BAE Systems is a defense, aerospace, and security company serving national security missions across air, land, maritime, space, and cyber. This junior information system security engineer will provide security engineering support for secure systems and networks, manage cyber requirements, validate technical implementations, and support Assessment and Authorization activities. The role also involves security assessments, incident response, risk management, compliance with NIST and customer security processes, and collaboration with cross-functional teams.
Supports the development, review, and advisement of programs on the engineering design, development, and deployment of secure systems, networks, and applications
Assists in validating and verifying system security requirements definitions and analysis and establishes system security designs
Supports maintaining and promoting a comprehensive and holistic cybersecurity engineering view while addressing stakeholder security risks and concerns through the application of systems engineering skills
Support security incident response and investigation activities, including root cause analysis and remediation efforts, collaborating with cross-functional teams, including Engineering, IT, Operations, and Compliance
Perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations and recommend mitigation strategies
Assist in the identification and implementation of appropriate information security functionality to ensure uniform application of customer security policy and enterprise security solutions
Assess and mitigate system security threats/risks throughout the program life cycle
Contribute to the security planning, assessment, risk analysis, risk management, certification and accreditation activities for system and network operations
Develop Assessment and Authorization (A&A) documentation, providing feedback on completeness and compliance of its content
Support security authorization activities in compliance with the NIST Risk Management Framework (RMF) and customer processes for security engineering
Creatively identify ways to provide security compliance while minimally impacting day-to-day operations
Identify, review, and define cybersecurity requirements that enable technical Architects / Systems Engineers and SMEs to secure hardware and software products
Develop, review, and recommend security policy, guidance, training, and best practices that align its implementation across the mission acquisition lifecycle
May interface with Program Managers (PMs), IPT Leads and customer security stakeholders
Maintain a regular and predictable work schedule
Establish and maintain effective working relationships within the department, the Strategic Business Units, Strategic Capabilities Units and the Company. Interact appropriately with others in order to maintain a positive and productive work environment
Perform other duties as necessary
Qualification
Required
BS degree or higher in Engineering or a related technical field is required plus 2 or more years related experience
Each higher-level degree, i.e., Master's Degree or Ph.D., may substitute for two years of experience. Related technical experience may be considered in lieu of education. Degree must be from a university, college, or school which is accredited by an agency recognized by the US Secretary of Education, US Department of Education
A current, active TS/SCI CI Polygraph security clearance is required
Knowledge of information security principles, practices, technologies, and standards, including NIST Standards (800-37, 800-53), DISA STIGs, and CIS benchmarks
Hands-on knowledge of cyber-enabling tools like Splunk, Tenable SC/ACAS, HBSS
Familiarity with DevSecOps concepts and software security engineering principles
Preferred
CISSP-ISSEP certification
Experience with Cloud-based security solutions, AWS preferred
Experience with the MITRE ATT&CK Framework
Benefits
For regular employees scheduled to work 20+ hours per week: health, dental, and vision insurance
For regular employees scheduled to work 20+ hours per week: health savings accounts
For regular employees scheduled to work 20+ hours per week: a 401(k) savings plan
For regular employees scheduled to work 20+ hours per week: disability coverage
For regular employees scheduled to work 20+ hours per week: life and accident insurance
For regular employees scheduled to work 20+ hours per week: an employee assistance program
For regular employees scheduled to work 20+ hours per week: a legal plan
Discounts on home, auto, and pet insurance
Paid time off
Paid holidays
Paid parental leave
Paid military leave
Paid bereavement leave
Applicable federal and state sick leave
Employees may participate in the company recognition program to receive monetary or non-monetary recognition awards
Other incentives may be available based on position level and/or job specifics
BAE Systems is an aerospace, defence, and information security company that provides advanced and technology-led solutions.
Glassdoor
3.6
Founded in 1999
London, England, GBR
10001+ employees
http://www.baesystems.com
BAE Systems is an aerospace, defence, and information security company that provides advanced and technology-led solutions.