Senior Information Assurance Engineer jobs in United States
cer-icon
Apply on Employer Site
company-logo

General Dynamics · 3 weeks ago

Senior Information Assurance Engineer

General Dynamics Mission Systems is a leading provider of high technology solutions that support missions across various domains. They are seeking a Senior Information Assurance Engineer to lead cybersecurity requirements analysis, security design, and risk management activities to ensure the development of cyber survivable systems.

AerospaceNational SecurityPublic Transportation
badNo H1BnoteSecurity Clearance RequirednoteU.S. Citizen Onlynote

Responsibilities

Lead cyber security requirements analysis, security requirements definition, survivability/Cyber resilience analysis, system security design, security architecture generation with the understanding of cyber security technology and trends, security trade studies, and security verification and validation
Lead security planning, cost and risk analyses for the program security activities
Develop system security requirements, allocate to lower levels (subsystem, elements and components), and validate by analysis or testing. (ex. Security Requirements Traceability Matrix – SRTM, Security Control Traceability Matrix – SCTM)
Synthesize security solutions within the context of the system to meet customer expectations while staying within schedule and cost constraints
Provide cybersecurity inputs to MBSE models and Digital Engineering (DE)
Assess and mitigate system security threats and risks throughout the program life cycle to develop cyber survivable systems – has experience with risk assessment or threat modeling techniques – familiar with Mission Based Cybersecurity Risk Assessment (MBCRA) approaches such as Mission Risk Assessment Process – Cyber (MRAP-C) and Cyber Table Top (CTTs) exercises
Research and analyze data, such as vendor products, COTS components, GFE/CFE, specifications, and manuals to review the security of the design – Be familiar with Trusted Systems and Networks (TSN) analysis and Supply Chain Risk Management
Work within cyber security guidance such as Risk Management Framework (RMF) 800-53, Security Technical Implementation Guides (STIGs), Cyber Survivability Endorsement Implementation Guide, and other government security specifications and guidelines
Develop and lead the development of the RMF body of evidence for security requirements including items such as system risk assessments and mitigation reports, security plans, security testing plans and procedures, Security Control Traceability Matrices, and System Impact Analyses
Lead and execute security testing and evaluation to ensure the correct implementation of security requirements (ex. Scanning with tools: Nessus, static code analysis, dynamic code analysis, and penetration testing)
Lead the Assessment and Authorization (A&A) activities and the generation of the cyber package for the program
Work with Secure Coding Practices and DevSecOps
Have a CISSP or equivalent certification
Excellent written and verbal communications skills
Able to sell concepts and ideas
Effective ability in communicating issues, impacts, and corrective actions as they affect the cyber design and implementation
Excellent ability in reporting relevant cyber systems engineering design
Able to mentor less experienced engineers internal and external to the department on IA/cyber principles, practices, and processes
Communicate and coordinate with project leaders, the customer program leadership, and professionals within the Engineering department and project teams
Excellent understanding and ability to apply basic project leadership principles including Earned Value, Cost Account Management (CAM), and Statistical Process Controls
Creative thinker, good multi-tasker

Qualification

System Security EngineeringRisk Management FrameworkCybersecurity CertificationSecurity TestingEvaluationCybersecurity Requirements AnalysisCommunication SkillsMentoring SkillsProject Leadership PrinciplesCreative Thinking

Required

Requires a Bachelor's degree in Engineering, or a related Science, Technology or Mathematics field
Requires 8+ years of job-related experience, or a Master's degree plus 6 years of job-related experience
Ability to obtain a Department of Defense Secret security clearance is required at time of hire
U.S. citizenship is required
Lead cyber security requirements analysis, security requirements definition, survivability/Cyber resilience analysis, system security design, security architecture generation with the understanding of cyber security technology and trends, security trade studies, and security verification and validation
Lead security planning, cost and risk analyses for the program security activities
Develop system security requirements, allocate to lower levels (subsystem, elements and components), and validate by analysis or testing
Synthesize security solutions within the context of the system to meet customer expectations while staying within schedule and cost constraints
Provide cybersecurity inputs to MBSE models and Digital Engineering (DE)
Assess and mitigate system security threats and risks throughout the program life cycle to develop cyber survivable systems
Research and analyze data, such as vendor products, COTS components, GFE/CFE, specifications, and manuals to review the security of the design
Work within cyber security guidance such as Risk Management Framework (RMF) 800-53, Security Technical Implementation Guides (STIGs), Cyber Survivability Endorsement Implementation Guide, and other government security specifications and guidelines
Develop and lead the development of the RMF body of evidence for security requirements including items such as system risk assessments and mitigation reports, security plans, security testing plans and procedures, Security Control Traceability Matrices, and System Impact Analyses
Lead and execute security testing and evaluation to ensure the correct implementation of security requirements
Lead the Assessment and Authorization (A&A) activities and the generation of the cyber package for the program
Work with Secure Coding Practices and DevSecOps
Have a CISSP or equivalent certification
Excellent written and verbal communications skills
Able to sell concepts and ideas
Effective ability in communicating issues, impacts, and corrective actions as they affect the cyber design and implementation
Excellent ability in reporting relevant cyber systems engineering design
Able to mentor less experienced engineers internal and external to the department on IA/cyber principles, practices, and processes
Communicate and coordinate with project leaders, the customer program leadership, and professionals within the Engineering department and project teams
Excellent understanding and ability to apply basic project leadership principles including Earned Value, Cost Account Management (CAM), and Statistical Process Controls
Creative thinker, good multi-tasker

Benefits

Highly competitive benefits
Flexible work environment
Contributions are recognized and rewarded

Company

General Dynamics

company-logo
General Dynamics is a defense industry contractor for shipbuilding, marine, combat and defense systems and, munitions.

Funding

Current Stage
Public Company
Total Funding
$84.9M
2010-09-10Grant· $30M
2009-12-30Grant· $33.6M
2009-08-05Grant· $21.3M

Leadership Team

leader-logo
Lauren Bradshaw, SHRM-CP
Global Mobility Business Partner/ EAP
linkedin
leader-logo
Matthew Brandon, MSHR
Manager, Sr HR Business Partner
linkedin
Company data provided by crunchbase