Apply with hirly
Cyber System Security Engineer (CSSE)
Kbr · El Segundo, California
Upload your resume to see how well you match this job — free, in seconds, no account needed.
Your resume is used only to score it against this job. If you don't create an account, it is deleted within 24 hours.
Title: Cyber System Security Engineer (CSSE) Belong. Connect. Grow. with KBR! KBR’s National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities. In this position, your work will have a profound impact on the country’s most critical role – protecting our national security. KBR is seeking a Cyber Security Engineer to join our team in El Segundo, CA. An active TS/SCI is required to be considered for this position. Why Join Us? Innovative Projects: KBR’s work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions. Collaborative Environment: Be part of a dynamic team that thrives on collaboration and innovation, fostering a supportive and intellectually stimulating workplace. Impactful Work: Your contributions will be pivotal in designing and optimizing defense systems that ensure national security and shape the future of space defense. We are seeking an experienced Space Systems, Cyber System Security Engineer (SSE) to support the integration of cybersecurity, systems security engineering, information assurance, program protection, and risk-management activities for defense-critical systems and information-network environments. The SSE will ensure cybersecurity is engineered throughout the system life cycle from requirements definition, architecture, design, integration, and test through deployment, authorization, sustainment, modernization, and disposal. The SSE will support systems pursuing and maintaining an Authority to Operate (ATO) through the Risk Management Framework (RMF) process. The SSE serves as a principal cybersecurity and RMF Subject Matter Expert (SME) to the program manager, chief engineer, Information System Security Manager (ISSM), Information System Security Officer (ISSO), system owner, Authorizing Official (AO), configuration-control authorities, and program leadership. Key Responsibilities Systems Security Engineering and RMF
- Apply systems security engineering principles across the system development life cycle in accordance with
Nist Sp
800-160 and applicable DoD acquisition and cybersecurity requirements.
- Translate mission, cybersecurity, privacy, program-protection, cryptographic, supply-chain, and compliance requirements into system specifications, architecture artifacts, interface-control requirements, verification criteria, and test procedures.
- Responsible for RMF activities, including system registration, categorization support, control selection and tailoring, control implementation, assessment support, authorization-package development, risk response, and continuous monitoring.
- Develop, maintain, and update authorization artifacts in eMASS or other approved governance, risk, and compliance tools, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Security Control Traceability Matrices (SCTMs), Contingency Plans, Configuration Management Plans, and supporting evidence.
- Provide technical cybersecurity risk assessments and recommendations to the ISSM, AO, program manager, and chief engineer regarding control deficiencies, residual risk, authorization dependencies, and risk-treatment options.
- Participate in technical and program reviews, including requirements reviews, design reviews, test-readiness reviews, production-readiness reviews, and deployment decisions. SOW, CDRL, and Acquisition Support
- Draft, review, and maintain cybersecurity and systems-security-engineering requirements for Statements of Work (SOWs), Performance Work Statements (PWSs), Statements of Objectives (SOOs), task orders, and acquisition documentation.
- Develop and manage Contract Data Requirements List (CDRL) requirements for cybersecurity deliverables, including RMF packages, vulnerability reports, STIG checklists, cybersecurity test reports, software and firmware inventories, supply-chain documentation, and incident reports.
- Ensure cybersecurity requirements are measurable, traceable, technically feasible, and aligned with program milestones, acceptance criteria, engineering baselines, and sustainment requirements.
- Review contractor cybersecurity deliverables for completeness, technical adequacy, compliance, traceability, and readiness for government acceptance.
- Support acquisition planning and source-selection activities by identifying cybersecurity risks, engineering dependencies, resource needs, and compliance requirements. Program Protection, Supply-Chain Risk, and Cryptography
- Support Program Protection Plan development and execution, including identification and mitigation of threats to critical technologies, mission-critical functions, hardware, software, interfaces, and data.
- Coordinate cybersecurity engineering with program protection, anti-tamper, software assurance, hardware assurance, supply-chain risk management, configuration management, and mission-assurance activities.
- Identify attack surfaces, trust boundaries, critical assets, cybersecurity dependencies, and protective measures across system architectures and interfaces.
- Support approved cryptographic solutions, encryption implementations, Public Key Infrastructure (PKI), certificate lifecycle management, key-management requirements, secure communications, and cryptographic modernization activities.
- Coordinate with designated communications-security, cryptographic, engineering, cybersecurity, and program-protection personnel to document and manage cryptographic dependencies and associated risks.
- Support compliance with applicable CNSS, NSA, DoD, DAF, and program requirements governing cryptographic products, services, key management, and secure communications. Continuous Monitoring, Vulnerability Management, and STIG Compliance
- Conduct and oversee continuous-monitoring activities, vulnerability assessments, configuration assessments, security scans, compliance validation, and remediation tracking.
- Use DISA STIGs, SRGs, SCAP Compliance Checker (SCC), ACAS/Nessus, endpoint-security tools, and manual validation procedures to assess system compliance.
- Analyze Windows, Linux, network devices, applications, databases, cloud services, and enterprise infrastructure against approved security baselines.
- Develop, document, coordinate, and validate remediation actions, compensating controls, mitigations, exceptions, and risk decisions for vulnerabilities and non-compliant security controls.
- Create, maintain, and report Plans of Action and Milestones (POA&Ms), including risk ratings, milestones, accountable owners, remediation evidence, dependencies, and closure documentation.
- Maintain continuous-monitoring plans, scan schedules, security metrics, compliance dashboards, and recurring cybersecurity status reports. Configuration Management, Audit, and Incident Support
- Serve as the cybersecurity and systems-security-engineering representative on the Configuration Control Board (CCB) and other engineering governance forums.
- Assess proposed hardware, software, firmware, network, interface, and operational changes for cybersecurity, RMF, STIG, cryptographic, supply-chain, and program-protection impacts before deployment.
- Ensure approved changes are tested, documented, authorized as required, and reflected in system baselines, inventories, configuration-management records, and authorization artifacts.
- Review audit logs, cybersecurity dashboards, and Security Information and Event Management (SIEM) reports, including Splunk reports where applicable, for unauthorized activity, anomalous behavior, and indicators of compromise.
- Support cybersecurity incident identification, triage, containment, reporting, remediation, evidence preservation, and lessons-learned activities in accordance with applicable DoD and organizational procedures. IT Governance, eMASS, ITIPS, and FISM