Scientist, Information Security Systems Engineering
About the role
L3Harris is seeking a Senior Cybersecurity Engineer to lead cybersecurity strategy and execution for the MOSSAIC Portfolio. This role involves leading portfolio-level cybersecurity strategy and execution, managing RMF and CMMC efforts, overseeing vulnerability management, and championing DevSecOps best practices.
Responsibilities
Lead portfolio-level cybersecurity strategy and execution for all security-related activities across the MOSSAIC Portfolio.
Provide technical architectural oversight on the design, development, and integration of cybersecurity solutions that meet mission needs while maintaining compliance with DoD standards, NIST RMF, and CMMC frameworks.
Partner with cross-functional teams to identify, develop, and integrate cybersecurity policies, principles, requirements, and architectures across system lifecycle phases.
Develop and maintain long-range cybersecurity risk burn-down roadmaps that systematically address technical debt and vulnerabilities while balancing program schedule and resource constraints.
Manage RMF authorization and accreditation (A&A) efforts, guiding systems through RMF Steps 1-4, and prepare Certification and Accreditation documentation using multiple standards including DoD 8510 and CNSSI 1253.
Drive CMMC implementation across portfolio systems, ensuring certification standards are met.
Lead adoption of Zero Trust Architecture (ZTA) principles across system design and operations, ensuring least-privilege access, continuous verification, and assume-breach security postures are embedded in technical solutions and operational practices.
Own vulnerability management strategy and execution, including tracking vendor-released security patches, Common Vulnerabilities and Exposures (CVEs), Information Assurance Vulnerability Management (IAVMs), and hardware/software obsolescence.
Oversee configuration and use of cyber defense and vulnerability assessment tools including Assured Compliance Assessment Solution (ACAS).
Ensure DISA SRGs and STIGs are applied to system configurations with appropriate rigor and documented evidence for assessment.
Oversee Static Application Security Testing (SAST) processes for Application Security and Development STIG compliance using tools like Fortify.
Champion DevSecOps best practices, partnering with development teams to embed security testing into automated pipelines.
Serve as Control Account Manager (CAM) for cybersecurity work packages within the program's Earned Value Management System (EVMS).
Conduct portfolio oversight to identify opportunities for staffing efficiencies, prevent cost overruns, optimize resource allocation within budget constraints, and make strategic workforce decisions that balance technical capability with financial performance.
Develop Basis of Estimate (BOE) for cybersecurity engineering efforts, translating security requirements into labor estimates, resource forecasts, and timeline projections that support program planning and customer negotiations.
Lead security engineering activities including requirements development, design, test planning, configuration management, and maintenance of information systems and data.
Represent portfolio cybersecurity needs, concerns, and requirements directly to customers, ensuring their security priorities are understood, documented, and addressed with appropriate technical fidelity throughout the system lifecycle.
Chair and participate in Configuration Working Groups (CWGs), Cybersecurity Working Groups, and Engineering Review Boards (ERBs).
Influence cross-functional stakeholders to adopt security best practices, accept new concepts, and implement process improvements.
Lead, mentor, and develop cybersecurity discipline talent, fostering a culture of technical excellence, continuous learning, and security-first thinking.
Requirements
Education: Bachelor's Degree and minimum 12 years of prior relevant experience, OR Graduate Degree and a minimum of 10 years of prior related experience, OR In lieu of a degree, minimum of 16 years of prior related experience.
Active SECRET security clearance required with ability to obtain TS/SCI.
DoD 8140.03 IAT Level 3 or IASAE Level 2 certification required.
Preferred Additional Skills:
Model-Based Systems Engineering (MBSE) and Digital Engineering methodologies experience.
Hands-on experience with Windows and Linux system administration and security hardening.
Deep understanding of engineering processes, concepts, and information security systems engineering principles (NIST SP 800-160 Volume 1).
System test and evaluation methods and RMF assessment methodology expertise.
Demonstrated experience with Agile system development methodologies, CI/CD toolchains, and DevSecOps automation frameworks.
Understanding of system vulnerabilities, exploitation techniques, and offensive security tradecraft.
Experience working with U.S. Space Force Combat Forces Command (CFC) Mission Delta 2 (MD2).
Top Secret / SCI clearance desired.
Benefits
L3Harris offers a variety of benefits including health and disability insurance, 401(k) match, flexible spending accounts, EAP, education assistance, parental leave, paid time off, and company-paid holidays.
Pay
The salary range for this role in Colorado state is $133,000-$247,000. This is not a guarantee of compensation or salary, as final offer amount may vary based on factors including but not limited to experience and geographic location.
Schedule
This position is performed 100% on-site and cannot be accomplished remotely.