About this role
IT Sys Sec Eng Sr Prin
Job Description: BAE Systems is seeking an Information Systems Security Officer (ISSO) to support the compliance and authority to operate requirements to support the technical solutions task order for the Executive Office for the U.S. Attorneys (EOUSA) for our customer, the US Attorneys’ Office (USAO). The candidate will work closely with the Assistant Director for the Enterprise Operations, Platforms and Solutions (EOPS) and supporting team, to secure and certify for use on the unclassified USAO network.
Background - The Executive Office for United States Attorneys (EOUSA) provides administrative, technical, and legal support to all United States Attorneys’ Offices (USAOs), and EOUSA’s IT Staffs deliver technology solutions to support USAO employees in performing their demanding operational responsibilities. Five (5) staff comprise the EOUSA IT organization, serving under the EOUSA Office of the Chief Information Officer (OCIO): Enterprise Operations, Platforms, and Solutions (EOPS), Cyber Systems Security Staff (CSS), Enterprise Voice Services (EVS), Enterprise Application Development (EAD), and Records Information Management (RIM). Government IT staff rely on contractors to deliver many of the engineering and steady state technical services to maintain the innovative technologies deployed in EOUSA and the USAOs.
Enterprise Operations, Platforms and Solutions (EOPS) regularly field new systems to enhance the USAO mission and upgrade aging systems. Most of the systems are Windows based. Systems also include virtualization, large storage nodes, wireless, cloud systems for office automation, eDiscovery, data protection and archiving. The customer base is over 19,000 users at 250+ locations. Scope of Work - The ISSO shall serve as the information security subject matter expert and implement processes and controls in support of cybersecurity programs to ensure compliance with EOUSA Cybersecurity Program Management and other governing DOJ directives and policies. The ISSO is primarily responsible for maintaining the cybersecurity posture and baseline of the EOPS steady state systems and applications deployed in Columbia, SC and across the EOUSA Enterprise. The ISSO provides operational feedback to the EOPS Assistant Director and EOUSA CISO and attends technical interchange meetings. The ISSO assists in providing status of onsite security posture, such as, IAVA, STIG, and other relevant system security patching compliance. The ISSO provides input to POA&M and processes and memorandum of understanding/agreements. Responsible for preparing and maintaining the ATOs for the EOPS systems and applications. The ISSO shall perform the following duties:
• Plan, implement, upgrade, and monitor security measures for the protection of communications and IT systems and information. • Draft, review, coordinate local IA policies, procedures and operating instructions, and provide recommendations for revisions. • Identify and manage cybersecurity risks; and implement controls to ensure the secure delivery of mission critical services. • Monitor and detect cybersecurity events; and implement appropriate response and recovery actions. • Manage cybersecurity incident management handing, response, escalation, and reporting. • Maintain the EOPS cybersecurity posture according to EOUSA and DOJ policies and directives. • Ensure all IT hardware/software products are configured according to relevant security configuration and implementation guidance. • Utilize standard software tools to perform vulnerability scans of network equipment and software; and assist network, systems, and client administrators in implementing corrective actions required when vulnerabilities are detected. • Develop, update, and maintain certification and accreditation documentation, including but not limited to Risk Management Framework (RMF) artifacts, Authority to Operate (ATO), Plan of Actions and Milestones (POA&M), waivers, and vulnerability mitigation plans. CSAM is the ATO management system currently used by DOJ to create, update, and document system information as required by FISMA and other Federal mandates. All updates to system ATO information shall be made in CSAM. • Assess the impact of changes on certification and accreditation packages and advise the government accordingly. • Process and coordinate system access authorization requests, software approval requests, firewall and proxy exemption requests/waivers, and other IA related documents. • Ensure IA related documentation is current and accessible to authorized individuals. • Research security issues affecting network/systems hardware and software and provide recommended solutions. • Ensure EOPS personnel are compliant with DOJ and EOUSA IA standards and guidance; and promote information security awareness.
Required Skills and Education: Minimum Candidate Requirements
• Bachelor's degree in computer science, cybersecurity, engineering; OR • Five years of comparable work experience; AND • Four plus years’ experience implementing and maintaining security controls for Federal IT systems in accordance with FISMA and NIST guidance; AND • Certified Information Systems Security Professional (CISSP) or similar certification. Skill Sets Anticipated • Proficient use and understanding of systems engineering concepts, principles, and theories. • Proficient understanding of cyber security specifications such as RMF, STIGS, IAVAs, and other government security specifications and guidelines. • Proficient knowledge of cybersecurity technology and trends. • Strong written and verbal communication skills. • Recognizes and incorporates various security designs and lessons learned. • Ability to participate or lead security-working groups/meetings. • Experience in problem solving and troubleshooting complex and distributed government IT systems. • Sounds knowledge and practical experience to direct the assessment and development of Tactics, Techniques, and Procedures (TTPs) and/or Operating Instructions (OIs) to effectively administer, operate and manage services under EOUSA operational control. • Knowledge of modern computer systems, network concepts, client/server, LAN/WAN, modern network management and monitoring concepts. • Knowledge and Proficiency in technical writing. • Excellent communications, teamwork, leadership and conflict management skills. • Committed to continuous learning and system development. • Familiar with NIST Special Publication 800-53 • Familiar with NIST Special Publication 800-137 Security Requirements
• Top Secret clearance required (Can start with Interim Clearance) • Must be able to obtain Top Secret clearance
About BAE Systems Intelligence & Security: BAE Systems, Inc. is the U.S. subsidiary of BAE Systems plc, an international defense, aerospace and security company which delivers a full range of products and services for air, land and naval forces, as well as advanced electronics, security, information technology solutions and customer support services. Improving the future and protecting lives is an ambitious mission, but it’s what we do at BAE Systems. Working here means using your passion and ingenuity where it counts – defending national security with breakthrough technology, superior products, and intelligence solutions. As you develop the latest technology and defend national security, you will continually hone your skills on a team—making a big impact on a global scale. At BAE Systems, you’ll find a rewarding career that truly makes a difference.
Intelligence & Security (I&S), based in McLean, Virginia, designs and delivers advanced defense, intelligence, and security solutions that support the important missions of our customers. Our pride and dedication shows in everything we do—from intelligence analysis, cyber operations and IT expertise to systems development, systems integration, and operations and maintenance services. Knowing that our work enables the U.S. military and government to recognize, manage and defeat threats inspires us to push ourselves and our technologies to new levels.
This position will be posted for at least 5 calendar days. The posting will remain active until the position is filled, or a qualified pool of candidates is identified.
Preferred Skills and Education: Preferred Candidate Requirements
• Experience with DOJ Joint Cybersecurity Authorization Management tool (or similar assessment tracking tool). • Experience guiding engineers in the remediation of vulnerabilities disclosed during system security scans using tools such as Qualys, Nessus, Webinspect, and App Detective. • Clear understanding of Risk Management frameworks, to include roles and responsibilities of System Owners, Cybersecurity Staff, and the Information System Security Officer. • General understanding of computer systems.
Benefits Information: Employee Benefits: At BAE Systems, we support our employees in all aspects of their life, including their health and financial well-being. Regular employees scheduled to work 20+ hours per week are offered: health, dental, and vision insurance; health savings accounts; a 401(k) savings plan; disability coverage; and life and accident insurance. We also have an employee assistance program, a legal plan, and other perks including discounts on things like home, auto, and pet insurance. Our leave programs include paid time off, paid holidays, as well as other types of leave, including paid parental, military, bereavement, and any applicable federal and state sick leave. Employees may participate in the company recognition program to receive monetary or non-monetary recognition awards. Other incentives may be available based on position level and/or job specifics.
Intern Benefits: Temporary employees generally are not eligible for BAE Systems benefits, but can elect to participate in the 401(k) savings plan. Temporary employees working 20+ hours per week are eligible for medical benefits, the employee assistance program, and business travel accident insurance.
Please note: Some benefits may be different for union employees that are governed by a collective bargaining agreement (CBA) or for positions covered by a wage law called the McNamara-O’Hara Service Contract Act (SCA).