Jobs · Information Technology · Colorado

Information System Security Engineer - Senior

BAE Systems, Inc. · Broomfield, CO · 2 wk ago
On-siteInformation Technology$97k–$165k/yrFull-time

About the Role

This position is for an experienced Information System Security Engineer (ISSE) to provide security engineering support within BAE Systems, Inc. Space & Mission Systems (SMS) Sector. The ISSE supports ongoing programs by managing cyber requirements, validating technical security implementations, and supporting Assessment & Authorization efforts pursuant to gaining and/or maintaining system Authorizations to Operate (ATO).

The Engineering, Science and Analysis (ESA) Strategic Capabilities Unit comprises the technical talent and organizational leadership that enables the successful delivery of high-impact discriminating technologies for our customers’ missions. Our collaborative, cross-functional teams are committed to innovation, integrity, continual learning and strong execution.

Responsibilities

  • Participates in the development, review, and advisement of programs on the engineering design, development, and deployment of secure systems, networks, and applications, aligning its implementation across the mission acquisition lifecycle.
  • Assists in validating and verifying system security requirements definitions and analysis and establishes system security designs.
  • Supports in maintaining and promoting a comprehensive and holistic cybersecurity engineering view while addressing stakeholder security risks and concerns through the application of systems engineering skills.
  • Supports security incident response and investigation activities, including root cause analysis and remediation efforts, collaborating with cross-functional teams, including Engineering, IT, Operations, and Compliance.
  • Performs, or reviews, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations, and recommends mitigation strategies.
  • Assists architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of customer security policy and enterprise security solutions.
  • Assesses and mitigates system security threats/risks throughout the program life cycle.
  • Contributes to the security planning, assessment, risk analysis, risk management, certification, and accreditation activities for system and network operations.
  • Develops Assessment and Authorization (A&A) documentation, providing feedback on completeness and compliance of its content.
  • Supports security authorization activities in compliance with the NIST Risk Management Framework (RMF) and customer processes for security engineering.
  • Creatively identifies ways to provide security compliance while minimally impacting day-to-day operations.
  • Identifies, reviews, and defines cybersecurity requirements that enable technical Architects / Systems Engineers and SMEs to secure hardware and software products.
  • Develops, reviews, and recommends security policy, guidance, training, and best practices that align its implementation across the mission acquisition lifecycle.
  • Interfaces with Program Managers (PMs), Mission Assurance Managers (MAMs), and customers.
  • Uses excellent presentation skills to convey security mission risks at program milestone reviews (SRR, PDR, CDR, etc.).
  • Maintains a regular and predictable work schedule.
  • Establishes and maintains effective working relationships within the department, the Strategic Business Units, Strategic Capabilities Units, and the Company. Interacts appropriately with others to maintain a positive and productive work environment.
  • Performs other duties as necessary.

Work Environment

  • On-site work requiring regular in-person engagement by working on-site five days each normally scheduled week in the primary work location.
  • Travel and local commute between company campuses and other possible non-company locations may be required.
  • Work is performed in an office, laboratory, production floor, or cleanroom, outdoors, or remote research environment.
  • May occasionally work in production work centers where use of protective equipment and gear is required.
  • May access other facilities in various weather conditions.

Requirements

  • BS degree or higher in Engineering or a related technical field is required plus 4 or more years related experience.
  • Each higher-level degree, i.e., Master’s Degree or Ph.D., may substitute for two years of experience. Related technical experience may be considered in lieu of education.
  • Degree must be from a university, college, or school which is accredited by an agency recognized by the US Secretary of Education, US Department of Education.
  • A current, active TS/SCI Polygraph security clearance is required.
  • DoD 8570 / DoD 8140 compliant security certification.
  • In-depth knowledge of information security principles, practices, technologies, and standards, including NIST Standards (800-37, 800-53), DISA STIGs, and CIS benchmarks.
  • Hands-on knowledge of cyber-enabling tools like Splunk, Tenable SC/ACAS, HBSS.
  • Familiarity with DevSecOps concepts and software security engineering principles.

Preferred Qualifications

  • CISSP-ISSEP certification.
  • Experience with Cloud-based security solutions, AWS preferred.
  • Experience with cybersecurity design principles applicable to Space Vehicles.
  • Experience with the Space Attack Research and Tactic Analysis (SPARTA) matrix.
  • Experience with the MITRE ATT&CK Framework.

Pay

Full-Time Salary Range: $97,008 - $164,914. Individual salaries are determined by a variety of factors including, but not limited to: business considerations, local market conditions, and internal equity, as well as candidate qualifications, such as skills, education, and experience.

Benefits

Regular employees scheduled to work 20+ hours per week are offered:

  • Health, dental, and vision insurance.
  • Health savings accounts.
  • A 401(k) savings plan.
  • Disability coverage.
  • Life and accident insurance.
  • Employee assistance program and a legal plan.
  • Paid time off, paid holidays, and other types of leave, including paid parental, military, bereavement, and any applicable federal and state sick leave.
  • Employee recognition program to receive monetary or non-monetary recognition awards.
  • Discounts on home, auto, and pet insurance.
  • Other incentives may be available based on position level and/or job specifics.

About BAE Systems Space & Mission Systems

BAE Systems, Inc. is the U.S. subsidiary of BAE Systems plc, an international defense, aerospace, and security company which delivers a full range of products and services for air, land, and naval forces, as well as advanced electronics, security, information technology solutions, and customer support services.

Headquartered in Boulder, Colorado, Space & Mission Systems is a leading provider of national defense and civil space applications, advanced remote sensing, scientific and tactical systems for government and commercial customers. We continually pioneer ways to innovate spacecraft, mission payloads, optical systems, and other defense and civil capabilities. Powered by endlessly curious people with an unwavering mission focus, we continually discover ways to enable our customers to perform beyond expectation and protect what matters most.

Similar jobs