Four BAE Systems employees standing in front of a digital jet, combat vehicle. marine vessel, and space satellite.
BAE Systems, Inc. Logo

BAE Systems, Inc.

Senior Systems Security Engineer ISSE

Posted 13 Days Ago
Be an Early Applicant
Hybrid
Quantico, VA
130K-222K Annually
Senior level
Hybrid
Quantico, VA
130K-222K Annually
Senior level
The ISSE role involves managing information system security for networks, ensuring compliance with policies, conducting vulnerability assessments, and preparing documentation for security authority approvals.
The summary above was generated by AI

Job Description
BAE Systems is excited to offer an opportunity to support a dynamic DOJ program as an Information Systems Security Engineer (ISSE), providing mission critical support to our federal law enforcement customer. If you are looking for an opportunity to help shape the future architecture for client forensic networks, work with a very diverse team of technical professionals, and share your knowledge and experiences, then this position if for you!
This position is part of a talented technical team responsible for the ongoing development, operations and maintenance of several networked systems supporting digital forensic investigations running primarily on Windows and utilizing virtual and cloud environments. The ideal candidate must be a self-starter with strong work habits, is able to complete task independently while working as part of a team, and have demonstrated career experience as an ISSO or ISSE and with the Federal ATO process.
Some duties of the position include:
Functional Responsibilities: Senior level capabilities regarding Information system security. Knowledgeable of current Information Assurance (IA) technologies to the architecture, design, development, evaluation, and integration of applications, systems, and networks to maintain the system security posture. Develops compliancy and standardization within the customer's policies regarding various information systems. Work closely with Government customers to ensure the confidentiality, integrity, and availability of systems, applications, networks, and data through the planning, analysis, development, implementation, maintenance, and enhancement of information systems security programs; infrastructure; application; Security Assessment and Authorization (SAA), IA policy directives (PD) and guides (PG); and IA Security tools (e.g., Tenable.io, Nessus Pro, NMap, etc.). The Contractor shall:
Have excellent verbal and written communication skills to be able to accurately relate requirements and document all within the appropriate security document and/or within the RMF system and coordinate with program, other system(s), and security personnel;
Prepare documentation from templates such as, but not limited to, Configuration Management Plan (CMP), Incident Response Plan (IRP), Information System Contingency Plan (ISCP), and Plan of Action and Milestones (POA&M) to ensure compliance with customer PDs and PGs and Federal IA requirements as well as coordinate review(s) and approvals;
Must be able to discern the program policies and procedures, identify areas that need work and bring up to management for resolution;
Identify IA vulnerabilities and coordinate with the Infrastructure and Development teams to correct, mitigated or apply for an exception via the POA&M processes;
Review vulnerability (i.e., patches, updates, etc.) and compliance (i.e., Security Content Automation Protocol (SCAP) and/or Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG)) scans on the infrastructure and applications to ensure patch and configuration compliance (on-premises and in the cloud (Azure preferred))
Prepares SAA package(s) to obtain and maintain an authority-to-operate (ATO), authority-to-test (ATT), or other SAA authority types for all systems and applications;
Attend Configuration Control Board (CCB) meetings and review all change requests for impact to the system/application security posture(s) and applicable Federal and customer PD and PG compliance requirements; and document decisions within the CMP;
Coordinate security incident and high priority compliance responses with the Enterprise Security Operations Center (ESOC);
Represent program security interests in various meetings within and outside of the program;
Schedule and conduct meetings with pertinent program personnel to address findings to determine appropriate path forward and document within the CMP and, if necessary, POA&M;
Coordinates with other system Information System Security Officers (ISSO) to ensure that their requirements for interconnection, policy and procedures are met and all documentation is provided and updated as necessary;
Ability to assess current and evolving security threats in an operational environment;
With an appropriate amount of Government PM guidance, works independently to carry out all technical requirements as directed by the Government PM, Information System Security Representative, Information System Security Manager, and Authorizing Official in a timely manner.
Required Education, Experience, & Skills
Ten (10) years of experience or more assessing and documenting results for system(s), infrastructure(s) and applications (on-premises and cloud (i.e., AWS GovCloud and/or Azure GovCloud)) against NIST SP 800-53 security controls and SP 800-171 Risk Management Framework (RMF) processes.
:Bachelor of Science (B.S.) Degree in Computer Security or related field of study; (ISC)2 Information Security Certification(s) (e.g., CISSP, CAP, etc.); or in lieu of education, an additional five (5) years of relevant experience that addresses all requirements of the position.
Day to Day expectations:

  • Experience working on an Agile team
  • Experience working with a federal law enforcement organization
  • Willingness to implement Lean principles, Agile engineering and DevSecOps
  • Desire longevity on the project.
  • Technical background desired, knowledge broader in scope.
  • Have an understanding of taclans, basic coding, and scripts.
  • Splunk and Tenable experience desired.
  • Need to be able to read technical diagrams, dataflows, create workflows, read network diagrams. Understand JRC and the 6 steps of the Risk Management Framework.
  • Have a team perspective, invite collaboration, the personality needs to be one of investment. Need to connect and to learn. Be function driven. They need to have an accountability to the program, be on time, personable, positive.


Preferred Education, Experience, & Skills

  • Experience in a cyber-risk and compliance management system (e.g., Xacta, RiskVision, etc.);
  • One (1) year experience or more configuring, performing, scheduling, reviewing, and assessing vulnerability (i.e., patches, updates, etc.) and compliance (i.e., Security Content Automation Protocol (SCAP) and/or Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG)) scans on the infrastructure and applications to ensure patch and configuration compliance on-premises and in the cloud (Azure preferred);
  • Technical background that will assist in assessing the NIST SP 800-53 security controls and gather evidence to support conclusions;
  • Knowledge of operating systems, network and application security to aid implementation of information security and assurance principles;
  • Knowledge of SPLUNK software and tools; and
  • Knowledge of Taclane, encryption devices and COMSEC technology.


Pay Information
Full-Time Salary Range: $130355 - $221603
Please note: This range is based on our market pay structures. However, individual salaries are determined by a variety of factors including, but not limited to: business considerations, local market conditions, and internal equity, as well as candidate qualifications, such as skills, education, and experience.
Employee Benefits: At BAE Systems, we support our employees in all aspects of their life, including their health and financial well-being. Regular employees scheduled to work 20+ hours per week are offered: health, dental, and vision insurance; health savings accounts; a 401(k) savings plan; disability coverage; and life and accident insurance. We also have an employee assistance program, a legal plan, and other perks including discounts on things like home, auto, and pet insurance. Our leave programs include paid time off, paid holidays, as well as other types of leave, including paid parental, military, bereavement, and any applicable federal and state sick leave. Employees may participate in the company recognition program to receive monetary or non-monetary recognition awards. Other incentives may be available based on position level and/or job specifics.
About BAE Systems Intelligence & Security
BAE Systems, Inc. is the U.S. subsidiary of BAE Systems plc, an international defense, aerospace and security company which delivers a full range of products and services for air, land and naval forces, as well as advanced electronics, security, information technology solutions and customer support services. Improving the future and protecting lives is an ambitious mission, but it's what we do at BAE Systems. Working here means using your passion and ingenuity where it counts - defending national security with breakthrough technology, superior products, and intelligence solutions. As you develop the latest technology and defend national security, you will continually hone your skills on a team-making a big impact on a global scale. At BAE Systems, you'll find a rewarding career that truly makes a difference.
Intelligence & Security (I&S), based in McLean, Virginia, designs and delivers advanced defense, intelligence, and security solutions that support the important missions of our customers. Our pride and dedication shows in everything we do-from intelligence analysis, cyber operations and IT expertise to systems development, systems integration, and operations and maintenance services. Knowing that our work enables the U.S. military and government to recognize, manage and defeat threats inspires us to push ourselves and our technologies to new levels.

Top Skills

Aws Govcloud
Azure
Nessus Pro
Nist Sp 800-53
Nmap
Rmf
Sp 800-171
Splunk
Tenable.Io

Similar Jobs at BAE Systems, Inc.

6 Hours Ago
Hybrid
Quantico, VA, USA
116K-197K Annually
Expert/Leader
116K-197K Annually
Expert/Leader
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
The Senior Systems Security Engineer will oversee system security for forensic networks, ensuring compliance, conducting vulnerability assessments, and collaborating with technical teams and government customers.
Top Skills: AWSAzureNessus ProNmapSplunkTenable.IoWindows
6 Hours Ago
Hybrid
Quantico, VA, USA
116K-197K Annually
Expert/Leader
116K-197K Annually
Expert/Leader
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
The Senior Systems Security Engineer will oversee system security for forensic networks, ensuring compliance, conducting vulnerability assessments, and collaborating with technical teams and government customers.
Top Skills: AWSAzureNessus ProNmapSplunkTenable.IoWindows
Yesterday
Hybrid
McLean, VA, USA
141K-239K Annually
Senior level
141K-239K Annually
Senior level
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
The Transformation/Process Improvement SME will enhance USACE's IT services using cloud solutions and ITIL practices, improving overall performance and service delivery.
Top Skills: AWSCiscoItilItsmMicrosoft Cloud

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account