> Markdown version of [/jobs/ext/2293091-senior-information-assurance-engineer](https://www.wearedevelopers.com/jobs/ext/2293091-senior-information-assurance-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information Assurance Engineer - **Company:** General Dynamics Mission Systems, Inc. - **Location:** Scottsdale, AZ, United States - **Experience:** Expert - **Salary:** $142,696.0 - $158,303.0 - **Contract:** Permanent contract - **Skills:** Adobe InDesign, Agile Methodology, Systems Engineering, Configuration Management, CompTIA Security+, Cyber Security, Information Systems, Data Flow Control, Information Systems Security Architecture Professional, Package Development Process, Systems Development Life Cycle, Role-Based Access Control, Secure Coding, Software Engineering, Software Requirements Analysis, Data Streaming, Software Vulnerability Management, Data Logging, Software Security, CIS Benchmarks, Devsecops, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 29, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88178050/1 ## About the Role Bachelor's degree in Engineering, or a related Science or Mathematics field, plus a minimum of 8 years of relevant experience; or Master's degree plus a minimum of 6 years of relevant experience., Department of Defense Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required., * Ability to clearly communicate complex cybersecurity, systems engineering, and risk-management concepts to technical teams, program leadership, customers, and other stakeholders. * Ability to translate mission, business, and operational objectives into actionable cybersecurity architecture, engineering requirements, and verification activities. * Strong collaboration skills and the ability to influence cross-functional development, integration, test, and operations teams in implementing cybersecurity technologies, principles, and controls. * A security-first mindset, with the technical curiosity to challenge system behaviors, assumptions, and design decisions that conflict with secure engineering principles or approved security architecture., * Strong understanding of cybersecurity systems engineering, secure architecture, RMF, and defense-in-depth principles. * Working knowledge of NIST RMF and associated guidance, including NIST SP 800-37 and security-control assessment/authorization processes. * Ability to perform requirements analysis, requirements definition, allocation, decomposition, traceability, and impact analysis while avoiding unnecessary requirements growth. * Ability to develop and evaluate system, network, and information-system designs against applicable security requirements and government specifications. * Experience analyzing technical security controls and their implementation across system components, interfaces, and operational environments. * Ability to execute complex technical tasks independently, identify technical risks and dependencies, and communicate issues, impacts, and corrective actions clearly. * Self-directed, proactive work style with sound engineering judgment in selecting technical approaches and developing solutions. * Demonstrated ability to design or contribute to the design of complex systems, products, frameworks, or cybersecurity architectures. Preferred Experience * Cybersecurity Systems Engineering, RMF implementation, and system authorization/accreditation support. * Experience developing RMF authorization packages and supporting assessments, including evidence collection, control implementation statements, SCTMs, POA&Ms, and security test artifacts. * Experience applying and tracing DISA STIGs, NCDSMO requirements, and other DoD/customer cybersecurity requirements to system designs. * Experience with Secure Software Factory, secure software development life cycle (SSDLC), DevSecOps, and the integration of security activities into CI/CD pipelines. * Knowledge of secure development practices, including vulnerability remediation, secure configuration, code/security scanning, software supply-chain considerations, and automated security testing. * Experience with multi-level security (MLS), cross-domain solutions (CDS), or other controlled information-sharing architectures. * Ground-to-satellite communications knowledge and/or ground operations experience. * Experience supporting space, satellite communications, or mission systems programs. * Experience collaborating with customers, suppliers, and mission partners such as Iridium, SDA, Northrop Grumman, York Space Systems, and Lockheed Martin. * Experience operating in Agile or hybrid Agile engineering programs. * Active cybersecurity certification such as ISC2 CISSP (preferred), CompTIA Security+, CEH, or equivalent. ## Description * Partner with system development, integration, deployment, and operations teams to define and implement secure system architectures and designs using defense-in-depth principles. * Lead cybersecurity engineering activities across the system life cycle, including requirements decomposition, architecture development, design analysis, implementation support, verification, validation, and accreditation. * Serve as the cybersecurity technical authority in design reviews, trade studies, and engineering decisions involving security architecture, system interfaces, data flows, and security-control implementation. * Develop, maintain, and baseline cybersecurity engineering artifacts, including System Security Plans (SSPs), cybersecurity design documentation, security architecture diagrams, data-flow diagrams, and security requirements specifications. * Produce and maintain Security Control Traceability Matrices (SCTMs), inheritable control sets, and associated evidence repositories to establish end-to-end traceability from security requirements through implementation, verification, and assessment evidence. * Lead Risk Management Framework (RMF), consistent with NIST SP 800-37, activities supporting the authorization process, including system categorization, control selection and tailoring, control implementation, assessment preparation, Plan of Action and Milestones (POA&M) management, and authorization package development. * Map and assess applicable cybersecurity requirements and technical guidance-including DISA STIGs, NCDSMO requirements, and other government/customer security baselines-within the SCTM and system security architecture. * Work with development and test teams to define objective security-verification criteria; plan and support security test events; and evaluate evidence demonstrating that security requirements and controls are correctly implemented and operating as intended. * Perform technical analyses of systems, networks, interfaces, and information systems to verify compliance with applicable government security specifications, customer requirements, and program security constraints. * Analyze and document security-relevant system capabilities, including identification and authentication, access control, least privilege, audit/logging, cryptographic protection, configuration management, labeling, and secure communications. * Support system accreditation/certification evaluations and cybersecurity test activities to identify control deficiencies, assess risk, recommend mitigations, and track corrective actions to closure. * Participate actively in Agile development environments by planning, prioritizing, estimating, and reporting cybersecurity engineering work in coordination with program and technical leadership. * Contribute technical input to customer engagements, technical interchange meetings, design reviews, and cross-team working groups. * Plan and execute assigned project tasks with appropriate technical rigor, schedule awareness, and risk management. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [How to Cause (or Prevent) a Massive Data Breach- Secure Coding and IDOR](https://www.wearedevelopers.com/videos/39-how-to-cause-or-prevent-a-massive-data-breach-secure-coding-and-idor) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)