
Principal Cybersecurity Engineer
- Bridgeton, MO
- Permanent
- Full-time
- Risk Management Framework (RMF) Implementation: Provide senior technical guidance and oversight for the RMF process for IT systems within tactical vehicles, from system categorization (SP 800-60) through security control selection (SP 800-53), implementation, assessment, authorization, and continuous monitoring.
- Security Assessments: Lead comprehensive security assessments of tactical vehicle IT systems, including hardware, software, and network configurations. This includes vulnerability scanning, penetration testing (where appropriate and authorized), security architecture reviews, and configuration analysis.
- Documentation: Develop and review detailed RMF documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Risk Assessments, Plans of Action and Milestones (POA&Ms), and other required artifacts. Ensure documentation not only complies with, but also sets the standard for, relevant regulations.
- Security Control Implementation and Validation: Serve as a senior technical advisor to engineering teams, driving the implementation and validation of security controls on tactical vehicle systems. This may involve hands-on configuration of systems, development of security hardening guidelines, and influencing system design.
- Vulnerability Management: Direct the identification, analysis, and prioritization of vulnerabilities discovered through assessments or continuous monitoring. Develop and champion remediation strategies, providing expert guidance to technical teams to implement solutions.
- Compliance: Serve as a subject matter expert on all security activities and documentation, ensuring compliance with relevant Department of Defense (DoD) instructions, NIST publications (specifically 800-series), Cybersecurity Maturity Model Certification (CMMC), and other applicable regulations and policies (e.g., DoDI 8510.01, DoDI 8500.01).
- Collaboration: Drive cross-functional collaboration with engineers, system administrators, program managers, and government representatives, acting as a key liaison to ensure security is integrated throughout the system lifecycle.
- Mentorship: Actively mentor and guide junior engineers, fostering their professional growth and expanding the team's overall technical capabilities.
- Continuous Improvement: Stay current with the latest cybersecurity threats, vulnerabilities, and technologies relevant to tactical vehicle systems. Recommend improvements to security processes and technologies.
- Travel: This position may require travel to test facilities, potentially up to 25% travel, occasional travel for 1-2 week periods.
- Additional Responsibilities: Support, communicate, reinforce and defend the mission, values and culture of the organization. Attend appropriate engineering, customer or business meetings. Lead less-experienced engineers.
- Master's degree in Cybersecurity, Computer Science, Information Technology, Electrical Engineering, or a related technical field
- Relevant cybersecurity certifications (e.g., CASP+, CISM, CISA, CRISC, Security+, (ISC)2 CAP, GSLC, CCNA, Network+)
- Minimum of 8 years of experience in cybersecurity engineering, with a demonstrated focus on applying the Risk Management Framework (RMF). This experience must include performing security assessments of IT systems.
- Strong understanding of NIST SP 800-37, SP 800-53, SP 800-60, SP 800-160, and other relevant NIST publications
- Experience conducting security assessments, including vulnerability scanning and security architecture reviews
- Experience with vulnerability scanning tools, specifically Nessus or ACAS
- Experience with a variety of security assessment tools, such as static code analyzers, dynamic application security testing (DAST) tools, or network analysis tools
- Proficiency in both Linux and Windows operating systems
- Experience with scripting in one or more common scripting languages (e.g., Python, PowerShell, Bash, Perl)
- Experience with the configuration, security hardening, and/or troubleshooting of network hardware
- Experience with security hardening techniques for operating systems (e.g., Windows, Linux), network devices, and applications
- Excellent written and verbal communication skills, with the ability to clearly articulate technical information to both technical and non-technical audiences
- Ability to work independently and as part of a team
- Strong problem-solving and analytical skills
- Ability to obtain and maintain a security clearance
*Some employees are eligible for limited benefits onlyLeonardo DRS, Inc. and its subsidiaries provide equal opportunities to all employees and applicants for employment and prohibit discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. #LSYOur Vision. To be the leading mid-tier defense technology company in the U.S.Our Values. The Leonardo DRS culture is defined by our Core Values and Principles:- Integrity
- Agility
- Excellence
- Customer Focus
- Community & Respect
- InnovationWe strive to uphold them in all aspects of our business practices to inspire our employees and provide outstanding support for our customers.