Information System Security Engineer - Senior

BAE Systems
Boulder, CO, United States
1 day ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
4 years minimum
Compensation
$97,008.0 - $164,914.0
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Systems Engineering Cloud Computing Security Cyber Security Information Security Management Information Systems Security Engineering Professional Computer Network Operations Software Security Mitre Att&ck CIS Benchmarks Splunk Devsecops

Job description

This position is for an experienced information system security engineer (ISSE) to provide security engineering support within BAE Systems, Inc. Space & Mission Systems (SMS) Sector. The ISSE supports ongoing programs by managing cyber requirements, validating technical security implementations, and supporting Assessment & Authorization efforts pursuant to gaining and/or maintaining system Authorizations to Operate (ATO).

The Engineering, Science and Analysis (ESA) Strategic Capabilities Unit comprises the technical talent and organizational leadership that enables the successful delivery of high-impact discriminating technologies for our customers missions. Our collaborative, cross-functional teams are committed to innovation, integrity, continual learning and strong execution.

What You ll Do:

  • Participates in the development, review, and advisement of programs on the engineering design, development, and deployment of secure systems, networks, and applications, aligning its implementation across the mission acquisition lifecycle.
  • Assists in validating and verifying system security requirements definitions and analysis and establishes system security designs.
  • Supports in maintaining and promoting a comprehensive and holistic cybersecurity engineering view while addressing stakeholder security risks and concerns through the application of systems engineering skills.
  • Support security incident response and investigation activities, including root cause analysis and remediation efforts, collaborating with cross-functional teams, including Engineering, IT, Operations, and Compliance.
  • Perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations and recommend mitigation strategies.
  • Assist architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of customer security policy and enterprise security solutions.
  • Assess and mitigate system security threats/risks throughout the program life cycle.
  • Contribute to the security planning, assessment, risk analysis, risk management, certification and accreditation activities for system and network operations.
  • Develop Assessment and Authorization (A&A) documentation, providing feedback on completeness and compliance of its content.
  • Support security authorization activities in compliance with the NIST Risk Management Framework (RMF) and customer processes for security engineering.
  • Creatively identify ways to provide security compliance while minimally impacting day-to-day operations.
  • Identify, review, and define cybersecurity requirements that enable technical Architects / Systems Engineers and SMEs to secure hardware and software products.
  • Develop, review, and recommend security policy, guidance, training, and best practices that align its implementation across the mission acquisition lifecycle.
  • Interface with Program Managers (PMs), Mission Assurance Managers (MAMs), and customers.
  • Use excellent presentation skills to convey security mission risks at program milestone reviews (SRR, PDR, CDR, etc.).
  • Maintain a regular and predictable work schedule.
  • Establish and maintain effective working relationships within the department, the Strategic Business Units, Strategic Capabilities Units and the Company. Interact appropriately with others in order to maintain a positive and productive work environment.
  • Perform other duties as necessary.

Requirements

  • BS degree or higher in Engineering or a related technical field is required plus 4 or more years related experience.
  • Each higher-level degree, i.e., Master s Degree or Ph.D., may substitute for two years of experience. Related technical experience may be considered in lieu of education. Degree must be from a university, college, or school which is accredited by an agency recognized by the US Secretary of Education, US Department of Education.
  • A current, active TS/SCI Polygraph security clearance is required.
  • DoW 8570 / DoW 8140 compliant security certification.
  • In-depth knowledge of information security principles, practices, technologies, and standards, including NIST Standards (800-37, 800-53), DISA STIGs, and CIS benchmarks.
  • Hands-on knowledge of cyber-enabling tools like Splunk, Tenable SC/ACAS, HBSS.
  • Familiarity with DevSecOps concepts and software security engineering principles., * CISSP-ISSEP certification.
  • Experience with Cloud-based security solutions, AWS preferred.
  • Experience with cybersecurity design principles applicable to Space Vehicles.
  • Experience with the Space Attack Research and Tactic Analysis (SPARTA) matrix.
  • Experience with the MITRE ATT&CK Framework.

Benefits & conditions

  • Work is performed in an office, laboratory, production floor, or cleanroom, outdoors or remote research environment.
  • May occasionally work in production work centers where use of protective equipment and gear is required.
  • May access other facilities in various weather conditions., Full-Time Salary Range: $97008 - $164914

Please note: This range is based on our market pay structures. However, individual salaries are determined by a variety of factors including, but not limited to: business considerations, local market conditions, and internal equity, as well as candidate qualifications, such as skills, education, and experience.

Employee Benefits: At BAE Systems, we support our employees in all aspects of their life, including their health and financial well-being. Regular employees scheduled to work 20 hours per week are offered: health, dental, and vision insurance; health savings accounts; a 401(k) savings plan; disability coverage; and life and accident insurance. We also have an employee assistance program, a legal plan, and other perks including discounts on things like home, auto, and pet insurance. Our leave programs include paid time off, paid holidays, as well as other types of leave, including paid parental, military, bereavement, and any applicable federal and state sick leave. Employees may participate in the company recognition program to receive monetary or non-monetary recognition awards. Other incentives may be available based on position level and/or job specifics.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:38 min

Using language models to self-detect and flag software vulnerabilities

Julian Totzek-Hallhuber Julian Totzek-Hallhuber · World Congress 2026 Europe

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:09 min

Shifting security left using the DevSecOps approach

Aarno Aukia · LIVE

3:09 min

Balancing data science skillings alongside systems engineering rigor

Nico Schmidt · LIVE

Videos

See all

Related articles

See all