L3Harris Senior, Information Systems Security Engineer in Colorado Springs, Colorado
Job Title: Senior Specialist, Information Security Systems Engineer
Job Code: SAS20231603-98471
Job Location: Colorado Springs, CO
Applies current systems security engineering methods, practices and technologies to the architecture, design, development, evaluation and integration of systems and networks to maintain system security. Works closely with Government customers to ensure that the security protection needs, concerns and requirements are defined and implemented with appropriate fidelity and rigor, early and in a sustainable manner throughout the life cycle of system that will allow for the security authorization of the system of interest. Works with systems developers or commercial product vendors in the design and evaluation of state-of-the-art secure systems, networks, and database products. Uses methods such as encryption technology, vulnerability analysis and security management. Responsible for integration of multiple methods into a cohesive system security perimeter and environment and the policies and procedures necessary to monitor and maintain such an environment. Will prepare Certification and Accreditation documentation, using multiple standards under RMF and derivitive processes (DOD 8510, JSIG, ICD-503, CNSSI 1253), to achieve security authorization of supported systems. Represents program security needs, concerns and requirements at customer meetings.
Experience in Static Application Security Testing (SAST) for Application Security and Development STIG compliance using tools such as Fortify and Gitlab as part of a DevSecOps Continuous Integration/Continuous Deployment (CI/CD) Pipeline, and generation of summary reports.
Experience in Risk Management Framework (RMF) accreditation and authorization (A&A) processes to include RMF steps 1-4 (categorization, controls selection, control implementation, security assessment) and standard body of evidence (BoE) package development.
Experience in DoD software selection and approval processes for COTS, GOTS and FOSS.
Experience in the application of DISA SRGs and STIGs.
Support security engineering activities, including basis of estimate development, requirements development, design, test, configuration management and maintenance of information systems and data.
Assist program security in the development of policies and procedures for emerging security technologies.
Support vulnerability assessment activities as required.
Support the evaluation, qualification, testing and delivery of security architecture improvement, obsolescence replacement and vulnerability response projects.
Experience in configuration and use of cyber defense and vulnerability assessment tools such as ACAS and SCC.
Work is 100% on-site and cannot be accomplished remotely.
Bachelor’s Degree and minimum 6 years of prior relevant experience, or
Graduate Degree and a minimum of 4 years of prior related experience.
Top Secret / SCI security clearance required.
DOD 8140.03M IAT-3 or IASAE-2 certification.
Preferred Additional Skills:
Experience in C2S Cloud authorizations, FedRAMP and DISA CSP requirements.
Windows and Linux system administration skills.
Experience in the content development and administration of SEIM/audit reduction tools (e.g., Splunk).
DOD 8140.03M IASAE-3 certification is desired.
Strong understanding of engineering processes, concepts and information security systems engineering principles (NIST SP 800-160 Vol1).
System test and evaluation methods and RMF assessment methodology & process.
Experience in Cyber Defense technologies.
Understanding of system vulnerabilities and exploitation.
Top Secret / SCI with an active CI Polygraph is highly desired.
Experience with cross domain systems.
In compliance with Colorado’s Equal Pay for Equal Work Act, the salary range for this role in Colorado is $87000 - $162000 (salary ranges in other locations could differ). This is not a guarantee of compensation or salary, as final offer amount may vary based on factors including but not limited to experience and geographic location. L3Harris also offers a variety of benefits including: health and disability insurance, 401(k) match, flexible spending accounts, EAP, education assistance, parental leave, paid time off, and company-paid holidays. The specific programs and options available to an employee may vary depending on date of hire, schedule type, and the applicability of collective bargaining agreements
L3Harris Technologies is proud to be an Affirmative Action/Equal Opportunity Employer. L3Harris is committed to treating all employees and applicants for employment with respect and dignity and maintaining a workplace that is free from unlawful discrimination. All applicants will be considered for employment without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender (including pregnancy, childbirth, breastfeeding or other related medical conditions), gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, characteristic or membership in any other group protected by federal, state or local laws. L3Harris maintains a drug-free workplace and performs pre-employment substance abuse testing and background checks, where permitted by law.