Information Systems Security Engineer

National Security Agency

Fort Meade (MD)

On-site

USD 87,000 - 153,000

Full time

16 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Comprehensive benefits

Job summary

NSA in Fort Meade, MD seeks an Information Systems Security Engineer from entry to mid level to help defend critical IT systems supporting SIGINT and Cybersecurity missions. You will design system and network architectures, implement risk management, and lead hardening efforts across cloud and on‑premises environments.

Qualifications include a degree in Computer Science or related field, experience in security, vulnerability analysis, and secure coding.

Qualifications

  • Degree must be in Computer Science or a related field (e.g., Engineering, Mathematics, Data Science, Artificial Intelligence, Computer Forensics, Cybersecurity, Information Technology, Information Assurance, Information Security, Information Systems, Informatics, Cyber Operations, and Cyber Defense).
  • Relevant experience in areas such as system design/development; programming; information/cyber/network security; system or network administration; vulnerability analysis; penetration testing; computer forensics; systems engineering; reverse engineering; or updating information assurance documentation (e.g., SSPs, Risk Assessments, CA packages, TRMs).
  • Completion of military training or cybersecurity certifications may count toward experience (e.g., JCAC, UCT, NWBC/INWT, Cyber Defense Ops; CISSP, CAP).

Responsibilities

  • Design system/network architectures to enforce confidentiality, integrity and availability
  • Define and manage remediation plans across applications, infrastructure, and cloud
  • Ensure compliance with cybersecurity standards (e.g. NIST)
  • Assess and mitigate risks in legacy systems, misconfigurations, and vulnerabilities
  • Analyze and prioritize vulnerabilities with cross functional teams
  • Lead and oversee patching and hardening of infrastructure
  • Define information system security requirements and functionality
  • Review security configurations of cloud services and recommend settings
  • Understand cryptography and programming (Python, Java)
  • Assess effectiveness of security solutions against frameworks (e.g., MITRE ATT&CK)
  • Monitor cybersecurity hygiene and direct remediation to reduce adversary risks
  • Understand OS, networks, applications, and controls security concepts
  • Operate with teams implementing security procedures in cloud environments
  • Conduct security engineering/hardening of OSes for mission areas
  • Implement automation and AI across the RMF lifecycle and continuous monitoring

Skills

Security frameworks
Vulnerability remediation
Cloud security
Secure coding
Risk translation
Vulnerability scanning
Container security
Threat modeling
Critical thinking

Education

Bachelor's degree in Computer Science or related field

Tools

Kubernetes
Docker
Cloud platforms (AWS/Azure/Google)

Job description

Information Systems Security Engineer - Entry to Mid Level (Maryland)

Fort George G. Meade Complex, MD. Pay Plan: GG, Grade: 07/1 to 12/10.

Responsibilities

Information System Security Professionals at NSA play a vital role in architecting, designing, operating, defending, and maintaining secure state of the art Information Technology (IT) systems executing NSA's SIGINT and Cybersecurity missions. NSA is advancing technology to deliver mission outcomes.

  • Design system/network architectures to enforce levels of confidentiality, integrity and availability
  • Ability to implement systems engineering principles/methodology
  • Define and manage remediation plans across applications, infrastructure, and cloud
  • Ensure compliance with cybersecurity standards and regulatory requirements (e.g. NIST)
  • Assess and mitigate risks in legacy systems, misconfigurations, and vulnerabilities
  • Analyze and prioritize vulnerabilities with cross functional teams
  • Lead and provide oversight to activities to patch and harden infrastructure systems
  • Define information system security requirements and functionality
  • Review security configuration options of cloud services and recommend security configurations
  • Understand cryptography and the ability to program (Python, Java, etc.)
  • Assess effectiveness of security solutions against cybersecurity frameworks (e.g. MITRE ATT&CK)
  • Monitor the cybersecurity hygiene for a family of IT systems directing remediation of configuration and vulnerability findings to reduce the adversary risks to systems
  • Understand concepts, principles, structure and standards used to design, implement, monitor and secure operating systems, equipment, networks, applications and controls
  • Operate within teams focused on implementing and evolving procedures and security settings designed to protect data and applications in cloud environments
  • Conduct security engineering/hardening of the latest operating systems, tailoring them for use in the specific mission area
  • Ability to implement automation and artificial intelligence across the RMF authorization life cycle and into continuous monitoring
Job Summary

Are you a cyber professional with the drive and expertise to be on the forefront of the cyber fight; tackling NSA's complex mission to defend against cyber threats of today and tomorrow? NSA, the nation's leading cyber agency, has exciting and challenging positions in Cyber Security Engineering and Cyber and TEMPEST vulnerability analysis/mitigation. Are you ready to help secure our Nation's critical Infrastructure? If so, NSA is the place for you!

Qualifications

The qualifications listed are the minimum acceptable to be considered for the position. Degree must be in Computer Science or a related field (for example Engineering, Mathematics, Data Science, Artificial Intelligence, Computer Forensics, Cybersecurity, Information Technology, Information Assurance, Information Security, Information Systems, Informatics, Cyber Operations, and Cyber Defense).Relevant experience must be in one or more of the following areas: computer or information systems design/development; programming; information/ cyber/network security; system or network administration; vulnerability analysis; penetration testing; computer forensics; systems engineering; computer systems research; reverse engineering; or updating information assurance documentation (for example System Security Plans, Risk Assessment Reports, Certification and Accreditation packages, and System Requirements Traceability Matrices).Completion of military training in a relevant area such as JCAC (Joint Cyber Analysis course), Undergraduate Cyber Training (UCT), Network Warfare Bridge Course (NWBC)/Intermediate Network Warfare Training (INWT), or Cyber Defense Operations will be considered towards the relevant experience requirement (i.e., 20-24 weeks course will count as 6 months of experience, 10-14 weeks will count as 3 months of experience). Cybersecurity Certifications (e.g., NET+, Security+, Certified Information System Security Professional (CISSP), and Certification Accreditation Professional (CAP)) may count as a total of 1 year of experience. ENTRY/DEVELOPMENTALEntry is with an Associate's degree plus 2 years of relevant experience, or a Bachelor's degree and no experience. FULL PERFORMANCEEntry is with an Associate's degree plus 5 years of relevant experience, or a Bachelor's degree plus 3 years of relevant experience, or a Master's degree plus 1 year of relevant experience, or a Doctoral degree and no experience.

  • Understanding of security frameworks (e.g. NIST 800-53, ISO 27001, CIS)
  • Understanding and experience prioritizing and remediating vulnerabilities across hybrid network environments
  • Cloud Security Knowledge for commercial cloud environments such as Amazon Web Services, Microsoft Azure, Oracle or Google cloud environments
  • Familiarity with secure coding, DevSecOps, and CI/CD pipelines
  • Ability to translate complex security issues into actionable guidance
  • Understanding of vulnerability scanning tools
  • Understanding of container security with knowledge of Kubernetes, Docker, and container hardening practices
  • Understanding of threat modeling and how to design mitigation strategies
  • Critical thinking and ability to break large complex problems into manageable parts

Pay: Salary offers are based on candidates' education level and years of experience relevant to the position and also take into account information provided by the hiring manager/organization regarding the work level for the position. Salary Range: $87,362 - $153,082 (Entry/Developmental, Full Performance). Salary range varies by location, work level, and relevant experience to the position. Training will be provided based on the selectee's needs and experience.

Benefits: NSA offers a comprehensive benefits package.

Work Schedule: This is a full-time position, Monday - Friday, with basic 8hr/day work requirement between 6:00 a.m. and 6:00 p.m. (flexible).

DCIPS Trial Period:If selected for this position, you will be required to serve a two-year DCIPS trial period, unless you are a veterans' preference-eligible employee, in which case you are required to serve a one-year trial period. This trial period runs concurrently with your commitment to the position, if applicable. Before finalizing your appointment at the conclusion of your trial period, NSA will determine whether your continued employment advances the public interest. This decision will be based on factors such as your performance and conduct; the Agency's needs and interests; whether your continued employment would advance the Agency's organizational goals; and whether your continued employment would advance the efficiency of the Federal service. Upon completion of your trial period, your employment will be terminated unless you receive certification, in writing, that your continued employment advances the public interest. If you do not receive certification for continued employment, you should receive written notice prior to the end of your trial period that your employment will be terminated and the effective date of such termination.

U.S. Citizenship is required for all applicants. NSA is an equal opportunity employer and abides by applicable employment laws and regulations. All applicants and employees are subject to random drug testing in accordance with Executive Order 12564. Employment is contingent upon successful completion of a security background investigation and polygraph. NSA is committed to providing reasonable accommodations to qualified applicants with disabilities during the application and hiring process.

DCIPS Disclaimer

**VETERANS AND TRANSITIONING SERVICE MEMBERS** Thank you for your service! The National Security Agency (NSA) is part of the Defense Civilian Intelligence Personnel System (DCIPS). All positions at NSA are in the Excepted Service under Title 10, United States Codes (U.S.C.), Section 1601 appointment authority. Veterans' PreferenceIn accordance with the procedures provided in DoD Instruction 1400.25, Volume 2005, "DoD Civilian Personnel Management System: Defense Civilian Intelligence Personnel System Employment and Placement," NSA applies veterans' preference, as defined by Section 2108 of Title 5, U.S.C., to eligible candidates. If you are claiming veterans' preference, you are required to provide acceptable documentation of your preference eligibility upon application.Acceptable documentation includes: - DD-214: "Certificate of Release or Discharge from Active Duty," which shows dates of service and discharge under honorable conditions (Copy 4); OR- Certification of Service:A written document on letterhead from the appropriate branch of the armed forces that certifies the service member is expected to be discharged or released from active duty service in the armed forces under honorable conditions not later than 120 days after the date the certification is signed. The certification should include the military service dates, including the expected discharge or release date; AND- Standard Form 15 (SF-15)Application for 10-point Veteran Preference (http://www.opm.gov/forms/pdf_fill/sf15.pdf).If you are claiming a service-connected disability of 30 percent or more, the documentation you provide must specifically demonstrate this level of disability; AND- VA Letter of Disability (for 10pt and Sole Survivorship rating)You may obtain a letter from the Department of Veterans Affairs reflecting your level of disability for preference eligibility by visiting a VA Regional Office, contacting a VA call center, or online (https://www.ebenefits.va.gov/).**Failure to provide sufficient documentation of veterans' preference eligibility may preclude NSA from identifying you as a preference eligible candidate during the hiring selection process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

System Vulnerability Analyst
System Vulnerability Analyst

National Security Agency • Fort Meade (MD)

On-site
USD 105,000 - 193,000
Digital Network Exploitation Analyst
Digital Network Exploitation Analyst

National Security Agency • Fort Meade (MD)

On-site
USD 105,000 - 153,000
Benefits package
Hardware Analysis & Design Engineer
Hardware Analysis & Design Engineer

National Security Agency • Fort Meade (MD)

On-site
USD 87,000 - 153,000
Engineer/Developer - Software, Hardware, Research (Capabilities Development Specialist)
Engineer/Developer - Software, Hardware, Research (Capabilities Development Specialist)

National Security Agency • Fort Meade (MD)

On-site
USD 105,000 - 193,000
Comprehensive benefits
Information Systems Security Engineer - Entry to Mid Level (Maryland)
Information Systems Security Engineer - Entry to Mid Level (Maryland)

National Security Agency • Fort Meade (MD)

On-site
USD 87,000 - 153,000
Network Systems Officer
Network Systems Officer

National Security Agency • San Antonio (TX)

On-site
USD 87,000 - 123,000
Comprehensive benefits
Digital Network Exploitation Analyst - Mid Level (Maryland)
Digital Network Exploitation Analyst - Mid Level (Maryland)

National Security Agency • Fort Meade (MD)

On-site
USD 105,000 - 153,000
Engineer/Developer - Software, Hardware, Research (Capabilities Development Specialist) - Mid to Experienced Level (MD, TX, CO)
Engineer/Developer - Software, Hardware, Research (Capabilities Development Specialist) - Mid to Experienced Level (MD, TX, CO)

National Security Agency • Fort Meade (MD)

On-site
USD 105,000 - 193,000
Logistics Services Officer
Logistics Services Officer

National Security Agency • Fort Meade (MD)

On-site
USD 76,000 - 133,000
Benefits package
AI Engineer
AI Engineer

National Security Agency • Fort Meade (MD)

On-site
USD 87,000 - 197,000