Information Systems Security Engineer
Listed on 2026-09-14
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Systems Engineer
Residency
All applicants must currently reside in the United States
OverviewBig Bear.ai is seeking an Information System Security Engineer (ISSE) to join our Information Services team, based out of Hill AFB, Utah and have an important role in supporting our mission of Strategic Deterrence through continual improvement and innovation. You’ll be supporting a cybersecurity effort to provide assistance obtaining and maintaining Air Force, Department of Defense (DoD), and public law compliance for enterprise business solutions and ICBM weapon system information technology, assisting and advising Air Force Nuclear Weapons Center (AFNWC) and MMIII & Sentinel Systems Directorates acquisition programs in applying the Risk Management Framework (RMF) Lifecycle steps throughout all DoD acquisition program phases.
Whatyou will do
- Ensure the confidentiality, integrity and availability of classified information systems and networks.
- Enforce information systems security programs, policies, procedures, and tools.
- Analyze equipment and software reliability and suitability for vulnerability assessment utilization.
- Conduct analyses of classified network usage, hardware and software capabilities, ineffective practices or procedures, equipment shortcomings, and other relevant factors.
- Conduct risk and vulnerability assessments of classified information systems to identify associated vulnerabilities, risks and protection needs.
- Perform, document and provide recommendations to the ISSM on security audits, evaluations, and risk assessments for all classified systems.
- Update and complete all Body of Evidence paperwork and artifacts.
- Serve as a technical expert and focal point for cybersecurity policies, planning, programs, initiatives, certification, and accreditation.
- Provide recommendations and assistance regarding security aspects of processing, storage, retrieval, transmission, and access of classified and unclassified information.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related Engineering field and a minimum of 8 years experience
- Master’s degree (MS or MBA) and 6 years of relevant experience.
- The applicant must meet DoD 8570.01-M IAT Level II, IAM Level I or higher certification requirements on hire date.
- Professional experience in information security, with a proven track record of leading large-scale projects
- Experience designing and implementing secure network architectures, Zero Trust environments, and cloud security frameworks (AWS, Azure, or GCP)
Deep experience operating within regulatory frameworks such as NIST (800-53, 800-171), ISO 27001, CMMC, or SOC2 - Incident Response:
Experience leading high-severity security incident responses and conducting post-mortem root cause analyses - Threat Modeling:
Proficiency in using frameworks like STRIDE or PASTA to identify vulnerabilities - Security Tooling:
Expert-level knowledge of SIEM (Splunk, Sentinel), EDR/XDR, Firewalls, and Vulnerability Scanners (Nessus, Qualys)
Identity & Access Management (IAM):
Expertise in OAuth, SAML, and multi-factor authentication (MFA) implementation - Secure Coding/Dev Sec Ops :
Ability to integrate security into the CI/CD pipeline using SAST (Static Analysis) and DAST (Dynamic Analysis) tools
Strategic Planning:
Ability to translate business requirements into a technical security roadmap - Stakeholder Management:
Capable of communicating complex technical risks to non-technical executives to secure budget and buy-in
Please note the targeted compensation range is provided as an estimate, and any actual compensation offer may vary depending on the needs of the company, or an applicant's skillset, competencies, experience, education, certifications,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).