Basic Qualifications
Bachelor's degree in Engineering, or a related Science or Mathematics field, plus a minimum of 2 years of relevant experience; or Master's degree, plus 6 months relevant experience.
Â
CLEARANCE REQUIREMENTS:Department of Defense Secret security clearance is required at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required.
Responsibilities for this Position
Â
What Sets You Apart
- Communicate technical cybersecurity topics clearly and effectively to diverse technical and non-technical audiences.
- Create an environment where the business and mission impact of cybersecurity, continuous monitoring, and risk decisions is clearly understood.
- Partner effectively with engineering, operations, and program teams to implement cybersecurity technologies, principles, and secure system practices.
- Apply a strong security mindset, including the ability to question system behavior, configurations, or operational activities that are inconsistent with security requirements and principles.
- Exercise sound judgment, initiative, and attention to detail when identifying, communicating, and driving corrective actions for cybersecurity risks.
Representative Duties and Tasks
- Serve in an Information System Security Officer (ISSO)-type capacity, supporting the system’s cybersecurity posture throughout development, deployment, operations, and sustainment.
- Perform continuous monitoring activities in accordance with RMF and program requirements, including reviewing security logs, audit records, alerts, vulnerability results, configuration changes, and security-relevant events.
- Analyze security events and log data to identify anomalous activity, potential indicators of compromise, control deficiencies, and compliance concerns; coordinate escalation and response activities as appropriate.
- Work with system development, deployment, and operations teams to implement and maintain secure system architectures, designs, configurations, and operational procedures.
- Champion the cybersecurity perspective in decisions related to the implementation, assessment, operation, and verification of security controls.
- Support the development, maintenance, and execution of Continuous Monitoring (ConMon) plans, including recurring security control assessments, evidence collection, status reporting, and risk tracking.
- Produce and maintain cybersecurity design documentation, system security documentation, security operating procedures, and other artifacts supporting authorization and ongoing system security.
- Produce and maintain the Security Control Traceability Matrix (SCTM), inheritable control sets, and control implementation statements to support test traceability and audit readiness.
- Lead or support NIST SP 800-37 Risk Management Framework (RMF) activities to develop and maintain the body of evidence required for security authorization and ongoing authorization activities.
- Coordinate with development, test, system administration, and operational teams to plan, implement, assess, and document security requirements and controls.
- Track security findings, vulnerabilities, control deficiencies, and remediation activities; support development and maintenance of Plans of Action and Milestones (POA&Ms).
- Review and map evidence from applicable security requirement sources—including STIGs, NCDSMO, DISA guidance, and customer requirements—within the SCTM and RMF evidence package.
- Support system accreditation/certification evaluation and test activities to ensure technical security features—including identification, authentication, access control, labeling, auditing, and accountability—are implemented and operating as intended.
- Participate actively in Agile teams to organize, prioritize, execute, and provide status for cybersecurity and continuous-monitoring work efforts.
- Contribute to incident-response preparedness and coordination by supporting log availability, audit configuration, event triage, reporting, and post-event corrective actions.
- Plan and execute project tasks supporting the cybersecurity, ISSO, RMF, and continuous-monitoring activities described above.
Knowledge, Skills, and Abilities
- Strong security mindset and comfort questioning system behavior or operational practices that conflict with key security principles.
- Experience reviewing, analyzing, and communicating the significance of security logs, audit records, alerts, and vulnerability data.
- Working knowledge of continuous monitoring, vulnerability management, incident reporting/escalation, security control assessment, and remediation tracking.
- Knowledge of NIST RMF, NIST SP 800-53 security controls, and DoD cybersecurity authorization processes.
- Self-directed, self-starting ability with the discipline to manage recurring monitoring, evidence collection, and reporting responsibilities.
- Ability to execute complex technical and administrative cybersecurity tasks with limited supervision.
- Excellent ability to communicate security issues, mission impacts, risk decisions, and corrective actions to technical teams, management, and customers.
- Ability to balance compliance, security risk, operational mission needs, and engineering constraints.
Preferred Experience
- Cybersecurity System Engineering, Information System Security Officer (ISSO) duties, Risk Management Framework, and Defense in Depth.
- Experience with security operations, security information and event management (SIEM) tools, log review, audit analysis, vulnerability management, and continuous monitoring.
- Experience supporting system authorization packages, annual/ongoing assessments, control validation, POA&M management, and authorization-to-operate (ATO) activities.
- Active cybersecurity certifications such as ISC2 CISSP (preferred), Security+, CEH, CAP, CISM, or similar credentials.
- Ground-to-satellite communications knowledge and/or ground operations experience.
- Experience performing requirements analysis, requirements definition, requirements management, functional analysis, performance analysis, system design, and technical trade studies under the leadership of a Lead Cybersecurity System Engineer.
- Experience analyzing customer requirements, developing system security requirements, and defining allocations to lower-level elements and components.
- Experience developing and evaluating systems, networks, and information systems to ensure designs meet applicable government security specifications.
- Experience with Secure Software Factory and Secure DevSecOps practices.
- Multi-level security domain expertise and cross-domain solution familiarity.
- Ability to decompose security requirements quickly using an Agile, lightweight approach while avoiding unnecessary requirements bloat and clearly communicating and tracking impacts.
- Experience supporting programs or organizations with relationships across partners such as Iridium, SDA, Northrop Grumman, York, and Lockheed Martin.
- Agile program experience.
- Active DoD Secret clearance required; TS/SCI preferred.
- Work will be five days a week at U.S. Army Garrison – Redstone Arsenal (USAG-RSA)
Our Commitment to You
- An exciting career path with opportunities for continuous learning and development.
- Research-oriented work alongside award-winning teams developing practical solutions for our nation’s security.
- Flexible schedules
- Competitive benefits, including 401(k) matching, flexible time off, paid parental leave, healthcare benefits, health and wellness programs, employee resource and social groups, and more.
Salary Note
This estimate represents the typical salary range for this position based on experience and other factors (geographic location, etc.). Actual pay may vary. This job posting will remain open until the position is filled.Combined Salary Range
USD $100,219.00 - USD $111,180.00 /Yr.Company Overview
General Dynamics Mission Systems (GDMS) engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. With a global team of 12,000+ top professionals, we partner with the best in industry to expand the bounds of innovation in the defense and scientific arenas. Given the nature of our work and who we are, we value trust, honesty, alignment and transparency. We offer highly competitive benefits and pride ourselves in being a great place to work with a shared sense of purpose. You will also enjoy a flexible work environment where contributions are recognized and rewarded. If who we are and what we do resonates with you, we invite you to join our high-performance team!
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans
Learn more about this Employer on their Career Site
