Cyber Security Systems Engineer - Expert
About the role
BAE Systems, a top-ten prime contractor to the U.S. Department of Defense, enables the U.S. government to transform data into intelligence and provides engineering, integration and sustainment support for critical military platforms and systems. Intelligence & Security provides services and products to the Department of Defense, the intelligence community, federal law enforcement officials, and troops deployed around the world.
We are looking for an ISSE to join our technology-based program supporting a key government customer. This program will deliver engineering services for network infrastructure as well as sophisticated enterprise computing infrastructure including end-point devices, data center hosted servers, multi-Cloud services as well as virtualized applications, and storage systems.
Responsibilities
Enterprise Computing Engineering services include modern application technology including containerized solutions with orchestrated workflow that function both on customer premise, and via remote Cloud services. Network infrastructure engineering services are comprised of core infrastructure, voice and video engineering, field engineering, application management and development for networks, network analytics, firewalls, network access controls and bandwidth service delivery.
- Possess multi-tasking skills, as well as be a good communicator/facilitator.
- Comfortable at all levels from developer to senior staff.
- Knowledge of the complex network environments involving shared networks and multiple security enclaves.
- Possess the ability to bridge the technical implementation (i.e. developer talk), into commonly understood security words.
- Document the various security control implementations as well as gather the artifacts that support the Risk Management Framework (RMF) and ICD 503 Security Accreditation for various Assessment and Authorization (A&A) efforts.
- Document and obtain a general understanding of the architecture being developed or that was developed for each project in order to write the Systems Security Plans (SSP)/CONOPS in the Greenlight application.
- Gather the information by working with various team members in order to write various additional A&A related documents such as Contingency Plan (CP), General User Guide (GUG), Privileged User Guide (PUG), Standard Operating Procedures (SOP’s), etc.
- Support Accreditation and Authorization (A&A) reviews by ISSO/M, as well as the Security Controls Assessor (SCA).
- Document the Plans of Actions and Milestones (POA&Ms) implementation responses or mitigations, as well as provide all required artifacts (i.e. evidence gathering from the teams).
- Coordinating with various contractor and staff personnel to obtain the A&A content, as well as working with various customer security organizations to navigate the customer’s A&A process in order to achieve Authority to Develop (ATD), Interim Authority to Operation (IATT), as well as Authority to Operate (ATO).
- Keep track of where each of the various A&A projects are within the customer’s A&A process in order to know when it’s time to re-submit for accreditation or an accreditation extension.
Requirements
We are actively seeking Cyber Security Systems Engineers with a minimum of eleven (11) years' experience. This opportunity is supporting the customer’s Division level A&A projects which has several Branches within it.
- Bachelor's or Master’s Degree are preferred in one or more discipline but can be waived if previous direct ISSE support to this customer’s agency.
Qualifications
- Previous ISSE experience directly supporting the customer.
- Previous ISSO experience directly supporting the customer is also helpful.
- Various security tools and reports such as Greenlight, RoadRunner, Rapid 7, WebInspect, App Detective, and Splunk.
- Public, private and hybrid Cloud experience (AWS, Microsoft Azure, etc.).
- Virtualization experience (VDI & VMWare).
- Basic knowledge is helpful, but not required for the following general topics: Cloud security control implementation, PKI implementation, STIG compliance and vulnerability management, and Security Development and Operations (SecDevOps).
- CISSP, or GSLC.
- AWS Certified Security Specialty.
- Basic Excel and Microsoft Office365.
Pay
Full-Time Salary Range: $149603 - $254317. Please note: This range is based on our market pay structures. However, individual salaries are determined by a variety of factors including, but not limited to: business considerations, local market conditions, and internal equity, as well as candidate qualifications, such as skills, education, and experience.
Benefits
At BAE Systems, we support our employees in all aspects of their life, including their health and financial well-being. Regular employees scheduled to work 20+ hours per week are offered: health, dental, and vision insurance; health savings accounts; a 401(k) savings plan; disability coverage; and life and accident insurance.
- We also have an employee assistance program, a legal plan, and other perks including discounts on things like home, auto, and pet insurance.
- Our leave programs include paid time off, paid holidays, as well as other types of leave, including paid parental, military, bereavement, and any applicable federal and state sick leave.
- Employees may participate in the company recognition program to receive monetary or non-monetary recognition awards.
- Other incentives may be available based on position level and/or job specifics.