Lead, Information Security Systems Engineer
Listed on 2026-10-09
-
IT/Tech
Cybersecurity, Security Management & Operations, Information Security & Data Protection
L3
Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do. Our employees are unified in a shared dedication to our customers’ mission and quest for professional growth. L3
Harris provides an inclusive, engaging environment designed to empower employees and promote work-life success. Fundamental to our culture is an unwavering focus on values, dedication to our communities, and commitment to excellence in everything we do.
L3
Harris is the Trusted Disruptor in defense tech. With customers’ mission-critical needs always in mind, our employees deliver end-to-end technology solutions connecting the space, air, land, sea and cyber domains in the interest of national security.
Job Title:
Lead, Information Security Systems Engineer
Job Code: 44627
Job Location:
Greenville, TX
Schedule: 9/80 - Employees work 9 out of every 14 days – totaling 80 hours worked – and have every other Friday off
Job Description:
The Lead Incident Response and Security Operations Engineer establish, operates, and continuously improves the Enterprise Product and Services’ incident response and security operations capability across a government-owned, contractor-operated hybrid environment that includes Amazon Web Services (AWS), multiple data centers, and a corporate location.
The role leads monitoring, investigation, detection engineering, incident coordination, and risk escalation to strengthen the availability, integrity, and confidentiality of GSS services.
Infrastructure, system, and application owners retain responsibility for technical remediation, patching, and platform repair.
Essential Functions:
- 15% travel based on business needs (CONUS or OCONUS).
- Ability to work a flexible schedule includes off-shift work, weekends, occasional overtime, and on-call duties.
- Establish and maintain security information and event management operations, including Wazuh health, log ingestion, data-quality validation, alert rules, dashboards, and detection tuning.
- Monitor, triage, investigate, document, and coordinate response to security events across AWS, datacenter, network, endpoint, and corporate environments.
- Create and manage security-incident tickets; preserve investigation evidence; document findings and actions; and validate closure with responsible technical owners.
- Develop and maintain incident-response plans, escalation paths, severity criteria, playbooks, runbooks, and after-action reports.
- Coordinate remediation tracking for vulnerabilities, security findings, and incident corrective actions, escalating overdue or material risk.
- Conduct AWS security-alert and exposure reviews, including identity and access management, privileged access, logging, and cloud-security findings within assigned authority.
- Onboard and maintain log sources and integrations needed to support monitoring, detection, incident investigation, and compliance evidence.
- Conduct periodic reviews of privileged access, security-tool access, and operational logging coverage; support disaster-recovery and incident-response exercises.
- Produce security-operations metrics, risk reports, and stakeholder briefings, and maintain documentation supporting the Risk Management Framework, audit readiness, and continuous monitoring.
Qualifications:
- Active US Secret security clearance or higher.
- Bachelor’s Degree and minimum 9 years of prior relevant experience.
- Graduate Degree and a minimum of 7 years of prior related experience.
- In lieu of a degree, a minimum of 13 years of prior related experience.
- Current in at least one of the following;
Certified Information Security Manager, Certified Information Systems Auditor, Certified Cloud Security Professional, Certificate of Cloud Security Knowledge, or comparable Department of Defense…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).