System Engineer- Cyber Security Engineering Focus
This position plays a hands-on role securing systems that support critical Defense and Intelligence missions. Focused on applying risk management frameworks, engineering security controls, and maintaining system authorizations for cloud and on-prem environments, you'll work closely with system engineers, administrators, and program teams to ensure compliance with DoD and NIST requirements. Esri offers a Relocation Assistance Program and can provide support with relocating to the St. Louis, MO area for this role.
Responsibilities
- Apply RMF processes to support system Assessment & Authorization (A&A), including control selection, implementation, assessment, and continuous monitoring
- Develop, review, and maintain security documentation such as SSPs, POA&Ms, SARs, and ATO artifacts in tools such as XACTA or eMASS
- Conduct vulnerability assessments and compliance scans (such as ACAS) and track remediation of findings and IAVM requirements
- Implement and validate security controls aligned with NIST 800-53, CNSSI 1253, and related DoD guidance
- Support system hardening, patching, and configuration management in compliance with STIGs for Linux, Windows, and network devices
- Monitor systems for security events and support incident response and risk mitigation activities
- Assess security impacts of system changes and support configuration control boards (CCBs)
- Collaborate with system engineers, administrators, and DevSecOps teams to integrate security throughout the system lifecycle
- Provide cybersecurity risk input to program leadership, Authorizing Officials (AOs), and stakeholders
Requirements
- 8+ years of professional experience in a similar position, supporting similar responsibilities
- Professional experience with RMF, A&A, POA&M, and ATO documentation (XACTA/eMASS)
- Hands-on experience with vulnerability scanning and compliance tracking (ACAS, IAVM)
- Experience securing Linux and Windows systems, STIGs, patching, and system hardening
- Knowledge of NIST 800-series publications and incident response processes
- DoD 8570 IAT Level II or higher certification (such as Security +, CySA +, CISSP)
- Strong analytical, communication, and collaborative skills
- US citizenship with Active or Current (within 2 years of active) Top Secret Security Clearance with SCI eligibility
- Bachelor's degree in Computer Science, Cybersecurity, Information Technology or STEM related field
Qualifications
- Scripting or development experience (Python, Java, React)
- DevSecOps tools and pipeline experience
- Experience with Linux (Red Hat/CentOS), databases, web apps, or big data platforms
- Familiarity with Agile environments and tools (Jira, Confluence)
- Experience with NIST SP 800-171 and System Security Engineering (SSE)
- Master's degree in Computer Science, Cybersecurity, Information Technology or STEM related field
Benefits
- Industry-leading health and welfare benefits: medical, dental, vision
- Basic and supplemental life insurance for employees (and their families)
- 401(k) and profit-sharing programs
- Minimum accrual of 80 hours of vacation leave
- Twelve paid holidays throughout the calendar year
- Opportunities for personal and professional growth
Pay
A reasonable estimate of the base salary range is $120,640 USD - $197,600 USD. Compensation decisions and the base range take into account skill sets, experience, training, licensure, certifications, and business needs.
About the Company
At Esri, diversity is more than just a word on a map. We believe in having a diverse workforce unified under our mission of creating positive global change. We understand that diversity, equity, and inclusion is an ongoing process and are committed to learning, growing, and changing our workplace so every employee can contribute to their life’s best work. Our commitment extends to global communities through positive change with GIS technology.