> Markdown version of [/jobs/ext/1846739-it-sys-sec-eng-sr-prin-ii](https://www.wearedevelopers.com/jobs/ext/1846739-it-sys-sec-eng-sr-prin-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Sys Sec Eng Sr Prin II - **Company:** BAE Systems - **Location:** Annapolis Junction, MD, United States - **Experience:** Expert - **Salary:** $127,800.0 - $142,000.0 - **Contract:** Temporary contract - **Skills:** Agile Methodology, Software System Penetration Testing, Systems Engineering, User Authentication, Communications Protocols, Cyber Security, Information Systems Security Engineering Professional, Nmap, Public Key Infrastructure, Systems Development Life Cycle, Software Engineering, Wireshark, Web Services, Scripting, Software Security, Information Technology, Nessus, Server Operating Systems & Platforms - **Published:** July 2, 2026 - **Apply:** https://www.careerjet.com/job/us63d6007cedf1e6a99314525aafe24714/eaa ## About the Role * Must currently hold a TS/SCI clearance with an appropriate polygraph. * Must have at least 12 years of experience working as an ISSE on a large technical program. * Must have a solid understanding of security practices and policies and hands-on vulnerability testing experience using Customer tools. * Must have experience applying Risk Management Framework. * Must have experience formulating and assessing IT security policy. * Must have demonstrated knowledge of and experience with common security tools, such as Nessus, NMAP and Wireshark hardware/software security implementation, communication protocol, encryption techniques/tools, and web services. * Must have experience with secure configurations of commonly used desktop and server operating systems. * Must be comfortable working on multiple systems and components simultaneously in various configurations. * Must have strong verbal and written communications skills. * Must be committed to adopting and adhering to best practices. * Must be able to effectively plan and prioritize tasking and communicate clearly regarding technical options and trade-offs. * Must be capable of performing high quality work both independently and with a team in a fast-moving environment., * Bachelor's degree in Computer Science, Information Assurance, Information Security System Engineering, or a related discipline. * Five (5) years of experience with Defense in Depth Principals/technology (including access control, authorization, identification and authentication, public key infrastructure, network and enterprise security architecture) and applying risk assessment methodology to system development. * DoD 8570 compliance with IASAE Level 2 or 3. * Information Systems Security Engineering Professional (ISSEP) Certification. * Computer Information Systems Security Professional (CISSP) Certification. * Experience developing/implementing integrated security services management processes, such as assessing and auditing network penetration testing, anti-virus planning assistance, risk analysis, and incident response. * Experience providing information assurance support for application development that includes system security certifications and project evaluations for firewalls that encompass the development, design, and implementation. * Experience with penetration testing tools. * Experience with scripting languages., Typically a Bachelor's Degree and 10 years work experience or equivalent experience Job Category ## Description * Security Architecture and Design: Validate and verify system security requirements, establish system security designs, and ensure uniform application of security policy and enterprise solutions. * Threat Assessment and Mitigation: Assess and mitigate system security threats and risks throughout the program life cycle, and recommend technical solutions, products, and standards. * Security Planning and Compliance: Lead and contribute to security planning, assessment, risk analysis, risk management, certification, and awareness activities for various system and networking operations. * Collaboration and Communication: Effectively collaborate with internal technical experts, Program Managers, and customer organizations to ensure security requirements are met. * Agile Team Activities: Participate in Program Increment Planning and related agile team activities to ensure seamless integration with development teams. * Security Testing and Verification: Plan and conduct security verification testing of relevant type 1 devices, and evaluate security solutions to ensure they meet customer-specified requirements. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How I saved 200K/yr in direct costs writing 0 code lines in K8s](https://www.wearedevelopers.com/videos/1055-how-i-saved-200k-yr-in-direct-costs-writing-0-code-lines-in-k8s) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [MySQL Protocol Features You Should Be Aware Of](https://www.wearedevelopers.com/videos/100267-mysql-protocol-features-you-should-be-aware-of) - [Let’s write an exploit using AI](https://www.wearedevelopers.com/videos/1004-let-s-write-an-exploit-using-ai) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)