> Markdown version of [/jobs/ext/2717365-cyber-architect-prin](https://www.wearedevelopers.com/jobs/ext/2717365-cyber-architect-prin). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Architect Prin - **Company:** BAE Systems - **Location:** Nashua, NH, United States - **Experience:** Expert - **Contract:** Temporary contract - **Skills:** Kubernetes Security, Systems Engineering, Cyber Security, Continuous Integration, Dynamic Program Analysis, Firmware, Formal Verification, Information Systems Security Architecture Professional, Information Systems Security Engineering Professional, Systems Development Life Cycle, Zero Trust Network Access, Security Software, Verification and Validation (Software), Data Streaming, Systems Modeling Language, Real Time Systems, Information Technology, Devsecops, Plan of Action and Milestones - **Published:** September 4, 2026 - **Apply:** https://www.careerjet.com/job/us7c1b8d16cd1924312196ce235748d762/eaa ## About the Role * Master's degree in Systems Engineering, Cybersecurity, or related field * Active TS/SCI security clearance * CISSP-ISSEP (Information Systems Security Engineering Professional) or equivalent certification or ability to obtain within 6 months of start date. * Experience with Model-Based Systems Engineering (MBSE) tools (e.g., Cameo, SysML) applied to security architecture * Familiarity with System-Theoretic Process Analysis for Security (STPA-Sec) tooling and processes * Experience with zero trust architecture design principles and implementation * Knowledge of cross-domain solutions, multi-level security architectures, and secure system integration patterns * Experience supporting security engineering for embedded systems, real-time systems, or weapon system platforms * Background in formal verification or assurance methods for high-assurance systems ## Description See what you're missing. Our employees work on the world's most advanced electronics - from detecting threats for F-35 pilots to illuminating the night for soldiers. Spanning air, land, sea, and space, we are developing the technology of tomorrow, delivered today. Drawing strength from our differences, we're innovating for the future. And you can, too. Our flexible work environment provides you a chance to change the world without giving up your personal life. We put our customers first - exemplified by our mission: "We Protect Those Who Protect Us®." Sound like a team you want to be a part of? Come build your career with BAE Systems. BAE Systems is seeking a Senior Principal Systems Security Engineer to lead the integration of security engineering practices across the full systems development lifecycle (SDLC) for mission-critical DoW programs. The qualified candidate will drive the specification, design, implementation, and verification of security controls within complex system architectures, ensuring that cybersecurity and information assurance are embedded from concept through deployment and sustainment. This role is grounded in the principles of NIST SP 800-160 (Systems Security Engineering) and emphasizes proactive security-by-design rather than reactive compliance. The Senior Principal Systems Security Engineer will serve as the technical authority for security engineering within multidisciplinary development teams, ensuring that protection strategies, threat-informed design decisions, and risk trades are woven into every phase of the engineering lifecycle. Salary Max Point 200762 About BAE Systems Electronic Systems BAE Systems, Inc. is the U.S. subsidiary of BAE Systems plc, an international defense, aerospace and security company which delivers a full range of products and services for air, land and naval forces, as well as advanced electronics, security, information technology solutions and customer support services. Improving the future and protecting lives is an ambitious mission, but it's what we do at BAE Systems. Working here means using your passion and ingenuity where it counts - defending national security with breakthrough technology, superior products, and intelligence solutions. As you develop the latest technology and defend national security, you will continually hone your skills on a team-making a big impact on a global scale. At BAE Systems, you'll find a rewarding career that truly makes a difference. Electronic Systems (ES) is the global innovator behind BAE Systems' game-changing defense and commercial electronics. Exploiting every electron, we push the limits of what is possible, giving our customers the edge and our employees opportunities to change the world. Our products and capabilities can be found everywhere - from the depths of the ocean to the far reaches of space. At our core are more than 14,000 highly talented Electronic Systems employees with the brightest minds in the industry, we make an impact - for our customers and the communities we serve. This position will be posted for at least 5 calendar days. The posting will remain active until the position is filled, or a qualified pool of candidates is identified. Clearance Level - Must be able to obtain for position Secret Shift 1st Shift Union Job None Business Area Countermeasure & Electromagnetic Attack Solutions Required Skills and Education * Lead systems security engineering activities across all phases of the SDLC, including concept definition, requirements analysis, architecture and design, implementation, integration, verification and validation, deployment, and sustainment * Define, decompose, and allocate security requirements to system elements (hardware, software, firmware, and interfaces) ensuring traceability from threat models through verification evidence * Develop and maintain security architectures, including protection strategies, trust boundaries, security-relevant data flows, and attack surface analyses for complex DoD systems * Conduct and lead threat modeling, Systems-Theoretic Process Analysis for Security and adversarial analysis to inform design trades and risk acceptance decisions * Drive the integration of security into Development Security Operations (DevSecOps) pipelines, including automated security testing, static/dynamic analysis, container security, and secure CI/CD practices * Lead Assessment and Authorization (A&A) activities for DoD systems in accordance with the Risk Management Framework (RMF), including security control selection, implementation, assessment, and continuous monitoring * Author and maintain security engineering artifacts including System Security Plans (SSPs), Security Concepts of Operations (CONOPS), Security Control Traceability Matrices (SCTMs), and risk assessment reports * Evaluate and apply applicable STIGs, SRGs, and security benchmarks to system components, and develop Plan of Action and Milestones (POA&Ms) for residual risks * Provide technical leadership and mentorship to cybersecurity engineers, systems engineers, and software developers on secure design principles and security engineering best practices * Engage with government customers, authorizing officials, and cross-functional program teams to communicate security posture, risk decisions, and compliance status * Support proposal development, technical volume writing, and independent review of security architectures for new business pursuits ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Playing Pong on a shoulder press machine](https://www.wearedevelopers.com/videos/100140-playing-pong-on-a-shoulder-press-machine) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Coding Boot Camps in Germany](https://www.wearedevelopers.com/magazine/237-best-coding-boot-camps-in-germany) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)