Job DescriptionBecause of the need for consistent, in-person collaboration and/or the requirement to perform all work onsite due to the nature of this particular role, it will be performed full- time on site. This means work will be conducted on location at a BAE Systems facility 100% of the time.
In Command, Control, Communications, Computers, Intelligence, Surveillance, and Reconnaissance (C4ISR) Systems, you'll help develop systems that sense, control, exploit and disseminate actionable information to warfighters supporting a variety of missions.
Advance your career as a Cybersecurity professional with BAE Systems, supporting and protecting information systems critical to national security at one of the leading companies in Aerospace and Defense. Develop your Cybersecurity career through hands on application, work with seasoned professionals, and a training and development plan designed to grow your skills in a fast paced, team-based environment.
If you are looking to learn, influence, and help develop top cyber technologies, applications, and processes that protect and service our customers wherever they may be air, land, and sea come join our award-winning security team at Electronic Systems (ES).
Specific job responsibilities include, but are not limited to:
- Adherence to all aspects of a rigorous Risk Managed Framework (RMF) compliance program as stipulated by NISPOM/DAAG, JSIG, ICD 503, STIGs and associated NIST publications.
- Ability to advance standardization, automation, and resilience capabilities across the organization while aligning with business priorities and risk tolerance
- Able to multitask and oversee programs spanning multiple disciplines, facilities, and Government Authorities.
- Ability to manage multiple Cybersecurity teams as well as collaborate with Business Area lead[SF1.1]s, other product line cybersecurity teams, security disciplines (industrial security/physical security, special programs security, etc.), IT product line leads, program personnel, and government security representatives.
- Ability to work with leadership at various levels and participate in the evaluation and recommendation of new security tools, techniques, and technologies to ensure they align with SecureIT strategy[SF2.1] and modernization initiatives.
- Demonstrated ability to prepare for and support government inspections/assessments
- Able to provide leadership, guidance, and training to a team of cybersecurity professionals.
- Be a cybersecurity Subject Matter Expert (SME) supporting a specific Business Product Line.
Required Skills and Education- Active US Secret Clearance and ability to obtain Top Secret Clearance
- IAM Level III certification commensurate with DoD 8570.1M / 8140.03 requirements
- High level of personal motivation and initiative to learn and acquire new skills, and adapt seamlessly to an ever-changing security environment
- Customer focused, excellent communicator and ability to work with limited supervision.
- Strong organizational skills
- Strong background in information technology with a clear understanding of the challenges of cybersecurity
- Ability to build and mentor a high performing cybersecurity team
- Experience developing, implementing, updating and enforcing companywide information assurance policies and procedures
- Demonstrated ability to run and maintain the entire information assurance program for more complex efforts or areas
- Implementation of Contingency and Incident Response Plan and subsequent experience with addressing cyber related investigations/incidents.
- Serve as the primary Cybersecurity Business Area focal point for a large number of complex effort(s) and/or area(s)
Preferred Skills and Education- Working knowledge of system functions, security policies, technical security safeguards, and operational security measures.
- In-depth knowledge/expertise with the majority of the following tools: Splunk, Nessus; SCAP, ACAS, E-Stig, other Security Information and Event Management (SIEM) Tools; Antivirus such as Trellix ; SIPR, eMASS and Xacta databases
- Translate operational requirements into technical requirements and architectures needed to meet program objectives
- Experience with auditing (preferably Splunk) and certifying/hardening compliance of various systems: Windows, Linux, Network Devices and peripherals.
- Experience with the reviewing, creation, and remediation of mitigation reports from compliance and vulnerability scanning tools
- Experience with overseeing accuracy and completion of Continuous Monitoring activities, self-inspections, corrective action plans, and Plan of Action and Milestones (POA&M)
- Experience with Contingency and Incident Response Plan development and implementation
- Experience conducting all aspects of a self-inspection, Staff Assist Visits, etc