Systems Security Engineer
Job Description
This on-site role is based at Wright-Patterson AFB in Ohio as part of Modern Technology Solutions, Inc (MTSI). The Systems Security Engineer will focus on the design, evaluation, and ongoing maintenance of secure embedded DoD oriented systems and networks, with particular emphasis on security architecture, RMF and A&A activities, and anti-tamper considerations in embedded avionics.
Responsibilities
- Leverage DoD and Air Force engineering practices to improve the performance and sustainability of current and future weapon systems.
- Convert user needs into weapon system requirements used to design, build, test and evaluate weapon systems, subsystems and equipment for fielding.
- Conduct technical and mission analyses of current and future operational requirements, help develop system concepts, and perform trade-off assessments of designs and modifications.
- Create and maintain RMF documentation required for Authorization, including the System Security Plan, Architecture Analysis Report, Continuous Monitoring Plan, Security Control Traceability Matrix, Security Assessment Report and Risk Assessment Report.
- Assist in producing or reviewing acquisition documentation such as Cybersecurity Strategy, Test and Evaluation Master Plan, Clinger-Cohen Act compliance, Capabilities Development Document, Concept of Operations and related items.
- Support system engineering and program management by preparing and reviewing milestone artifacts like System Requirements Review, Preliminary Design Review, Critical Design Review and Program Management Review.
- Perform information system security engineering tasks to ensure security requirements are incorporated across architecture, design, development, configuration and deployment processes.
- Develop and enforce information system security policies to address security requirements throughout the acquisition lifecycle.
- Review and validate security designs within embedded avionics to confirm proper security controls and architectures.
- Carry out RMF based Assessment and Authorization tasks, identify deficiencies and propose risk mitigations to program management.
- Apply best practices for security controls, including secure software engineering, secure design and architecture, and secure coding techniques.
- Develop and integrate new techniques to improve confidentiality, integrity and availability across networks and systems at multiple classification levels.
- Assist program managers, system engineers and cyber test engineers with mission-based cyber risk assessments.
- Identify vulnerabilities and non-compliance with cybersecurity standards and regulations, and recommend mitigation strategies.
- Apply cybersecurity policy, procedures and workforce structure to implement secure networking, computing and enclave environments.
- Identify designs that span multiple enclaves with differing data protection and classification requirements.
Requirements
- Education: BS degree from an accredited university with coursework in computer science, cybersecurity, electrical/electronics/systems/computer engineering or related field.
- Experience: Five-plus years in systems security architecture or engineering, ideally within a government or DoD setting.
- Certifications: DoD 8140 aligned certifications such as CISSP, CISM or CCSP.
- Knowledge: Strong understanding of NIST cybersecurity frameworks and standards, RMF, DISA STIGs, and system accreditation processes.
- Technical Skills: Experience with security in avionics, embedded systems, operational technology and SCADA, plus familiarity with network security, firewalls, intrusion detection/prevention systems, secure coding practices and vulnerability scanning tools.
- Clearance: Active Top Secret clearance with eligibility for SCI.
Technologies
- NIST, Risk Management Framework (RMF), DISA STIGs
- Firewalls, Intrusion Detection/Prevention Systems
- Vulnerability Scanning Tools, Secure Coding Practices
Benefits
- Vacation
- Health Insurance
- Flexible Schedules
- Professional Development
- Employee Stock Ownership Plan (ESOP)
- 401k Match
- Bonus Program
- Mentorship
Desired qualifications
- Experience with government contracting and DoD security program management
- Familiarity with scripting, automation tools and secure system integration techniques
- Understanding of cloud security in classified environments
Travel
20 percent anticipated travel, with variation possible.
Why MTSI is a great place to work
- Interesting Work: Colleagues support critical national defense and security programs.
- Values: The company places employees first, offering strong support and competitive benefits.
- 100 Percent Employee Owned: Everyone has a stake in success and knowledge is shared through regular town hall meetings.
- Great Benefits: Generous PTO (starting at 20 days per year) plus 10 holidays, flexible schedules, a 6 percent 401k match with immediate vesting up to $9k, semi-annual bonus eligibility, and an ESOP.
- Educational Support: Up to $10,000 annually for educational reimbursement and access to life and disability insurance programs.
- Health Options: Optional zero deductible Blue Cross/Blue Shield health plan.
- Track Record: The company has grown every year since its 1993 founding.