Advanced Information Assurance Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

General Dynamics Mission Systems · 2 months ago

Advanced Information Assurance Engineer

General Dynamics Mission Systems engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. The Advanced Information Assurance Engineer will support cyber security requirements analysis, system security design, and the development of security documentation while ensuring compliance with government security specifications and guidelines.

AerospaceBusiness Information SystemsInformation ServicesInformation TechnologyNational SecuritySensor
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Supports cyber security requirements analysis, security requirements definition, survivability/Cyber resilience analysis, system security design, security architecture generation, security trade studies, and security verification and validation with little or no supervision. (ex. Cybersecurity Architecture Analysis Report – AAR)
Supports customer security requirements analysis, develops system security requirements and defines allocations to lower levels (subsystem, elements and components) (ex. Security Requirements Traceability Matrix – SRTM, Security Control Traceability Matrix – SCTM)
Understands and provides cybersecurity inputs to MBSE models and Digital Engineering (DE)
Supports assessments and mitigations of system security threats and risks throughout the program life cycle to develop cyber survivable systems – familiar with Mission Based Cybersecurity Risk Assessment (MBCRA) approaches such as Mission Risk Assessment Process – Cyber (MRAP-C) and Cyber Table Top (CTTs) exercises
Researches and analyzes data, such as vendor products, COTS components, GFE/CFE, specifications, and manuals to determine security of design – familiarity with Trusted Systems and Networks (TSN) analysis and Cybersecurity – Supply Chain Risk Management desirable
Experience with DevSecOps
CISSP or equivalent certification
Strong understanding of cyber security technology and trends
Recognizes various security architectural patterns, applies them appropriately, understands strengths/weaknesses within those security architectures
Effectively selects and implements the appropriate cyber standards, processes, procedures, and tools throughout the system development life cycle to support the generation of the security engineering products
Support development of required security documentation, including items such as security plans, risk assessments and mitigation reports, and security tests plans and procedures in compliance with the IA policy
Strong understanding of cyber security guidance such as Risk Management Framework (RMF) 800-53, STIGs, Cyber Survivability Endorsement Implementation Guide, and other government security specifications and guidelines. Experience performing vulnerability and code analysis scans in DevSecOps environment (ex. Nessus, Static Code Analysis – SCA, STIGs)
Supports the development of the RMF body of evidence for security requirements including items such as system risk assessments and mitigation reports, security plans (SP), security testing plans and procedures, Security Control Traceability Matrices (SCTM), and System Impact Analyses
Supports the Assessment and Authorization (A&A) activities and the generation of the cyber package for the program leading to granting of the Authority To Operate (ATO)
Supports the execution of the security testing and evaluation to ensure the correct implementation of security requirements (ex. Scanning with tools for static and dynamic code analysis. Penetration Testing)
Excellent written and verbal communications skills
Effective ability in communicating issues, impacts, and corrective actions as they affect the cyber design and implementation
Excellent ability in reporting relevant cyber systems engineering design topics
Effective communication and coordination with project leaders, the customer program leadership, and professionals within the Engineering department and with project teams
Creative thinker, good multi-tasker

Qualification

CISSP certificationDevSecOpsCybersecurity architectureRisk Management FrameworkCybersecurity guidanceMulti-taskerCommunicationCreative thinker

Required

Bachelor's degree in Engineering, or a related Science or Mathematics field
5+ years of job-related experience, or a Master's degree plus 3 years of job-related experience
Department of Defense Top Secret security clearance is required at time of hire
U.S. citizenship is required
Strong understanding of cyber security technology and trends
Recognizes various security architectural patterns, applies them appropriately, understands strengths/weaknesses within those security architectures
Effectively selects and implements the appropriate cyber standards, processes, procedures, and tools throughout the system development life cycle to support the generation of the security engineering products
Support development of required security documentation, including items such as security plans, risk assessments and mitigation reports, and security tests plans and procedures in compliance with the IA policy
Strong understanding of cyber security guidance such as Risk Management Framework (RMF) 800-53, STIGs, Cyber Survivability Endorsement Implementation Guide, and other government security specifications and guidelines
Supports the development of the RMF body of evidence for security requirements including items such as system risk assessments and mitigation reports, security plans (SP), security testing plans and procedures, Security Control Traceability Matrices (SCTM), and System Impact Analyses
Supports the Assessment and Authorization (A&A) activities and the generation of the cyber package for the program leading to granting of the Authority To Operate (ATO)
Supports the execution of the security testing and evaluation to ensure the correct implementation of security requirements
Excellent written and verbal communications skills
Effective ability in communicating issues, impacts, and corrective actions as they affect the cyber design and implementation
Excellent ability in reporting relevant cyber systems engineering design topics
Effective communication and coordination with project leaders, the customer program leadership, and professionals within the Engineering department and with project teams
Creative thinker, good multi-tasker

Preferred

Experience with DevSecOps
CISSP or equivalent certification
Familiarity with Trusted Systems and Networks (TSN) analysis and Cybersecurity – Supply Chain Risk Management

Company

General Dynamics Mission Systems

company-logo
General Dynamics Mission Systems designs and delivers critical systems and products for defense and cybersecurity customers. It is a sub-organization of General Dynamics.

Funding

Current Stage
Late Stage

Leadership Team

leader-logo
Bo Elam
VP and CFO
linkedin
leader-logo
Scott Butler
Senior Vice President Program Execution
linkedin
Company data provided by crunchbase