U
Information Systems Security Engineer - Entry to Mid Level
Job Description
At the U.S. National Security Agency/Central Security Service (NSA), Information Systems Security Professionals help architect, design, operate, defend, and maintain secure IT systems that support NSA SIGINT and Cybersecurity missions. This onsite role at Fort Meade, Maryland applies full life-cycle security engineering to manage risk, remediate vulnerabilities, and maintain compliance with relevant standards.
Working within security engineering teams, you will contribute to securing hybrid environments, including cloud services, while supporting authorization and continuous monitoring activities. The position is a permanent, full-time appointment in the Excepted Service, with eligibility for benefits based on the type of appointment.
Responsibilities
- Design system and network architectures to enforce confidentiality, integrity, and availability.
- Apply systems engineering principles and methodology.
- Define and manage remediation plans across applications, infrastructure, and cloud environments.
- Ensure compliance with cybersecurity standards and regulatory requirements (for example NIST).
- Assess and mitigate risks in legacy systems, misconfigurations, and vulnerabilities.
- Analyze and prioritize vulnerabilities in collaboration with cross-functional teams.
- Lead and provide oversight for patching and hardening of infrastructure systems.
- Define information system security requirements and functionality.
- Review cloud service security configuration options and recommend secure configurations.
- Use knowledge of cryptography and programming capability (including Python and Java).
- Assess the effectiveness of security solutions against cybersecurity frameworks such as MITRE ATT&CK.
- Monitor cybersecurity hygiene for a family of IT systems and direct remediation of configuration and vulnerability findings to reduce adversary risk.
- Apply concepts, principles, structure, and standards to design, implement, monitor, and secure operating systems, equipment, networks, applications, and controls.
- Operate within teams implementing and evolving procedures and security settings for protecting data and applications in cloud environments.
- Conduct security engineering and hardening of the latest operating systems, tailoring them for specific mission needs.
- Implement automation and artificial intelligence across the RMF authorization life cycle into continuous monitoring.
Requirements
- All applicants and employees are subject to random drug testing in accordance with Executive Order 12564.
- Relevant experience must be in one or more areas such as computer or information systems design/development; programming; information/cyber/network security; system or network administration; vulnerability analysis; penetration testing; computer forensics; systems engineering; computer systems research; reverse engineering; or updating information assurance documentation (for example System Security Plans, Risk Assessment Reports, Certification and Accreditation packages, and System R…).
- Completion of military training in relevant areas (such as JCAC, UCT, NWBC/INWT, or Cyber Defense Operations) may count toward the relevant experience requirement, based on course duration.
- Cybersecurity certifications (for example NET+, Security+, CISSP, and CAP) may count as a total of 1 year of experience.
- Entry/Developmental: Associate’s degree plus 2 years of relevant experience, or a Bachelor’s degree with no experience.
- Full Performance: Associate’s degree plus 5 years of relevant experience; Bachelor’s degree plus 3 years of relevant experience; Master’s degree plus 1 year of relevant experience; or Doctoral degree with no experience.
- Degree must be in Computer Science or a related field (examples include Engineering, Mathematics, Data Science, Artificial Intelligence, Computer Forensics, Cybersecurity, Information Technology, Information Assurance, Information Security, Information Systems, Informatics, Cyber Operations, and Cyber Defense).
- Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of the American republic, and committed to upholding the rule of law and the U.S. Constitution.
Technologies
- Commercial cloud fabrics, artificial intelligence, and high performance computing
- Advanced cryptographic systems
- Python, Java
- NIST, MITRE ATT&CK, RMF authorization life cycle
- Amazon Web Services, Microsoft Azure, Oracle, and Google cloud environments
- NET+, Security+, CISSP, CAP
- NIST 800-53, ISO 27001, CI/CD pipelines, DevSecOps
- Container security, Kubernetes, Docker
Evaluation and Selection
- Understanding of security frameworks (for example NIST 800-53, ISO 27001, and CIS)
- Ability to prioritize and remediate vulnerabilities across hybrid network environments
- Cloud security knowledge across AWS, Microsoft Azure, Oracle, and Google cloud environments
- Familiarity with secure coding, DevSecOps, and CI/CD pipelines
- Capability to translate complex security issues into actionable guidance
- Understanding of vulnerability scanning tools
- Understanding of container security, including Kubernetes, Docker, and container hardening practices
- Understanding of threat modeling and mitigation design strategies
- Critical thinking and problem decomposition skills
How the Role Is Structured
- Location: Fort Meade, MD (onsite)
- Telework: No; Remote: No
- Relocation expenses reimbursed: Yes (in accordance with agency policy)
- Salary: $87,362 - $153,082 per year
- Pay scale & grade: GG 7 - 12; Work schedule: Full-time
- Travel: Occasional
- Appointment type: Permanent
- Occupations and job series: 0132 Intelligence; Supervisory status: No
- Federal service type: Excepted Service
- Drug test: Yes
- Security clearance: Top Secret
- Position sensitivity and risk: Critical-Sensitive (CS)/High Risk
- Background check type: National security
- Financial disclosure required: Yes
Open To
- The public: U.S. Citizens, Nationals, or those who owe allegiance to the U.S.
- Federal employees in the Excepted Service: current federal employees whose agencies have their own hiring rules, pay scales, and evaluation criteria
- Veterans, and eligible spouses, widows, widowers, or parents of veterans for derived preference
- Military spouses
- Individuals with disabilities eligible under Schedule A
Required Documents
- NSA positions are part of the DoD Intelligence Community Defense Civilian Intelligence Personnel System (DCIPS).
- All NSA positions are in the Excepted Services under 10 U.S.C. 1601 appointment authority.
- Veterans' Preference may apply to eligible candidates for DoD Components with DCIPS positions, as defined by Section 2108 of Title 5 U.S.C., following DoD Instruction 1400.25, Volume 2005.
- If claiming veterans' preference, you may be asked to submit documents verifying eligibility.
- If relying on education to meet qualification requirements, the education must be accredited by an accrediting institution recognized by the U.S. Department of Education.
- Failure to provide all required information as stated in the vacancy announcement may result in an ineligible rating or may affect the overall rating.
Agency Contact
- Phone: 1-844-424-4737
- Email: [email protected]