Senior Specialist, Info Security Systems Engineer Secret - Boulder, CO jobs in United States
cer-icon
Apply on Employer Site
company-logo

L3Harris Technologies · 2 weeks ago

Senior Specialist, Info Security Systems Engineer Secret - Boulder, CO

L3Harris Technologies is a leading company in the defense industry focused on delivering innovative technology solutions. The Senior Specialist, Information Security Systems Engineer will apply security engineering methods to ensure the architecture and integration of secure systems and networks, working closely with government customers to meet their security needs throughout the system lifecycle.

CommercialInformation TechnologyNational Security
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Applies current systems security engineering methods, practices and technologies to the architecture, design, development, evaluation and integration of systems and networks to maintain system security
Works closely with Government customers to ensure that the security protection needs, concerns and requirements are defined and implemented with appropriate fidelity and rigor, early and in a sustainable manner throughout the life cycle of system that will allow for the security authorization of the system of interest
Works with systems developers •or• commercial product vendors in the design and evaluation of state-of-the-art secure systems, networks, and database products
Uses methods such as encryption technology, vulnerability analysis and security management
Responsible for integration of multiple methods into a cohesive system security perimeter and environment and the policies and procedures necessary to monitor and maintain such an environment
Will prepare Certification and Accreditation documentation, using multiple standards, to achieve security authorization of supported systems
Represents program security needs, concerns and requirements at customer meetings
Experience in writing and managing RMF body of evidence documents (e.g., System Security Plan (SSP), Security Compliance Traceability Matrix (SCTM), Risk Assessment Report (RAR), Continuous Monitoring (ConMon) Plan, and Security Assessment Plans and Procedures (SAPP)
Experience with A&A package processing in eMASS and Xacta
Experience in DoD software selection and approval processes for COTS, GOTS and FOSS
Experience in the application of DISA SRGs and STIGs
Experience in the implementation and use of cybersecurity tools (ACAS, SCAP, etc.)
Support security engineering activities, including basis of estimate development, requirements development, design, test, configuration management and maintenance of information systems and data
Assist program security in the development of policies and procedures for emerging security technologies
Perform functional analysis, timeline analysis, detailed trade studies, requirements derivation and allocation, and interface definition studies to translate customer Information Security requirements into hardware and software specifications
Provide Information Assurance (IA) technical leadership for development teams of new multi-discipline (mechanical, electrical, software, RF, etc.) products
Responsible for developing security control selections, data flow diagrams, internal requirements, CONOPs and interface control documents from customer / product requirements
Expertise in security requirements, documentation, and risk mitigation strategies
AWS cloud security knowledge including architecture, design, deployment, and management of cloud security technologies
Strong familiarity with Linux
Familiarity with security related tools – SIEM, malware, HIPS, etc
Identify security risks, threats and vulnerabilities of networks, systems, applications and new technology initiatives (hardware, software, cross-domain solutions, cryptographic devices, firewalls, intrusion detection systems, anti-virus systems and software deployment tools)
Support vulnerability assessment activities as required
Support the evaluation, qualification, testing and delivery of security architecture improvement, obsolescence replacement and vulnerability response projects
Ability to work individually or as part of a cybersecurity team. Must be able to lead and provide direction based on program and customer requirements and compliance
Possess excellent speaking abilities and skills to brief leadership and customers
Possess ability to conduct research on security and other applicable topics as needed as the cybersecurity lead
Must be a self-starter that is able to understand requirements and develop plans and articulate needs to meet compliance and requirements
This is an On-Site Position
Travel up to 25% to potential system deployment locations

Qualification

RMF documentation managementCybersecurity tools implementationAWS cloud securitySecurity risk assessmentDoD software approval processesLinux familiarityScripting experiencePolicy developmentResearch skillsTechnical leadership

Required

Bachelor's Degree and minimum 6 years of prior relevant experience, or
Graduate Degree and a minimum of 4 years of prior related experience or
In lieu of a degree, minimum of 10 years of prior related experience
Must have active Secret security clearance, TS/SCI preferred
DoD 8140.03 IAT Level 3 certification
Experience in writing and managing RMF body of evidence documents (e.g., System Security Plan (SSP), Security Compliance Traceability Matrix (SCTM), Risk Assessment Report (RAR), Continuous Monitoring (ConMon) Plan, and Security Assessment Plans and Procedures (SAPP)
Experience with A&A package processing in eMASS and Xacta
Experience in DoD software selection and approval processes for COTS, GOTS and FOSS
Experience in the application of DISA SRGs and STIGs
Experience in the implementation and use of cybersecurity tools (ACAS, SCAP, etc.)
Support security engineering activities, including basis of estimate development, requirements development, design, test, configuration management and maintenance of information systems and data
Assist program security in the development of policies and procedures for emerging security technologies
Perform functional analysis, timeline analysis, detailed trade studies, requirements derivation and allocation, and interface definition studies to translate customer Information Security requirements into hardware and software specifications
Provide Information Assurance (IA) technical leadership for development teams of new multi-discipline (mechanical, electrical, software, RF, etc.) products
Responsible for developing security control selections, data flow diagrams, internal requirements, CONOPs and interface control documents from customer / product requirements
Expertise in security requirements, documentation, and risk mitigation strategies
AWS cloud security knowledge including architecture, design, deployment, and management of cloud security technologies
Strong familiarity with Linux
Familiarity with security related tools – SIEM, malware, HIPS, etc
Identify security risks, threats and vulnerabilities of networks, systems, applications and new technology initiatives (hardware, software, cross-domain solutions, cryptographic devices, firewalls, intrusion detection systems, anti-virus systems and software deployment tools)
Support vulnerability assessment activities as required
Support the evaluation, qualification, testing and delivery of security architecture improvement, obsolescence replacement and vulnerability response projects
Ability to work individually or as part of a cybersecurity team. Must be able to lead and provide direction based on program and customer requirements and compliance
Possess excellent speaking abilities and skills to brief leadership and customers
Possess ability to conduct research on security and other applicable topics as needed as the cybersecurity lead
Must be a self-starter that is able to understand requirements and develop plans and articulate needs to meet compliance and requirements
This is an On-Site Position
Travel up to 25% to potential system deployment locations

Preferred

Familiarity with Model Based System Engineering (UML, SysML, UAF)
Experience in configuration and use of cyber defense and vulnerability assessment tools such as ACAS and SCC
Moderate understanding of vulnerability analysis tools such Tenable NESSUS Security products
Experience in the content development and administration of SEIM/audit reduction tools (e.g., Splunk)
Foundational knowledge of Layer 3 architecture and diagramming within Model based System Engineering tools such as CAMEO (or equivalent)
Supporting account management, PKI cert management, LDAP configuration/management
Scripting experience (Bash/Shell, Python, Perl, PowerShell)

Benefits

Health and disability insurance
401(k) match
Flexible spending accounts
EAP
Education assistance
Parental leave
Paid time off
Company-paid holidays

Company

L3Harris Technologies

company-logo
L3Harris Technologies provides platform management system solutions for armed forces.

Funding

Current Stage
Public Company
Total Funding
$2.25B
2024-03-27Post Ipo Debt· $2.25B
1978-01-13IPO

Leadership Team

leader-logo
Tania Hanna
Vice President Government & Customer Relations
linkedin
leader-logo
Chip Teets
Senior Director, International Programs, Products & Technology
linkedin
Company data provided by crunchbase