SAIC

Information Systems Security Engineer

SAIC$160K — $200K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with 14+ years, or Master's with 12+ years, or PhD/JD with 9+ years of relevant experience.
  • Proven track record of developing Risk Management Framework (RMF) products and system accreditations.
  • Experience interfacing with ISSOs and ISSMs, including document reviews and risk assessment.
  • Subject matter expertise in vulnerability management, scanning tools, and security compliance.
  • Skilled in crafting evidence documents and assessing NIST 800-53 / JSIG security controls.
  • Ability to independently develop RMF A&A documentation for obtaining Authority to Operate (ATO).
  • U.S. citizenship with an active TS/SCI clearance.

Responsibilities

  • Define and implement cybersecurity architecture for multi-domain cloud environments.
  • Collaborate with cloud infrastructure teams using Agile processes for solution design.
  • Develop RMF Body of Evidence and system security plans for cloud operations.
  • Employ best practices in security controls, architecture, and software engineering methodologies.
  • Test and validate implementation of system security requirements across infrastructure.
  • Support A&A activities to secure Authority to Operate (ATO) for security certifications.
  • Mentor and oversee team members as required.

Benefits

  • Ongoing application acceptance with no set deadline.
  • On-site work opportunity in San Diego, CA.
Full Job Description
Job Description

Description

We are seeking a highly skilled Information Systems Security Engineer. This position is on-site in San Diego, CA.

Cybersecurity Engineer
Define, communicate, and implement cybersecurity architecture and administration processes for cloud environments across multiple network domains. Collaborate across our cloud infrastructure delivery team and with stakeholders using an Agile process to ensure design, implementation, verification, and continuous monitoring of cloud solutions across multiple domains. Develop Risk Management Framework (RMF) Body of Evidence artifacts, including system security plans and cybersecurity concept of operations documents operating within Cloud environments in alignment with existing RMF packages. Experience in security focused system design that can be scalable across multiple domains while accounting for security requirements across multiple system architectures. Employs best practices when implementing security controls, secure architecture and design to include software engineering methodologies, security engineering principles, secure design and secure coding techniques along with the control selection, configuration and operation of applicable tools, including static analysis and dynamic analysis together with supporting processes. This includes testing of the system security requirements implementation across infrastructure to ensure security control validation as well as functionality. Support assessment and authorization activities to achieve and maintain Authority to Operate (ATO)s. Responsible for the coordination, generation and oversite of RMF documentation for the successful accreditation of multiple cloud environments including the Cyber Security Strategy and Continuous Monitoring Plans as well as overall program lifecycle RMF requirements to include but not be limited to patch management, supply chain, change and defect management. Mentor and supervise team members, as needed.

Qualifications

Typical Education and Experience:
  • Bachelors and fourteen (14) years or more experience; Masters and twelve (12) years or more experience; PhD or JD and nine (9) years or more experience.
  • Multiple years of experience with developing Risk Management Framework (RMF) products and working through system accreditations to ensure RMF implementation across multiple environments
  • Experience in interfacing with Information System Security Officers (ISSO) and Information System Security Managers (ISSM), including reviewing documentation, systems security plans (SSPs), risk assessment reports, accreditation packages, and Plan of Actions and Milestones (POA&Ms)
  • Experience with providing subject matter expertise in a cyber domain, including vulnerability management and assessment, scanning tools, and assessing system compliance with security controls
  • Experience with reviewing policy, planning compelling evidence documents, and writing test results for NIST 800-53 / JSIG Security Controls and Assessment Procedures
  • Ability to work independently to develop RMF A&A documentation and artifacts to obtain RMF Authority to Operate (ATO)
  • U.S. citizenship and an active TS/SCI clearance

Target salary range: $160,001 - $200,000. The estimate displayed represents the typical salary range for this position based on experience and other factors.

Overview

SAIC accepts applications on an ongoing basis and there is no deadline.

About SAIC

Science Applications International Corporation (SAIC) is a technology integrator in the technical, engineering, intelligence, and enterprise information technology markets. SAIC has approximately 26,000 employees and operates in more than 70 countries. The company was founded in 1969 and is headquartered in Reston, Virginia. SAIC provides services to the U.S. government, including the Department of Defense, the intelligence community, and civilian agencies. The company also serves commercial customers in the healthcare, energy, and financial services sectors.
Learn more about SAIC
Size
26,000 employees
Market Cap
$6 billion
Industry
Net Income
$206 million
Founded
1969
5 Year Trend
+10.7%
Revenue
$6.8 billion
NASDAQ

Similar Jobs

More Jobs at SAIC

More Information Technology Jobs

Find similar Information Systems Security Engineer jobs: