Job DescriptionThis position is for a junior information system security engineer (ISSE) to provide security engineering support within BAE Systems, Inc. Space & Mission Systems (SMS) Sector. The ISSE supports ongoing programs by managing cyber requirements, validating technical security implementations, and supporting Assessment & Authorization efforts pursuant to gaining and/or maintaining system Authorizations to Operate (ATO).
What You'll Do:- Supports the development, review, and advisement of programs on the engineering design, development, and deployment of secure systems, networks, and applications.
- Assists in validating and verifying system security requirements definitions and analysis and establishes system security designs.
- Supports maintaining and promoting a comprehensive and holistic cybersecurity engineering view while addressing stakeholder security risks and concerns through the application of systems engineering skills.
- Support security incident response and investigation activities, including root cause analysis and remediation efforts, collaborating with cross-functional teams, including Engineering, IT, Operations, and Compliance.
- Perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations and recommend mitigation strategies.
- Assist in the identification and implementation of appropriate information security functionality to ensure uniform application of customer security policy and enterprise security solutions.
- Assess and mitigate system security threats/risks throughout the program life cycle.
- Contribute to the security planning, assessment, risk analysis, risk management, certification and accreditation activities for system and network operations.
- Develop Assessment and Authorization (A&A) documentation, providing feedback on completeness and compliance of its content.
- Support security authorization activities in compliance with the NIST Risk Management Framework (RMF) and customer processes for security engineering.
- Creatively identify ways to provide security compliance while minimally impacting day-to-day operations.
- Identify, review, and define cybersecurity requirements that enable technical Architects / Systems Engineers and SMEs to secure hardware and software products.
- Develop, review, and recommend security policy, guidance, training, and best practices that align its implementation across the mission acquisition lifecycle.
- May interface with Program Managers (PMs), IPT Leads and customer security stakeholders.
- Maintain a regular and predictable work schedule.
- Establish and maintain effective working relationships within the department, the Strategic Business Units, Strategic Capabilities Units and the Company. Interact appropriately with others in order to maintain a positive and productive work environment.
- Perform other duties as necessary.
On-Site Work Environment: This position requires regular in-person engagement by working
on-site five days each normally scheduled week in the primary work location. Travel and local commute between company campuses and other possible non-company locations may be required.
Working Conditions: - Work is performed in an office, laboratory, production floor, or cleanroom, outdoors or remote research environment.
- May occasionally work in production work centers where use of protective equipment and gear is required.
- May access other facilities in various weather conditions.
Required Skills and Education- BS degree or higher in Engineering or a related technical field is required plus 2 or more years related experience.
- Each higher-level degree, i.e., Master's Degree or Ph.D., may substitute for two years of experience. Related technical experience may be considered in lieu of education. Degree must be from a university, college, or school which is accredited by an agency recognized by the US Secretary of Education, US Department of Education.
- A current, active TS/SCI CI Polygraph security clearance is required.
- DoW 8570 / DoW 8140 compliant security certification.
- Knowledge of information security principles, practices, technologies, and standards, including NIST Standards (800-37, 800-53), DISA STIGs, and CIS benchmarks.
- Hands-on knowledge of cyber-enabling tools like Splunk, Tenable SC/ACAS, HBSS.
- Familiarity with DevSecOps concepts and software security engineering principles.
#LI-MT1
Preferred Skills and Education- CISSP-ISSEP certification.
- Experience with Cloud-based security solutions, AWS preferred.
- Experience with the MITRE ATT&CK Framework.
This position will be posted for at least 5 calendar days. The posting will remain active until the position is filled, or a qualified pool of candidates is identified.
Multiple positions may be available on this opening.