Information Systems Security Engineer - Entry to Mid Level
Job Description
At the US National Security Agency/Central Security Service, Information System Security Professionals support NSA SIGINT and Cybersecurity missions by engineering and defending secure IT environments end to end. This entry to mid level position focuses on designing and operating secure systems through full life-cycle security engineering, risk and vulnerability management, and adherence to established standards.
The work is performed onsite in Fort Meade, MD. The salary range for this role is USD 87,362 - 153,082 per year, with a GG 7 - 12 pay scale and grade. The appointment is Permanent, and the schedule is full-time with occasional travel possible.
Responsibilities
- Design system and network architectures to enforce confidentiality, integrity, and availability.
- Apply systems engineering principles and methodology to security engineering efforts.
- Define and manage remediation plans across applications, infrastructure, and cloud.
- Ensure compliance with cybersecurity standards and regulatory requirements, including NIST.
- Assess and mitigate risks in legacy systems, misconfigurations, and vulnerabilities.
- Analyze and prioritize vulnerabilities in coordination with cross functional teams.
- Lead and provide oversight for activities to patch and harden infrastructure systems.
- Define information system security requirements and functionality.
- Review security configuration options for cloud services and recommend security configurations.
- Use knowledge of cryptography and programming capability in languages such as Python and Java.
- Assess the effectiveness of security solutions against cybersecurity frameworks such as MITRE ATT&CK.
- Monitor cybersecurity hygiene for a family of IT systems and direct remediation of configuration and vulnerability findings to reduce adversary risk.
- Apply concepts, principles, structure, and standards used to design, implement, monitor, and secure operating systems, equipment, networks, applications, and controls.
- Operate within teams implementing and evolving procedures and security settings that protect data and applications in cloud environments.
- Conduct security engineering and hardening of the latest operating systems, tailoring them for specific mission needs.
- Implement automation and artificial intelligence across the RMF authorization life cycle into continuous monitoring.
Requirements
- All applicants and employees are subject to random drug testing in accordance with Executive Order 12564.
- Relevant experience may be in one or more areas including computer or information systems design and development, programming, information or cyber network security, system or network administration, vulnerability analysis, penetration testing, computer forensics, systems engineering, computer systems research, reverse engineering, or updating information assurance documentation (for example System Security Plans, Risk Assessment Reports, Certification and Accreditation packages, and System R).
- Completion of relevant military training such as JCAC, Undergraduate Cyber Training (UCT), NWBC/INWT, or Cyber Defense Operations may count toward relevant experience (course duration mapping to experience time is provided in the listing).
- Cybersecurity certifications such as NET+, Security+, CISSP, and CAP may count as a total of 1 year of experience.
- Entry / developmental: Associate's degree plus 2 years of relevant experience, or Bachelor's degree and no experience.
- Full performance: Associate's degree plus 5 years of relevant experience, or Bachelor's degree plus 3 years of relevant experience, or Master's degree plus 1 year of relevant experience, or Doctoral degree and no experience.
- Degree must be in Computer Science or a related field, including options listed such as Engineering, Cybersecurity, Information Assurance, Information Security, Information Systems, and Cyber Defense.
- Candidates should be committed to improving the efficiency of the Federal government, passionate about the ideals of the American republic, and committed to upholding the rule of law and the U.S. Constitution.
Technologies
- Commercial cloud fabrics
- Artificial intelligence
- High performance computing
- Advanced cryptographic systems
- Python, Java
- NIST, MITRE ATT&CK
- RMF authorization life cycle
- Amazon Web Services, Microsoft Azure, Oracle, Google cloud environments
- NET+, Security+, CISSP, CAP
- NIST 800-53, ISO 27001
- CI/CD pipelines, DevSecOps
- Container security, Kubernetes, Docker
How You Will Be Evaluated
- Understanding of security frameworks such as NIST 800-53 and ISO 27001.
- Experience prioritizing and remediating vulnerabilities across hybrid network environments.
- Cloud security knowledge for commercial cloud environments including AWS, Azure, Oracle, and Google cloud environments.
- Familiarity with secure coding, DevSecOps, and CI/CD pipelines.
- Ability to translate complex security issues into actionable guidance.
- Understanding of vulnerability scanning tools.
- Understanding of container security, including Kubernetes, Docker, and container hardening practices.
- Understanding of threat modeling and mitigation strategy design.
- Critical thinking to break complex problems into manageable parts.
Conditions of Employment
- Security clearance: Top Secret
- Position sensitivity and risk: Critical-Sensitive (CS)/High Risk
- Background check type: National security
- Drug test: Yes
- Financial disclosure required: Yes
Benefits
NSA offers a comprehensive benefits package, with eligibility depending on the type of position held and whether the role is full-time, part-time, or intermittent.
Required Documents
- NSA is part of the DoD Intelligence Community Defense Civilian Intelligence Personnel System (DCIPS).
- All positions are in the Excepted Services under 10 USC 1601 appointment authority.
- DoD Components with DCIPS positions apply Veterans' Preference to eligible candidates under the procedures referenced in the listing.
- Veterans claiming veterans' preference may be asked to submit documents verifying eligibility.
- If relying on education for qualification: education must be accredited by an accrediting institution recognized by the U.S. Department of Education.
- Failure to provide all required information may result in an ineligible rating or may affect the overall rating.
Additional Information
- Telework eligible: No
- Remote job: No
- Relocation expenses reimbursed: Yes (you may qualify under agency policy)
- Occupations and job series: 0132 Intelligence
- Supervisory status: No
- Federal service type: Excepted Service
- Represented by a union: No
- Promotion potential: None
- Appointment type: Permanent
- Work schedule: Full-time
Who This Job Is Open To
- The public (U.S. Citizens, Nationals, or those who owe allegiance to the U.S.)
- Federal employees in Excepted service
- Veterans (and eligible derived preference categories as stated in the listing)
- Military spouses (including eligibility categories listed)
- Individuals with disabilities eligible under Schedule A
Agency Contact Information
- Phone: 1-844-424-4737
- Email: [email protected]