L3Harris Technologies
L3Harris Technologies
L3Harris Technologies develops aerospace and defense technologies for missions across air, land, sea, space, and cyber environments. Its work includes autonomous systems, command and control, electronic warfare, and resilient communications, serving national security organizations and commercial customers. The company brings together engineering and technology teams focused on solving complex operational challenges through advanced, mission-oriented systems.

Lead Information Security Systems Engineer - Chantilly, VA

Lead information security engineering for L3Harris government and national security systems in Chantilly. Design, accredit, and sustain secure on-premises and cloud architectures.

Description

  • Guide engineering teams in defining, designing, implementing, documenting, testing, and sustaining security solutions for National Security Systems and government customer systems.
  • Apply NIST RMF, NIST SP 800-37, 800-53, and 800-171, along with CNSSI 1253, JSIG, and FIPS, to support certification and system accreditation.
  • Collaborate with system developers and commercial vendors to design and evaluate secure systems, networks, and database products.
  • Use encryption technologies, vulnerability analysis, and security management practices to address system security needs.
  • Prepare RMF and security documentation, including system security plans, traceability matrices, monitoring plans, assessment plans, security concepts of operations, and POA&Ms.
  • Implement and assess security controls, establish baselines and overlays, apply controls to computing and network nodes, and verify their implementation.
  • Support systems and software engineering activities involving data flow diagrams, interface control documents, trade studies, SAST, STIG compliance, and summary reports.
  • Define and manage security architectures, system boundaries, vulnerability management programs, and risk mitigation and remediation strategies.
  • Configure and operate defense and assessment tools across on-premises data centers and secure cloud environments.
  • Support IaaS, PaaS, and SaaS implementations while developing Configuration Management Plans.
  • Travel up to 10% as required.

Requirements

  • Bachelor’s degree with at least 9 years of relevant experience, or a graduate degree with at least 7 years of related experience.
  • In lieu of a degree, at least 13 years of related experience.
  • Active Top Secret security clearance is required.
  • Active TS/SCI clearance with polygraph is highly desired.
  • DoD 8140.03 IASAE Level 2 certification.
  • Experience with the NIST Risk Management Framework and related NIST publications.
  • Experience preparing System Security Plans, Security Control Traceability Matrices, Continuous Monitoring Plans, Security Assessment Plans and Procedures, Security Concepts of Operations, and Plans of Action and Milestones.
  • Experience implementing and assessing security controls.
  • Experience with data flow diagrams, interface control documents, trade studies, and Static Application Security Testing (SAST).
  • Experience with Fortify or Coverity, GitLab, and DevSecOps CI/CD pipelines.
  • Experience defining and managing systems and security architectures, vulnerability management, and risk mitigation and remediation strategies.
  • Experience with cloud IaaS, PaaS, and SaaS implementations and Configuration Management Plans.
  • Ability to work 100% onsite in Chantilly, Virginia.
  • Up to 10% travel may be required.

Benefits

  • Health and disability insurance.
  • 401(k) matching.
  • Flexible spending accounts.
  • Employee Assistance Program (EAP).
  • Education assistance.
  • Parental leave.
  • Paid time off.
  • Company-paid holidays.

Related Jobs