Level 3 Communications, Inc

Information Security Systems Engineer

Level 3 Communications, Inc$106K — $197K *
Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with 6+ years of relevant experience, or a graduate degree with 4+ years of experience, or 10+ years of equivalent work experience in lieu of a degree.
  • Active TS/SCI security clearance required, with ability to obtain and maintain SAP clearance after hire.
  • DoD 8140.03 Level 3 or 4 certification essential.

Responsibilities

  • Perform incident response and cyber threat identification, including malware analysis and supply chain risk management assessments.
  • Utilize NIST Risk Management Framework to develop security documentation, including System Security Plans and Continuous Monitoring Plans.
  • Implement and assess security controls, including writing security categorization memorandums and defining security control baselines.
  • Assist in systems/software engineering tasks, such as data flow diagram creation and Static Application Security Testing in a DevSecOps environment.
  • Manage systems/security architectures, focusing on vulnerability management and remediation strategies in diverse environments.
  • Configure and utilize defense and assessment tools for both on-premises and cloud systems, ensuring proper security boundaries are defined and maintained.
  • This role requires 100% onsite work with no remote options available.

Benefits

  • Health and disability insurance.
  • 401(k) match options.
  • Flexible spending accounts.
  • Education assistance and parental leave.
  • Paid time off and company-paid holidays.
Full Job Description
Job Title: Information Security Systems Engineer (ISSE)

Job Code: 38251

Job Location: Chantilly, VA

Job Schedule: 5/8 Monday - Friday

Job Description:

The successful candidate will support a highly motivated engineering team in defining, designing, implementing, documenting, testing and sustaining security solutions on National Security Systems, or other systems engineered for our government customers, using current standards within National Institute of Standards & Technology (NIST) Risk Management Framework, Special Publications 800-37, 800-53, 800-171, and other NIST publications; Committee on National Security Systems Instruction (CNNSI) 1253, Joint SAP Implementation Guide (JSIG), and Federal Information Processing Standards (FIPS) to certify and achieve system accreditations. The successful candidate will work with system developers or commercial product vendors in the design and evaluation of state-of-the-art secure systems, networks, and database products, using methods such as encryption technology, vulnerability analysis and security management.

Essential Functions:

  • Perform incident response cyber threat identification, incident response support, defensive cyber operations coordination, malware analysis, supply chain risk management assessments per NIST SP 800-161, vendor provenance, counterfeit detection.
  • Exercise skills in NIST Risk Management Framework (RMF) and all related NIST publications, to include writing System Security Plans, Security Control Traceability Matrix, Continuous Monitoring Plan, Security Assessment Plans & Procedures, Security Concept of Operations, Plan of Action and Milestones.
  • Perform skills in implementing/assessing security controls, to include writing system security categorization memorandum, recommending appropriate security control overlays, define security control baseline based on defined system security categorization and approved security overlays, and apply security controls to computing/network nodes and verify implementation of security controls.
  • Assist in systems/software engineering functions, to include creation of data flow diagrams, interface control documents, perform trade studies, and Static Application Security Testing (SAST) for Application Security and Development Secure Technical Implementation Guide (STIG) compliance using tools such as Fortify/Coverity and Gitlab as part of a DevSecOps Continuous Integration/Continuous Deployment (CI/CD) Pipeline, and generation of summary reports.
  • Define/manage systems/security architectures including system security boundaries, vulnerability management and risk mitigation and remediation strategies within networks, systems, applications and new technology initiatives (hardware, software, firewalls, intrusion detection systems, anti-virus systems and software deployment tools); and Infrastructure/Platform/Software-as-a-Service (IaaS/PaaS/Saas) implementations in cloud environments.
  • Define/manage systems/security architectures including system security boundaries in on-premises data center systems and ultimately deploy to secure cloud-based system, to include configuration and use of defense and assessment tools specific to each environment type.
  • This position is performed 100% onsite and cannot be performed remotely.


Qualifications:

  • Bachelor's Degree and a minimum of 6 years of prior relevant experience; Or, Graduate Degree and a minimum of 4 years of prior related experience; Or, in lieu of a degree, minimum of 10 years of prior related experience.
  • Must have active TS/SCI security clearance. Ability to obtain and maintain Special Access Program (SAP) clearance after hire is required.
  • DoD 8140.03 Level 3 or 4 certification.


Preferred Additional Skills:

  • Perform Model Based System Engineering (UML, SysML, UAF).
  • Confugure/operate vulnerability analysis tools such Tenable NESSUS Security products.
  • Develop dashboards, configure rules and operate/administer SEIM/audit reduction tools (e.g., Splunk).


In compliance with pay transparency requirements, the salary range for this role in Virginia state is $106,500-$197,500. This is not a guarantee of compensation or salary, as final offer amount may vary based on factors including but not limited to experience and geographic location. L3Harris also offers a variety of benefits, including health and disability insurance, 401(k) match, flexible spending accounts, EAP, education assistance, parental leave, paid time off, and company-paid holidays. The specific programs and options available to an employee may vary depending on date of hire, schedule type, and the applicability of collective bargaining agreements.

#LI-CG1

Similar Jobs

More Jobs at Level 3 Communications, Inc

More Aerospace & Defense Jobs

Find similar Information Security Systems Engineer jobs: