Senior Specialist, Information Security Systems Engineer
Palm Bay, Florida; Rochester, New York
Job ID 43113L3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do. Our employees are unified in a shared dedication to our customers’ mission and quest for professional growth. L3Harris provides an inclusive, engaging environment designed to empower employees and promote work-life success. Fundamental to our culture is an unwavering focus on values, dedication to our communities, and commitment to excellence in everything we do.
L3Harris is the Trusted Disruptor in defense tech. With customers’ mission-critical needs always in mind, our employees deliver end-to-end technology solutions connecting the space, air, land, sea and cyber domains in the interest of national security.
Job Title: Senior Specialist, System Security Engineer - Secret Clearance
Job Code: 43113
Job Location: Palm Bay, FL or Rochester, NY
Job Schedule: 9/80: Employees work 9 out of every 14 days – totaling 80 hours worked – and have every other Friday off
Job Description:
Applies current Systems Security Engineering methods, practices, and technologies to the architecture, design, development, evaluation, and integration of systems and networks to maintain system security. Works closely with Government customers to ensure that the security protection needs, concerns, and requirements are defined and implemented with appropriate fidelity and rigor, early and in a sustainable manner throughout the life cycle of system that will allow for the security authorization of the system of interest. Works with systems developers or commercial product vendors in the design and evaluation of state-of-the-art secure systems, networks, and database products. Uses methods such as encryption technology, vulnerability analysis, and security management. Responsible for integration of multiple methods into a cohesive system security perimeter and environment and the policies and procedures necessary to monitor and maintain such an environment. Will prepare Certification and Accreditation documentation, using multiple standards under RMF and derivative processes (DOD 8510, JSIG, ICD-503, CNSSI 1253), to achieve security authorization of supported systems. Represents program security needs, concerns and requirements at customer meetings.
Essential Functions:
- Program Protection and System Security Engineering experience to include support of accreditation activities.
- Lead the development and implementation of System Security Engineering throughout the System Development Lifecycle.
- Assess systems for Critical Program Information (CPI).
- Conduct trade studies and develop System Security Engineering requirements.
- Assess threats via attack/countermeasure analysis.
- Conduct Verification and Validation activities.
- Use DoD 5200.39 for the identification and protection of CPI.
- Engineer trustworthy and secure systems in accordance with NIST 800-160.
- Develop and implement comprehensive Program Protection Plans (PPP) to safeguard critical program information (CPI) and technologies.
- Draft Program Protection Plans (PPPs), Cybersecurity Strategies, Security Classification Guides (SCGs), and System Security Engineering Plans.
- Interact with customers to define System Security Engineering requirements, solutions, trades, costs, implementation, system impacts, and effectiveness.
- Experience with DOD 5200.39.
- Experience in Risk Management Framework (RMF) accreditation and authorization (A&A) processes to include RMF steps 1-4 (categorization, controls selection, control implementation, security assessment) and standard body of evidence (BoE) package development.
- Experience with A&A package processing and RMF accreditation of Platform IT (PIT) systems
- Assess security and privacy controls in embedded systems using NIST 800-53
- Experience in DoD software selection and approval processes for COTS, GOTS and FOSS.
- Support security engineering activities, including basis of estimate development, requirements development, design, test, configuration management and maintenance of information systems and data.
- Assist program security in the development of policies and procedures for emerging security technologies.
- Collaborate with customers, internal program teams, and leadership to address program needs.
- Support vulnerability assessment activities as required.
- Support the evaluation, qualification, testing and delivery of security architecture improvement, obsolescence replacement and vulnerability response projects.
- Experience with Security Testing and Verification
- Work is to be accomplished 100% onsite, in a lab environment, with no options for remote support.
- Ability to obtain and maintain a DOD 8140 certification (or NIST 800-181), appropriate for the position within 6 months of start
Qualifications:
- Bachelor’s Degree and minimum 6 years of prior relevant experience. Graduate Degree and a minimum of 4 years of prior related experience. In lieu of a degree, minimum of 10 years of prior related experience.
- Minimum of Collateral Secret security clearance required.
Preferred Additional Skills:
- Program Protection and System Security Engineering experience.
- Prior or current experience with the development and implementation of System Security Engineering for the protection of CPI throughout the System Development Lifecycle.
- Prior or current experience with Risk Management Frame A&A on embedded systems.
- Prior or current experience with developing and High Assurance Device certification on embedded systems
- Experience in configuration and use of cyber defense and vulnerability assessment tools such as ACAS and SCC.
- Experience in Model-Based Systems Engineering (MBSE).
- NSA Type 1 Certification of cryptographic high value products.
- Experience with NSA High Assurance products and IASRD requirements.
- Experience in the application of DISA SRGs and STIGs.
- Windows and Linux system administration skills.
- Experience in the content development and administration of SEIM/audit reduction tools (e.g., Splunk).
- DOD 8140 IASAE certification is desired.
- Strong understanding of engineering processes, concepts and information security systems engineering principles (NIST SP 800-160 Vol1).
- System test and evaluation methods and RMF assessment methodology & process.
- Experience in Cyber Defense technologies.
- Experience with CI/CD, agile system development, and DevSecOps tools and processes.
- Understanding of system vulnerabilities and exploitation.
- Top Secret / SCI with an active Poly is highly desired.
In compliance with pay transparency requirements, the salary range for this role in New York state is $92,500 - $171,500. This is not a guarantee of compensation or salary, as final offer amount may vary based on factors including but not limited to experience and geographic location. L3Harris also offers a variety of benefits, including health and disability insurance, 401(k) match, flexible spending accounts, EAP, education assistance, parental leave, paid time off, and company-paid holidays. The specific programs and options available to an employee may vary depending on date of hire, schedule type, and the applicability of collective bargaining agreements.
#LI-KT1
L3Harris Technologies is proud to be an Equal Opportunity Employer. L3Harris is committed to treating all employees and applicants for employment with respect and dignity and maintaining a workplace that is free from unlawful discrimination. All applicants will be considered for employment without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender (including pregnancy, childbirth, breastfeeding or other related medical conditions), gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, characteristic or membership in any other group protected by federal, state or local laws. L3Harris maintains a drug-free workplace and performs pre-employment substance abuse testing and background checks, where permitted by law.
Please be aware many of our positions require the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. In addition, applicants who accept a conditional offer of employment may be subject to government security investigation(s) and must meet eligibility requirements for access to classified information.
By submitting your resume for this position, you understand and agree that L3Harris Technologies may share your resume, as well as any other related personal information or documentation you provide, with its subsidiaries and affiliated companies for the purpose of considering you for other available positions.
L3Harris Technologies is an E-Verify Employer. Please click here for the E-Verify Poster in English or Spanish. For information regarding your Right To Work, please click here for English or Spanish.