically requiring a deep regulatory background to confidently address and resolve rigorous compliance inquiries using U.S. security frameworks. This role requires a deep working knowledge of NIST RMF, FISMA, and the NIST SP 800 series, particularly as they apply to mission-critical tactical platforms and embedded systems. You will translate complex U.S. technical artifacts into clear assurance narratives, engage directly with original equipment manufacturers (OEMs), and senior leadership. The ideal candidate has experience working across allied government security frameworks and can confidently defend U.S. compliance postures to foreign stakeholders.
summaries.
Required Skills:
- Deep working knowledge of U.S. information assurance frameworks, specifically NIST RMF, FISMA, and the NIST SP 800 series.
- Proven ability to act as a technical liaison, fielding and resolving rigorous regulatory and compliance inquiries from allied partner nations.
- Experience applying IA and cybersecurity standards to mission-critical tactical platforms and embedded systems.
- Demonstrated ability to translate complex U.S. technical artifacts into clear, actionable assurance narratives for leadership.
- Strong stakeholder engagement skills, with experience coordinating directly with original equipment manufacturers (OEMs) and engineering teams.
- Exceptional verbal and written communication skills, with the confidence to defend technical compliance postures to foreign stakeholders.
- 8570 IAM Level II certification
Preferred Skills:
- Prior experience serving as an assurance liaison or integrator between the U.S. and allied government security frameworks (e.g., U.S. to U.K.).
- Familiarity with the cyber accreditation lifecycle for large-scale, complex defense platforms (such as aircraft or other major tactical systems).
- Experience supporting formal risk acceptance forums and briefing senior risk authorities.
- A risk-focused and independent mindset, with the confidence to challenge technical findings or push back on continuous inquiries when necessary.