Information Systems Security Engineer

Aerospace & Defense
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Active DoD TOP SECRET clearance with SCI eligibility at application time
  • Bachelor's Degree with 4-6 years of IT/RMF/GRC experience; Master’s degree equivalent to 4 years experience
  • Meets DoD 8140 Mid-Level Cybersecurity Analyst qualifications (CySA, Sec+, etc.)
  • Reports to designated work location in Colorado Springs as required by customer needs
  • Experience with ITIPS, eMASS, FISMA, IASE, Xacta preferred

Responsibilities

  • Build and maintain cybersecurity baselines via eMASS or equivalent
  • Review and update enclave documentation for ISSM approval
  • Identify and maintain RMF required artifacts for compliance
  • Ensure accurate system documentation reflects current baselines
  • Provide quarterly evaluations of system's RMF compliance
  • Conduct annual security reviews and validate control compliance
  • Participate in technical meetings to align cybersecurity requirements

Benefits

  • Comprehensive health insurance options
  • Flexible spending and health savings accounts
  • Retirement savings plans
  • Life and disability insurance programs
  • Paid and unpaid time off supports work-life balance
Full Job Description
Overview

The Space and Intelligence Division provides professional services to the US Space Force, Combatant Commands, Intelligence Community, and NASA. Our work includes enterprise architectural assessments, systems engineering and integration, test, planning and execution, cost estimating and analysis, acquisition support, and cybersecurity.  We are trusted partners developing approaches and concepts to meet emerging high priority needs, assessing cutting-edge technologies, and supporting capabilities for our National Defense.  Come join the fastest growing Division at Systems Planning and Analysis, Inc.!

 

The Space Systems Group (SSG), part of SPA’s Space and Intelligence Division, provides timely and objective assessments and recommendations integrating technical, operational, programmatic, policy and business analysis. We focus on our key clients in the Space community including the US Space Force’s Space Systems Command (USSF/SSC), one of the three designated Field Commands under USSF. We work tirelessly to provide integrated solutions based on information and communications throughout the chain of command.  We provide clear and consistent analysis and recommendations which are aligned to strategic and leadership goals while balancing the ability to  execute on time and on budget within the technical communities. Come join an organization responsible for being a key enabler of Spacepower!

 

SPA has an immediate need for an Information Systems Security Engineer.

Responsibilities

This is an exciting opportunity to support the United States Space Force (USSF). The Space Systems Command has the collective USSF mission responsibility for the development, deployment, maintenance and sustainment of space systems providing early missile warning capability; environmental sensing; precision navigation, guidance and timing; nuclear event detection; space launch capability; national and military satellite communications capabilities; launch range and network systems; advanced systems; and technology development programs. This position will work in close collaboration with the Information Systems Security Manager (ISSM) and Information Systems Owner (ISO) to ensure security posture is met and maintained, develops security policies, procedures, plans, and all other evidence of compliance with various security controls. Creates and maintains RMF documentation to include Enterprise Mission Assurance Support Service (eMASS) and Information Technology Investment Portfolio Suite (ITIPS) database entries with System Security Plans (SSP), Security Assessment Reports (SAR), Plans of Action & Milestones (POA&M), all other artifacts and documentation tied to the NIST processes. Provide support to maintain a strong cybersecurity posture for the system until its disposal.

Responsibilities

  • Build, maintain, and track system’s cybersecurity baselines via eMASS or equivalent, IAW cybersecurity policies, guidance and plans.
  • Review, assess, create, and update enclave documentation in eMASS and any Configuration Management (CM) system for the ISSM review and approval such as: Security Plan, Security Assessment Plan, Category selection checklist, control results, and POA&Ms.
  • Identify, collect, review, and maintain RMF required artifacts IAW cybersecurity policies, guidance and plans.
  • Ensure accurate system documentation and configuration logs are maintained to reflect current and prior configuration baselines.
  • Provide written evaluations portraying system progress on RMF compliance IAW cybersecurity guidance (one evaluation for each system per quarter).
  • Maintain cybersecurity data for systems registered in the ITIPS IAW FISMA requirements.
  • Conduct and/or report annual FISMA security reviews, contingency test completion dates, and validation of cybersecurity control compliance, IAW cybersecurity guidance, the organizational cybersecurity strategy, and POA&M.
  • Conduct annual control validations (ACVs) for all NC3 systems IAW AF Global Strike Command (AFGSC) cybersecurity guidance and for all non-NC3 systems in a similar manner, but in accordance with SMC/ECP policies and schedule.
  • Create and maintain mission common control packages and serve as the common control provider for each mission systems.
  • Create and maintain Authority-to-Connect (ATC) guest system packages in eMASS for non-USSF systems connected to SMC/ECP systems.
  • Ensure the required Cybersecurity functional activities and actions during the systems’ O&S phase are conducted IAW Cybersecurity related laws and regulations such as the National Cybersecurity Protection Act, FISMA, OMB A1-30 mandate, and EO 13636.
  • Improving Critical Infrastructure Cybersecurity and Resilience including policies, standards, special publications, instructions and guidance from the DoD, Military, NIST, CNSS, Defense Information Systems Agency (DISA), and Department of the AF (DAF).
  • Participate in the system’s IPTs and sustainment contractor meetings/teleconferences, change control boards (CCBs) and working groups (WGs) to ensure the continued alignment of cybersecurity requirements in the technical baselines, the system security architecture, information flows, design, and the security controls.
  • Evaluate system’s sources of changes such as Deficiency Reports (DRs), Problem Reports (PRs), Change Requests/Proposals (CRs/CPs), Request For Change (RFC), and AF Form 1067s; determine the security impacts of proposed or actual changes to the system, environment, threats, and vulnerabilities; and if any, update all needed RMF artifacts to reflect the changes/revisions.
  • Review and provide inputs to modification packages, program/system documents and support agreements updates, and communications and network infrastructure upgrades to ensure proper cybersecurity configuration modification management and planning support are implemented.
  • Review system’s test plans and test results and if necessary observe system testing for security control implementation IAW cybersecurity policies, guidance and plan.
  • Document all findings. Perform security impact analysis on any system change and appropriately prepare letters of assurance, security impact letters, and risk assessment letters to include exceptions, deviations, or waivers to cybersecurity requirements when applicable.
  • Monitor and adhere to the system’s A&A schedule deadlines IAW the Program Office’s Cybersecurity Plan and IPT’s schedule.
  • Review annually and provide recommended updates to program cybersecurity policies and plans IAW cybersecurity guidance.
  • Review and provide advice on RMF related memorandums of agreements/ memorandums of understanding/ service level agreements/ interconnection service agreements (MOA/MOU/SLA/ISA) for RMF compliance IAW cybersecurity policies, guidance and plans.
  • Assist with the cybersecurity vulnerability management plan and risk assessment capability.
  • Receive and review ACAS and SCC reports from the sustainment contractor for each system quarterly and characterize risk for each system semi-annually.
Qualifications

Required Qualifications

  • Active DoD TOP SECRET clearance with SCI eligibility at time of application
  • Bachelor's Degree with 4 - 6 years of experience in IT/RMF/GRC and leadership; Master's degree equivalent to 4 years experience 
  • Meets DoD 8140 Cybersecurity Analyst Mid-Level Education, Training or Certification qualifications. (CySA, Sec+, etc.)
  • Reports to designated work location in Colorado Springs up to full time, based on the needs of the customer

Preferred Qualifications

  • Experience with ITIPS
  • Experience with eMASS
  • Experience with FISMA
  • Experience with IASE
  • Experience with Xacta

 

 

Pay Range InformationAt SPA, we strive to deliver a robust total compensation package that will attract and retain top talent. Elements of the compensation package include competitive base pay and variable compensation opportunities. SPA provides eligible employees with an opportunity to enroll in a variety of benefit programs, generally including health insurance, flexible spending accounts, health savings accounts, retirement savings plans, life and disability insurance programs, and a number of programs that provide for both paid and unpaid time away from work. The specific programs and options available to any given employee may vary depending on eligibility factors such as geographic location, date of hire, etc. Please note that the salary information shown below is a general guideline only. Salaries are commensurate with experience and qualifications, as well as market and business considerations. Colorado, Pay Transparency Salary range: USD $85,000.00/Yr. - USD $100,000.00/Yr.

About Systems Planning And Analysis, Inc.

Systems Planning And Analysis, Inc. Careers

Joining Systems Planning And Analysis, Inc. presents an unparalleled opportunity to advance a career in a leading-edge professional environment that is committed to innovation and leadership. This company is renowned for its strategic role in providing integral analysis and planning solutions across various sectors.

Explore Job Opportunities

Systems Planning And Analysis, Inc. offers a variety of job opportunities that cater to a range of skills and experiences. Whether one is a seasoned professional or a recent graduate, there is a position that can fit one's career aspirations and expertise. The company values diversity and strives to create an inclusive culture where every team member can thrive.

Internship Programs

For those starting their career journey, Systems Planning And Analysis, Inc. provides robust internship programs designed to foster growth, enhance skills, and offer real-world experience in a supportive and dynamic environment. Internships are a stepping stone to full-time employment and offer invaluable networking opportunities within the company.

Professional Growth and Development

Commitment to professional growth is a cornerstone of Systems Planning And Analysis, Inc. Employees are encouraged to pursue continuous improvement through various training programs, including leadership development and diversity training. The company supports career advancement with resources and tools that help individuals expand their knowledge and take on new challenges.

Benefits and Culture

Systems Planning And Analysis, Inc. is dedicated to supporting its employees with comprehensive benefits designed to promote a healthy work-life balance. The benefits package includes health, dental, and vision insurance, as well as competitive retirement plans. The company culture is built on a foundation of respect and integrity, fostering an environment where innovation and collaboration are paramount.

Hiring Process

The hiring process at Systems Planning And Analysis, Inc. is designed to be transparent and efficient. Candidates can expect a thorough interview process where they can showcase their skills and learn more about the company's operations and values. Interested candidates are encouraged to submit a detailed resume and cover letter through the Systems Planning And Analysis, Inc. careers page.

Networking and Career Opportunities

Systems Planning And Analysis, Inc. actively encourages its employees to engage in networking within the industry to enhance their career prospects. Regular company events and professional meet-ups provide platforms for employees to connect with industry leaders and peers.

Join the Team

Systems Planning And Analysis, Inc. is continuously searching for passionate, curious, and innovative team players who are ready to make a significant impact. Explore the open positions that match your skills and interests on the Systems Planning And Analysis, Inc. jobs portal.

Stay Connected

Keep up to date with career tips, insider perspectives, and industry-leading insights that can be put to use today—all from the people who work at Systems Planning And Analysis, Inc.

Job Alert Emails

Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding opportunities that await at Systems Planning And Analysis, Inc.
Learn more about Systems Planning And Analysis, Inc.

Similar Jobs

More Jobs at Systems Planning And Analysis, Inc.

More Aerospace & Defense Jobs

Find similar Information Systems Security Engineer jobs: