System Security Engineer (5168)
Essential Duties & Responsibilities
- Provide support to PMA-268 Cyber Leads in execution of the PMA-268 Cybersecurity Program:
- Provide support in drafting and reviewing Program Documentation, Policies and Plans.
- Coordinate with PMA-268 Cyber Leads when changes occur that might affect system’s security posture, cybersecurity authorization(s) and/or certifications.
- Lead product specific System Security Engineering activities for all systems within scope of IPT:
- Provide oversight of all IPT cybersecurity activities.
- Review system documentation to obtain and sustain Subject Matter Expert (SME) level knowledge of the system architecture, functionality and capabilities
- Work closely with the IPT Class Desk and IPT Leadership to ensure early engagement when cybersecurity items may impact the program cost, schedule, or performance.
- Develop and maintain a cyber schedule to include a detailed Work Breakdown Schedule (WBS) for significant efforts.
- Provide input for SOWs, DIDs, and CDRLs for IPT contract activities.
- Identify, define and document system security requirements for incorporation of product specifications.
- Conduct derivation and traceability of cyber requirements.
- Track execution and performance of security measures to protect information and network infrastructure and computer systems.
- Conduct critical function analysis.
- Identify Mission Essential Functions (MEF).
- Lead Critical Program Information (CPI) assessments.
- Understand vulnerabilities and attack vectors that can impact the cyber posture of the systems/environment.
- Identify and recommend security solutions to PMA-268 Cyber Leads.
- Perform SSE duties in support of Cyber Survivability Risk Assessments (CSRA) and CYBERSAFE to include leading execution of collaborative development of artifacts and data (Objective Quality Evidence, Mission Critical Function/Component Traceability).
- Lead DFIA implementation efforts through definition of enclaves and enclave boundary protection requirements.
- Lead system security certification and registration activities (e.g. CSfC, CDS, Cryptographic Modules).
- Lead IPT cybersecurity activities:
- Initiate, communicate and coordinate with stakeholders and SMEs to address actions and RFIs required for IPT cybersecurity activities in a timely manner (no actions/RFIs to be stagnant for longer than 2 weeks).
- Lead IPT SSE Working Group (SSEWG) to:
- Coordinate with Contractors/Organizations supporting IPT cybersecurity efforts.
- Maintain awareness of authorization of Systems/Subsystems.
- Review all IPT cybersecurity CDRLs.
- Actively participate as a stakeholder in change management processes to ensure cybersecurity posture is not impacted due to a change.
- Coordinate Risk Management (Opportunities, Issues, Risks) activities with Risk Managers (Cyber, PMA, Product) to document, socialize and work mitigation steps.
- Assist IPT ISSO with the following activities identified in the PMA-268 Cyber RMF Roles and Responsibilities chart:
- Defining Information Types: work with engineering to ensure the proper information types for the system(s) are identified.
- Approval of CIA: identify the initial CIA impact levels for the identified information types and socialize with the Class Desk for concurrence.
- Review POA&M: ensure awareness of all open findings and identify areas of concern that need to be socialized with the Class Desk when cost, schedule, or performance impacts are identified. Assist the ISSO with mitigation identification for open findings.
- Review hardware/software lists: investigate potential issues (e.g. Open Source, foreign software).
In addition, the following are administrative team execution expectations for all PMA-268 Cybersecurity team personnel.
- Login to Microsoft Teams at the beginning of each day and have a headset to participate in Teams meetings.
- At a minimum, in person workdays in PMA-268 Program Office every Tuesday, Wednesday and Thursday unless pre-coordinated with PMA-268 Cyber Leads. Core office hours 0830-1430.
- Additional days in the office are required if there is work that requires in person/office presence to complete outside of the designated office days.
- Provide updates to the following:
- Cyber Status Slide (weekly)
- Microsoft Planner Task Status (weekly)
- Task Tracker (weekly)
- Cyber Schedule (biweekly)
- No actions to be stagnant for longer than 2 weeks.
- Provide meeting summary notes for meetings attended to the PMA-268 cyber team for awareness.
Required Skills & Experience
- Clearance Required: Secret
- US Citizenship is required for work on DoD contract
- Technical or Scientific BS or BA degree from an accredited college or university
- Minimum of seven (7) years of cyber-related experience, preferably in a DoD environment
Desired Skills & Experience
- Program office experience highly desired
- Aviation engineering experience highly desired
#cjpost #LI-HYBRID
The SMX salary determination process takes into account a number of factors, including but not limited to, geographic location, Federal Government contract labor categories, relevant prior work experience, specific skills, education and certifications. At SMX, one of our Core Values is to Invest in Our People so we offer a competitive mix of compensation, learning & development opportunities, and benefits. Some key components of our robust benefits include health insurance, paid leave, and retirement.
At SMX®, we are a team of technical and domain experts dedicated to enabling your mission. From priority national security initiatives for the DoD to highly assured and compliant solutions for healthcare, we understand that digital transformation is key to your future success.
We share your vision for the future and strive to accelerate your impact on the world. We bring both cutting edge technology and an expansive view of what’s possible to every engagement. Our delivery model and unique approaches harness our deep technical and domain knowledge, providing forward-looking insights and practical solutions to power secure mission acceleration.
SMX is an Equal Opportunity employer including disabilities and veterans.
Selected applicant may be subject to a background investigation and/or education verification.
SMX does not sponsor a new applicant for employment authorization or immigration related support for this position (i.e. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-2, E-3, L-1 and O-1, or any EADs or other forms of work authorization that require immigration support from an employer).
As published by greenhouse
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter
- Legal First Name
- Legal Last Name
- Full Middle Name
- Suffix optional
- Street Address
- City
- State choose one
- Postal Code
- Are you at least 18 years of age? choose one
- What level of security clearance do you currently hold? choose any
- Work Authorization choose one
- Will you at any time require any form of work authorization, visa, or other immigration sponsorship? choose one
- Salary Requirements
- Have you previously worked for SMX or a subsidiary? choose one
- WE ARE AN EQUAL OPPORTUNITY EMPLOYER. Applicants and employees are considered for positions and are evaluated without regard to mental or physical disability, race, color, creed, religion, sex, gender, national origin, ancestry, age, genetic information, military or veteran status, sexual orientation, gender identity or expression, marital status, familial status or any other legally protected status under applicable law or other similar factors that are not job-related. No question on the application is intended to secure information about these subjects. We encourage all qualified individuals to apply for employment. We also provide reasonable accommodation to qualified individuals with disabilities in accordance with the Americans With Disabilities Act and applicable state and local law. If you require assistance or a reasonable accommodation to complete the application or any aspect of the application process, please contact the Talent Acquisition team at [email protected]. All applicants must properly complete this employment application; failure to do so may result in denial of employment. Rhode Island Applicants: PURSUANT TO THE WORKERS’ COMPENSATION LAW SECTION 28-29-6, THE ORGANIZATION INFORMS YOU THAT IT IS SUBJECT TO THE WORKERS’ COMPENSATION LAWS. IF YOU PROVIDE FALSE INFORMATION ABOUT YOUR ABILITY TO PERFORM THE ESSENTIAL FUNCTIONS OF THE JOB WITH OR WITHOUT ACCOMMODATION, YOU MAY BE BARRED FROM FILING A CLAIM UNDER THE PROVISIONS OF THE WORKERS’ COMPENSATION ACT OF THE STATE OF RHODE ISLAND. choose one
- I have read and agree to the SMX Data Privacy Policy. choose one
- I agree to the Conditions of Application and Employment statement below. choose one
- I hereby authorize this electronic signature submittal to serve as my legal signature. choose one
- Enter Full Legal Name
- Date (mm/dd/yyyy)