Security Engineer (Multiple Levels)
Job Description
Noblis is hiring for a Security Engineer (Multiple Levels) role supporting FAA systems and applications across the system development life cycle. This position combines hands-on security engineering and assessment work with compliance support, helping teams plan, document, and implement security controls in line with federal and FAA expectations. Remote work is available.
Salary: USD 71,010 - 240,350 per year. Minimum experience: 2 years. Education: Bachelor’s degree in any engineering field.
What You’ll Do
- Provide information systems security analysis, design support, and implementation assistance
- Conduct system engineering studies and security assessments, including identifying security risks, vulnerabilities, and threats and recommending mitigation strategies
- Perform preliminary vulnerability testing early in the system development life cycle
- Analyze the security impacts of system changes and modifications
- Support Certification and Authorization (C&A) activities and associated documentation
- Implement and sustain FAA Information Systems Security Program (ISSP) controls
- Develop and maintain System Security Plans (SSP), Security Impact Analyses, and POA&M documentation
- Ensure compliance with FAA directives, federal regulations, and NIST standards (including NIST 800-53)
- Support processing of Security Certification and Authorization Process (SCAP) requirements
- Apply security subject matter expertise across multiple domains, including access control systems, network and telecommunications security, application and systems development security, cryptography, security architectures and models, and operations security
- Support security testing, validation, and acceptance activities
- Review and develop security-related documentation for audits and assessments; assist with test procedures, standards, and evaluation documentation
- Provide technical security support during factory acceptance tests and system testing
- Support business continuity and disaster recovery planning and exercises, including participation in disaster recovery planning and execution of test events
- Ensure the operational security posture of systems, programs, and designated assets
- Serve as a security advisor to program management and technical teams
Key Technologies
- NIST 800-53
- NIST security frameworks
- Security Certification and Authorization Process (SCAP)
- System Security Plans (SSP)
- POA&M
Requirements
- Experience in information systems security, cybersecurity, or security engineering
- Knowledge of federal and FAA security requirements and standards
- Familiarity with NIST security frameworks (e.g., NIST 800-53)
- Experience developing and maintaining security documentation (SSP, POA&M, risk assessments)
- Ability to analyze system vulnerabilities and recommend security controls
- Strong written and verbal communication skills
- Ability to work collaboratively with engineering, operations, and program teams
Experience and education levels (Senior/Mid-level/Junior-level):
- Senior-level: Minimum of 15 years’ experience with a Bachelor’s degree in any engineering field. A Master’s degree may be substituted for Bachelor’s and 3 years’ experience. A PhD may be substituted for Bachelor’s and 7 years’ experience.
- Mid-level: Minimum of 10 years’ experience with a Bachelor’s degree in any engineering field. A Master’s degree may be substituted for Bachelor’s and 3 years’ experience. A PhD may be substituted for Bachelor’s and 7 years’ experience.
- Junior-level: Minimum of 2 years’ experience with a Bachelor’s degree in any engineering field. A Master’s degree may be substituted for Bachelor’s and 3 years’ experience. A PhD may be substituted for Bachelor’s and 7 years’ experience.
Benefits
- Health, life, disability, financial, and retirement benefits
- Paid leave
- Professional development
- Tuition assistance
- Work-life programs
- Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in benefit programs
Desired Qualifications
- Experience supporting FAA, NAS, or other federal systems
- Knowledge of system development life cycle (SDLC) security integration
- Experience supporting audits, security assessments, and test activities
- Relevant security certifications (as required by program or contract)