Senior Specialist, Information Security Systems Engineer

L3Harris Technologies, Inc.
Ontario Center, NY, United States
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Compensation
$92,500.0 - $171,500.0
Working hours
Regular working hours

Tech stack

Antivirus Softwares Systems Engineering Software as a Service Cloud Computing Security Configuration Management Cyber Security Databases Continuous Delivery Continuous Integration Data Centers Network Interface Controllers Federal Information Processing Standards (FIPS)
+21 more
Infrastructure as a Service (IaaS) Intrusion Detection Systems Information Systems Security Architecture Professional Platform as a Service (PAAS) Fortify (Software) SAP Implementation Software Deployment Software Engineering Systems Modeling Language UML Software Vulnerability Management Cloud Platform System Software Security Firewalls (Computer Science) Gitlab Tenable Nessus Splunk Devsecops Plan of Action and Milestones Static Application Security Testing Vulnerability Analysis

Job description

The successful candidate will support a highly motivated engineering team in defining, designing, implementing, documenting, testing and sustaining security solutions on National Security Systems, or other systems engineered for our government customers, using current standards within National Institute of Standards & Technology (NIST) Risk Management Framework, Special Publications 800-37, 800-53, 800-171, and other NIST publications; Committee on National Security Systems Instruction (CNNSI) 1253, Joint SAP Implementation Guide (JSIG), and Federal Information Processing Standards (FIPS) to certify and achieve system accreditations.

The successful candidate will work with system developers or commercial product vendors in the design and evaluation of state-of-the-art secure systems, networks, and database products, using methods such as encryption technology, vulnerability analysis and security management.

Essential Functions:

Exercise skills in NIST Risk Management Framework (RMF) and all related NIST publications, to include writing System Security Plans, Security Control Traceability Matrix, Continuous Monitoring Plan, Security Assessment Plans & Procedures, Security Concept of Operations, Plan of Action and Milestones.

Perform skills in implementing/assessing security controls, to include writing system security categorization memorandum, recommending appropriate security control overlays, define security control baseline based on defined system security categorization and approved security overlays, and apply security controls to computing/network nodes and verify implementation of security controls.

Assist in systems/software engineering functions, to include creation of data flow diagrams, interface control documents, perform trade studies, and Static Application Security Testing (SAST) for Application Security and Development Secure Technical Implementation Guide (STIG) compliance using tools such as Fortify/Coverity and Gitlab as part of a DevSecOps Continuous Integration/Continuous Deployment (CI/CD) Pipeline, and generation of summary reports.

Define/manage systems/security architectures including system security boundaries, vulnerability management and risk mitigation and remediation strategies within networks, systems, applications and new technology initiatives (hardware, software, firewalls, intrusion detection systems, anti-virus systems and software deployment tools); Infrastructure/Platform/Software as a Service (IaaS, PaaS, SaaS) implementations in cloud environments and development of Configuration Management Plans (CMP).

Define/manage systems/security architectures including system security boundaries in on-premises data center systems and ultimately deploy to secure cloud-based system, to include configuration and use of defense and assessment tools specific to each environment type.

This position is performed 100% onsite and cannot be performed remotely., L3Harris Technologies is proud to be an Equal Opportunity Employer. L3Harris is committed to treating all employees and applicants for employment with respect and dignity and maintaining a workplace that is free from unlawful discrimination. All applicants will be considered for employment without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender (including pregnancy, childbirth, breastfeeding or other related medical conditions), gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, characteristic or membership in any other group protected by federal, state or local laws. L3Harris maintains a drug-free workplace and performs pre-employment substance abuse testing and background checks, where permitted by law.

Requirements

o Bachelor’s Degree and minimum 6 years of prior relevant experience.

o Graduate Degree and a minimum of 4 years of prior related experience.

o In lieu of a degree, minimum of 10 years of prior related experience.

Must have active TS/SCI Security Clearance.

DoD 8140.03 IASAE Level 1 or 2 certification.

Preferred Additional Skills:

Perform Model Based System Engineering (UML, SysML, UAF).

Configure/operate vulnerability analysis tools such Tenable NESSUS Security products.

Develop dashboards, configure rules and operate/administer SEIM/audit reduction tools (eg, Splunk).

Active TS/SCI with poly is highly desired.

Benefits & conditions

In compliance with pay transparency requirements, the salary range for this role in New York state is $92,500 - $171,500 . This is not a guarantee of compensation or salary, as final offer amount may vary based on factors including but not limited to experience and geographic location. L3Harris also offers a variety of benefits, including health and disability insurance, 401(k) match, flexible spending accounts, EAP, education assistance, parental leave, paid time off, and company-paid holidays. The specific programs and options available to an employee may vary depending on date of hire, schedule type, and the applicability of collective bargaining agreements.

About the company

L3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do. Our employees are unified in a shared dedication to our customers’ mission and quest for professional growth. L3Harris provides an inclusive, engaging environment designed to empower employees and promote work-life success. Fundamental to our culture is an unwavering focus on values, dedication to our communities, and commitment to excellence in everything we do.

L3Harris is the Trusted Disruptor in defense tech. With customers’ mission-critical needs always in mind, our employees deliver end-to-end technology solutions connecting the space, air, land, sea and cyber domains in the interest of national security., L3Harris Technologies is an E-Verify Employer. Please click here for the E-Verify Poster in English or Spanish. For information regarding your Right To Work, please click here for English or Spanish

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerboard.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

2:13 min

Evaluating UML, block diagrams, and the C4 model

Simon Lasselsberger · WWC 2022

6:14 min

Structuring CI/CD pipelines with integrated security and quality checks

Christoph Ruggenthaler · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

4:36 min

Visualizing system architecture with Mermaid UML diagrams

Jakov Semenski · LIVE

Videos

See all

Related articles

See all