> Markdown version of [/jobs/ext/3099304-cyber-systems-security-engineering-stf-e4](https://www.wearedevelopers.com/jobs/ext/3099304-cyber-systems-security-engineering-stf-e4). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Systems Security Engineering Stf - E4 - **Company:** Lockheed Martin - **Location:** Las Vegas, NV, United States - **Experience:** Expert - **Salary:** $70,000.0 - $80,000.0 - **Contract:** Permanent contract - **Skills:** C (Programming Language), Java (Programming Language), Agile Methodology, Software System Penetration Testing, JIRA, C++ (Programming Language), Configuration Management, Static Program Analysis, Cyber Security, Information Systems, Computer Engineering, Embedded Operating Systems, Real-Time Operating Systems, SAP (Applications), Security Content Automation Protocol, Software Engineering, Subsystems, VersionOne, VxWorks, Information Security Management System, SC Clearance, Yocto, Information Technology, Nessus, Plan of Action and Milestones, Vulnerability Analysis, Programming Languages - **Published:** September 26, 2026 - **Apply:** https://www.careerjet.com/job/us0975426746b2303667e6bf1a494341e8/eaa ## About the Role * Acitve Secret Clearance * IASAE Level II - IAW 8570 or higher certification (CASP+ CE, CISSP, CSSLP) * Ability to travel as required (typically up to 20%) ## Desired Skills * B.S. degree in a technical discWine such as Computer Science, Computer Engineering, Electrical Engineering, Computer Security, or Information Technology - or equivalent applied experience * Experience utilizing Joint Special Access Program (SAP) Implementation Guide (JSIG), Committee on National Security Systems Instruction (CNSSI) 1253, and NIST sp 800-37 Risk Management Framework (RMF) to design and harden information systems commensurate with customer needs * Ownership of, or ability to acquire and maintain, a CAC Card is strongly desired * Experienced with ACAS software (Nessus and Tenable. SC) * Ability to troubleshoot ACAS software (Nessus and Tenable.SC) * Experienced with SCC SCAP tool to conduct compliance assessment * Ability to troubleshoot SCC SCAP tool * Have knowledge of Group Policy Management * STIG experience * Work alongside software team to find common ground on STIGs * Experience analyzing, decomposing, and allocating security controls into executable security requirements at the system, sub-system and component level * Experience with secure software development concepts (e.g. static code analysis, dynamic code analysis, STIG/SRG hardening, etc.) as applied to high-level programming languages (C, C++, Java) * Experience with engineering change processes and/or configuration control processes Extensive experience developing and maintaining core security documentation artifacts for A&A Packages including Security Control Traceability Matrix (SCTM), System Security Plan (SSP) and/or Information Assurance Standard Operating Procedures (IA SOP), Plan of Action & Milestones (POA&M), and Risk Assessment Report (RAR) * Extensive knowledge of DoD Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs) * Background/knowledge working with information systems/environments that utilize the Open Mission Systems (OMS) standard and Universal Command and Control Standards Initiative (UCI) message set * Expertise/knowledge in both compliance testing and penetration testing methodologies. * Experience with Real-Time Embedded Operating Systems (e.g. GreenHills INEGRITY, LynxOS, VxWorks, Yocto) * Experience with Agile project management tods (JIRA, VersionOne, etc.) * Experience conducting technical trade studies and assessments * Must be willing to mentor junior-level team members * Experience with creating and presenting technical information to senior-level executives and customers * Demonstrated problem-solving and troubleshooting skills * Proficient technical writing skills * Strong analytical and organizational skills with excellent communication skills (written and verbal communications) and have the ability to work in a dynamic work environment * Experience working in an aerospace design environment with exposure to DOD customers and their accrediting authorities. ## Description Responsible for applying an interdisciplinary, collaborative approach to plan, design, develop, validate and verify Cyber solutions across the lifecycle. Conduct cyber risk assessment activities including threat modeling, vulnerability analysis and analysis of mitigation solutions. Coordinates and addresses Supply Chain risk management concerns. Develop, evaluate and analyze design constrains, trade-offs and detailed system and security design as they pertain to the Cyber domain. Coordinate with Cyber and system architects and developers to provide oversight in the development of solutions. Conduct cybersecurity test and evaluation of hardware and/or software designs to verify and validate compliance with defined specifications and requirements. Employs cyber security processes, methods, techniques and tools and assure their consistent application. Implements appropriate Assessment and Authorization activities as required by customers. *USE OF THIS CLASSIFICATION REQUIRES AUTHORIZATION FROM THE BUSINESS AREA CYBER DIRECTOR OR DELEGATE* ## Related Videos - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Collaboration Quantified: Lessons from Open Source Developer Networks](https://www.wearedevelopers.com/videos/1422-collaboration-quantified-lessons-from-open-source-developer-networks) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Integrate your Cognitive Assistant with 3rd-party DBs and software](https://www.wearedevelopers.com/videos/249-integrate-your-cognitive-assistant-with-3rd-party-dbs-and-software) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)