Information System Security Engineer

Navstar Inc.
United States
12 days ago
Apply on www.thejobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Agile Methodology Application Layers Software Applications Systems Engineering Acceptance Test-Driven Development Behavior-Driven Development C++ (Programming Language) Cloud Computing Cyber Security Continuous Integration Enterprise JavaBeans Java Platform Enterprise Edition (J2EE)
+31 more
Network Interface Controllers Firmware FitNesse Global Positioning Systems (GPS) Information Security Management Networking Hardware Java Persistence API Java Transaction API Java API for RESTful Web Services (JAX-RS) Python (Programming Language) PostgreSQL MongoDB Network Architecture Oracle (Applications) Pair Programming Windows PowerShell Mockito Zero Trust Network Access Requirements Management Scaled Agile Framework Selenium Simple Object Access Protocol (SOAP) Software Engineering SQL Databases Web Services Description Language Scripting Computer Network Technologies Test-Driven Development (TDD) Jax Ws Cucumber (Software) Code Restructuring

Job description

The Senior ISSE shall deliver and lead threat-informed cybersecurity products - cybersecurity risk assessments, architecture reviews, and engineering guidance that bring sound, accurate, timely, and actionable service to mission partners. This includes

Requirements

  • Bachelor of Science degree from an accredited university ideally in Computer Science, Information Assurance, Information Security System Engineering or related field with a minimum of 14 years of experience as an Information Systems Security Engineer (ISSE) or System Engineer. \n

  • CISSP OR CASP certification required. \n

  • Strong writing skills. \n

  • Confidence and ability to present briefing to senior level DoD officials in both prepared briefings and/or in ad hoc discussions. \n

  • Expertise in the Risk Management Framework (RMF) and conducting cybersecurity risk assessments. \n

  • Expertise in network technology and systems security engineering. Experience in identifying, researching, characterizing, and documenting security weaknesses related to operating systems, software applications, firmware, network hardware components, as well as network architecture design to identify protection needs and documented policies and procedures. \n

  • Experience developing and documenting system security requirements and conducting requirements gap analysis. \n

  • Experience with security monitoring and incident response capabilities. \n

  • Experience with emerging technologies such as Zero Trust, Cloud Computing, etc. \n

  • Knowledge of, and practical experience with the NIST Special Publications 800 Series, CNSSI 1253, and DoD 8500. \n

  • Ability to work independently within a schedule and with little direction. \n, * Experience with the following: JEE (EJB, JPA, JTA, JAX-B, JAX-RS, JAX-WS), SQL, application servers (Tomcat, WebLogic, JBoss), scripting. \n

  • Experience with high level requirements management including requirements decomposition, secure systems engineering and development, trade-off analysis, interface control, and testing and continuous integration. \n

  • Experience in software development on Agile teams using Agile Developer practices such as Pair Programming, TDD, Refactoring, and ATDD. \n

  • Experience with FITNesse, Mockito, Cucumber, Unified Functional Tester (UFT), Selenium. \n

  • Experience with Behavior Driven Development (BDD). \n

  • Secure Software development (i.e., Layer 7 Policy). \n

  • Experience with the Scaled Agile Framework (SAFe) methodology, SAFe Agilest Certification, or experience as a member of an agile team. \n

  • Additional experience in J2EE, Python, C/C++, SQL, SOAP, WSDL, Postgres, Oracle, Mongo, PowerShell a plus.

Benefits & conditions

n \n

  • Conduct cybersecurity risk assessments and provide prioritized risk mitigation recommendations in support of the customer’s mission. \n

  • Support the design, implementation, and operation of real-time capabilities to discover, detect, analyze, and mitigate threats and vulnerabilities. \n

  • Analyze candidate architectures by evaluating against defined security requirements to identify security gaps, and provide recommended mitigation strategy. \n

  • Research and evaluate candidate emerging technologies to determine cybersecurity effectiveness. \n

  • Aid stakeholders through the development, refinement, delivery, and implementation of innovative solutions and capabilities. \n

  • Engage stakeholders to ensure security objectives, protection needs, security requirements and associated validation methods are defined. \n

  • Validates and verifies system security requirements definitions and analysis and establishes system security design. \n

  • Designs, develops, implements and/or integrates IA and security systems and system components including those for networking, computing and enclave environment to include those with multiple enclaves and with differing data protection/classification requirements. \n

  • Assist architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of Agency security policy and enterprise solutions. \n

  • Contributes to the security planning, assessment, risk analysis, risk management, certification and awareness activities for system and networking operations. \n

  • Reviews C&A documentation, providing feedback on completeness and compliance of its content. \n

\n

\n

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.thejobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

5:46 min

Mocking repository endpoints with Mockito and REST Assured

Eric Deandrea Eric Deandrea · World Congress 2025

2:01 min

Migrating existing applications from MongoDB to Postgres

Nikita Shamgunov Nikita Shamgunov · World Congress 2024

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

5:31 min

Writing automated tests with Mockito and WireMock

Jakov Semenski · LIVE

1:21 min

Realizing the limitations of MongoDB for live statistics

Josip Stuhli Josip Stuhli · World Congress 2023

Videos

See all

Related articles

See all