Information System Security Engineer
| Verified Pay check_circle | Provided by the employer$125000 - $130000 per year |
|---|---|
| Hours | Full-time |
| Location | Hill Air Force Base, Utah |
About this job
Job Description
Information System Security Engineer
Tope is seeking a Information Systems Security Engineer to support the AF Strategic Program Information Services team in support of the Sentinel Information Services (IS) team. The selected candidate will join our Information Services team and have an important role in supporting our mission of Strategic Deterrence through continual improvement and innovation. The position will have the following duties and responsibilities:
· Ensure the confidentiality, integrity and availability of classified information systems.
· Enforce information systems security programs, policies, procedures, and tools.
· Analyzes equipment and software reliability and suitability for vulnerability assessment. Conducts analysis of classified network usage, hardware and software capabilities, ineffective practices or procedures, equipment shortcomings, and other relevant factors.
· Conducts risk and vulnerability assessments of classified information systems to identify associated vulnerabilities, risks and protection needs.
· Performs, documents and provides recommendations to the ISSM on security audits, evaluations, and risk assessments for all classified systems.
· Updates and completes all Body of Evidence paperwork and artifacts.
· Serves as a technical expert and focal point for cybersecurity policies, planning, programs, initiatives, certification, and accreditation.
· Provides recommendations and assistance regarding security aspects of processing, storage, retrieval, transmission, and access of classified and unclassified information
Position requires a current CISSP, CISSP-ISSEP, CASP+ CE (CompTIA SecurityX), or CSSLP Certification, fully adjudicated DoD Secret or Top-Secret Security Clearance and at least 8+ years’ experience and a BS degree in Computer Science, Cybersecurity, Information Technology, or a related Engineering field or 6+ years’ experience and a MS degree in Computer Science, Cybersecurity, Information Technology, or a related Engineering field.
· Professional experience in information security leading large-scale projects
· Experience designing and implementing secure network architectures, Zero Trust environments, and cloud security frameworks (AWS, Azure, or GCP)
· Deep experience operating within regulatory frameworks such as NIST (800-53, 800-171), ISO 27001, CMMC, or SOC2
· Experience leading high-severity security incident responses and conducting post-mortem root cause analyses
· Threat Modeling: Proficiency in using frameworks like STRIDE or PASTA to identify vulnerabilities
· Security Tooling: Expert-level knowledge of SIEM (Splunk, Sentinel), EDR/XDR, Firewalls, and Vulnerability Scanners (Nessus, Qualys)
· Identity & Access Management (IAM): Expertise in OAuth, SAML, and multi-factor authentication (MFA) implementation
· Secure Coding/DevSecOps: Ability to integrate security into the CI/CD pipeline using SAST (Static Analysis) and DAST (Dynamic Analysis) tools
· Strategic Planning: Ability to translate business requirements into a technical security roadmap
· Stakeholder Management: Capable of communicating complex technical risks to non-technical executives to secure budget and buy-in
· Certification Requirement
· The applicant must meet DoD 8570.01-M IAT Level II, IAM Level I or higher certification requirements on hire date..
Other skills desired are:
· Cross-Domain Expertise: Experience transitioning security postures across different environments, such as moving a legacy on-premises system to a hybrid-cloud or fully cloud-native environment
· Industry-Specific Tenure: In the context of defense and aerospace, a preference for candidates with experience in Cross-Domain Solutions (CDS), air-gapped networks, and highly classified environments
· Security Leadership: Proven experience as a "Lead" or "Architect" where the candidate was responsible for the security roadmap of an entire product line or business unit
· Public Speaking/Thought Leadership: A history of contributing to the security community through white papers, conference presentations (e.g., DEF CON, Black Hat), or open-source security projects
· Automation & Orchestration: Proficiency in Python, Go, or PowerShell to automate security responses (SOAR) and infrastructure as code (Terraform, Ansible)
· Advanced Cryptography: Deep understanding of PKI (Public Key Infrastructure), quantum-resistant encryption, and hardware security modules (HSMs)
· Red Teaming/Adversarial Simulation: The ability to not only defend but to simulate advanced persistent threats (APTs) to test the resilience of the organization
· Data Science for Security: Ability to apply machine learning (ML) and AI to anomaly detection and threat hunting.
This is a challenging, but very rewarding, opportunity to work in a very rewarding environment with Education Assistance. Position is full time with benefits, in Utah and requires security clearance qualification. Send resume and salary requirements to Gary Petersen.
Tope Technology, LLC provides equal employment opportunities without regard to race, religion, sex, national origin, age, disability, marital status, or veteran status.
Tope Technology, LLC provides equal employment opportunities without regard to race, religion, sex, national origin, age, disability, marital status, or veteran status.