> Markdown version of [/jobs/ext/2079436-information-system-security-engineer-senior](https://www.wearedevelopers.com/jobs/ext/2079436-information-system-security-engineer-senior). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information System Security Engineer - Senior - **Company:** BAE Systems - **Location:** Broomfield, CO, United States - **Experience:** Expert - **Salary:** $97,008.0 - $164,914.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Systems Engineering, Cloud Computing Security, Cyber Security, Information Security Management, Information Systems Security Engineering Professional, Computer Network Operations, Software Security, Mitre Att&ck, CIS Benchmarks, Splunk, Devsecops - **Published:** August 16, 2026 - **Apply:** https://dejobs.org/x/x/3DDB83C20465412EAD784D8353A06959/job/ ## About the Role * BS degree or higher in Engineering or a related technical field is required plus 4 or more years related experience. * Each higher-level degree, i.e., Master s Degree or Ph.D., may substitute for two years of experience. Related technical experience may be considered in lieu of education. Degree must be from a university, college, or school which is accredited by an agency recognized by the US Secretary of Education, US Department of Education. * A current, active TS/SCI Polygraph security clearance is required. * DoW 8570 / DoW 8140 compliant security certification. * In-depth knowledge of information security principles, practices, technologies, and standards, including NIST Standards (800-37, 800-53), DISA STIGs, and CIS benchmarks. * Hands-on knowledge of cyber-enabling tools like Splunk, Tenable SC/ACAS, HBSS. * Familiarity with DevSecOps concepts and software security engineering principles., * CISSP-ISSEP certification. * Experience with Cloud-based security solutions, AWS preferred. * Experience with cybersecurity design principles applicable to Space Vehicles. * Experience with the Space Attack Research and Tactic Analysis (SPARTA) matrix. * Experience with the MITRE ATT&CK Framework. ## Description This position is for an experienced information system security engineer (ISSE) to provide security engineering support within BAE Systems, Inc. Space & Mission Systems (SMS) Sector. The ISSE supports ongoing programs by managing cyber requirements, validating technical security implementations, and supporting Assessment & Authorization efforts pursuant to gaining and/or maintaining system Authorizations to Operate (ATO). The Engineering, Science and Analysis (ESA) Strategic Capabilities Unit comprises the technical talent and organizational leadership that enables the successful delivery of high-impact discriminating technologies for our customers missions. Our collaborative, cross-functional teams are committed to innovation, integrity, continual learning and strong execution. What You ll Do: * Participates in the development, review, and advisement of programs on the engineering design, development, and deployment of secure systems, networks, and applications, aligning its implementation across the mission acquisition lifecycle. * Assists in validating and verifying system security requirements definitions and analysis and establishes system security designs. * Supports in maintaining and promoting a comprehensive and holistic cybersecurity engineering view while addressing stakeholder security risks and concerns through the application of systems engineering skills. * Support security incident response and investigation activities, including root cause analysis and remediation efforts, collaborating with cross-functional teams, including Engineering, IT, Operations, and Compliance. * Perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations and recommend mitigation strategies. * Assist architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of customer security policy and enterprise security solutions. * Assess and mitigate system security threats/risks throughout the program life cycle. * Contribute to the security planning, assessment, risk analysis, risk management, certification and accreditation activities for system and network operations. * Develop Assessment and Authorization (A&A) documentation, providing feedback on completeness and compliance of its content. * Support security authorization activities in compliance with the NIST Risk Management Framework (RMF) and customer processes for security engineering. * Creatively identify ways to provide security compliance while minimally impacting day-to-day operations. * Identify, review, and define cybersecurity requirements that enable technical Architects / Systems Engineers and SMEs to secure hardware and software products. * Develop, review, and recommend security policy, guidance, training, and best practices that align its implementation across the mission acquisition lifecycle. * Interface with Program Managers (PMs), Mission Assurance Managers (MAMs), and customers. * Use excellent presentation skills to convey security mission risks at program milestone reviews (SRR, PDR, CDR, etc.). * Maintain a regular and predictable work schedule. * Establish and maintain effective working relationships within the department, the Strategic Business Units, Strategic Capabilities Units and the Company. Interact appropriately with others in order to maintain a positive and productive work environment. * Perform other duties as necessary. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) ## Related Articles - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Best Countries for Software Engineers](https://www.wearedevelopers.com/magazine/267-best-countries-for-software-engineers) - [Software Engineer Career: Things You Should Know](https://www.wearedevelopers.com/magazine/143-software-engineer-career-things-you-should-know)