
Lead System Security Engineer
- Boulder, CO
- Permanent
- Full-time
- Serve as the technical SME for RMF-based cybersecurity assessments and system authorization strategies.
- Develop and update RMF artifacts, including some or all of the following:
- System Security Plans (SSPs)
- Security Control Traceability Matrices (SCTMs)
- Configuration Management Plans
- Incident Response Plans
- Continuous Monitoring (CONMON) Plans
- POA&Ms and Security Assessment Reports (SARs)
- Support the IATT, ATC, and ATO processes, supporting internal engineering teams and external Authorizing Officials (AOs).
- Perform system-level security control assessments (NIST SP 800-53) and validation of security posture.
- Evaluate external connection risks and support the ATC approval process with boundary defense configurations and enclave protections.
- Support vulnerability and compliance scans using tools such as ACAS, Tenable Security Center, STIG Viewer, and Evaluate STIG.
- Work with development and infrastructure teams to define, validate, and maintain secure configurations and baselines.
- Maintain and update continuous monitoring (CONMON) processes, collect metrics, track findings, and coordinate with ISSMs and stakeholders.
- Draft and maintain cyber documentation required for accreditation package submission.
- Assist in security impact analyses for changes in configuration, new software deployments, or system modifications
- Bachelor’s degree in Software, Computer, Systems, Electrical, Information Technology Engineering, or a related technical field. Additional years of experience can count in lieu of a degree.
- 15+ years of related experience
- Experience with RMF-based cybersecurity assessments
- Experience supporting IATT, ATO, or ATC approval efforts
- Strong understanding of DoD and NIST cybersecurity frameworks and controls
- Possess a DoD 8140.03/8570.01 Information Assurance Manager II certification or able to obtain within 6 months of hire: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Authorization Professional (CAP), CompTIA Advanced Security Practitioner Plus (CASP+), GIAC Security Leadership Certification (GSLC), Chief Information Security Officer Certification (CCISO), or Healthcare Information Security and Privacy Practitioner (HCISPP)
- Knowledge of and hands on experience with Security Technical Implementation Guides (STIGs), Assured Compliance Assessment Solution (ACAS), Host Based Security System (HBSS) / Trellix
- Must have the ability to work in a dynamic environment and effectively interact with numerous DOD, military/civilian personnel and industry partners
- Working knowledge of Microsoft Office (Word, PowerPoint, and Excel)
- Cybersecurity certifications such as CompTIA CASP+, CISSP, OSCP, CISM, CEH, GSEC
- System administration experience with Linux
- Network switch and router administration experience or network engineering experience
- Experience with VMware
- Experience with Kubernetes and Docker
- Familiarity with MBSE/SysML system engineering