Principal Systems Security Engineer (Cyber) - P4
Job Description
This onsite role in Massachusetts leads Systems Security Engineering activities to define requirements, architect security solutions, ensure RMF/NIST controls, and support bids and proposals.
Responsibilities
- Collaborate with the customer to establish SSE requirements, evaluate solutions, perform trade studies, estimate costs, plan implementations, assess system impact, and measure effectiveness
- Prepare project plans and estimates, manage task execution, monitor progress, produce status reports, and identify and mitigate risks
- Ensure compliance with NIST RMF controls
- Provide guidance and support to program management on SSE architecture and related issues
- Support the development of bids and proposals
- Define security development and testing activities for implementing controls across networking devices, databases, operating systems, and hardware/software components
- Integrate cybersecurity development activities into program execution
- Develop high level system requirements and decompose them into subsystem requirements and implementation concepts
- Maintain understanding of DoD technology release and export licensing policies to ensure compliance
Requirements
- A Bachelor’s degree in Science, Technology, Engineering or Mathematics (STEM) and eight years of relevant experience
- U.S. citizenship and an active, transferable Secret security clearance required prior to start; only U.S. citizens are eligible for clearance
- Experience in System Security Engineering or Cybersecurity Engineering
- Experience with NIST Risk Management Framework (RMF)
Technologies
- Splunk
- Bash scripting
- Python scripting
- NIST RMF
Benefits
- Medical insurance
- Dental insurance
- Vision insurance
- Life insurance
- Short-term disability
- Long-term disability
- 401(k) match
- Flexible spending accounts
- Flexible work schedules
- Employee assistance program
- Employee Scholar Program
- Parental leave
- Paid time off
- Holidays
- Relocation assistance
Qualifications We Prefer
- Managerial or leadership experience
- Experience with security toolsets including antivirus, vulnerability assessment, host-based or network IDS/NIPS, multi-factor authentication, SIEM and centralized auditing; familiarity with Splunk is a plus
- Linux Bash scripting or Python scripting experience
- Security systems engineering across hardware, software, operating systems, and applications in stand-alone and LAN/WAN configurations
- DoD DoDI 8570.01-M IAT Level II compliant certification (for example Security+ or CISSP or equivalent)
- Security features and vulnerability analysis of various operating systems as defined by intelligence agencies
- IT, network, and system security administration experience, including OS security configuration and account management practices for UNIX, Windows, Red Hat Enterprise Linux, and Cisco systems
- Understanding of Systems Engineering requirements, specifications, and experience implementing DoD and Federal IA Certification and Accreditation Processes, IA controls, and related certification and accreditation documentation
- Familiarity with Program Protection Plan requirements under DoDI 5000.02 and DoDI 5200.39
- Experience supporting U.S. Government contract proposals as an Information Assurance Engineer subject matter expert