Leads information systems security, risk assessment, compliance, vulnerability management, and authorization activities. Develops security documentation, supports ATO and ATT packages, reviews SCAP and STIG scans, coordinates remediation and incident responses, evaluates security controls, and works with government customers, ISSOs, infrastructure teams, and authorizing officials to maintain system security across on-premises and cloud environments.
Job Description
Senior level capabilities regarding Information system security. Knowledgeable of current Information Assurance (IA) technologies to the architecture, design, development, evaluation, and integration of applications, systems,
and networks to maintain the system security posture. Develops compliancy and standardization within policies regarding various information systems. Work closely with Government customers to ensure the confidentiality, integrity, and availability of systems, applications, networks, and data through the planning, analysis,
development, implementation, maintenance, and enhancement of information systems security programs; infrastructure; application; Security Assessment and Authorization (SAA), policy directives (PD) and guides (PG); and IA Security tools (e.g., Tenable.io, Nessus Pro, NMap, etc.).
Required Education, Experience, & Skills
Have excellent verbal and written communication skills to be able toaccurat ely relate requirements and document all within the appropriate security document and/or within the RMF system and coordinate with program, other
system(s), and security personnel; Prepare documentation from templates such as, but not limited to,
Configuration Management Plan (CMP), Incident Response Plan (IRP), Information System Contingency Plan (ISCP), and Plan of Action and Milestones (POA&M) to ensure compliance with PDs and PGs and Federal IA
requirements as well as coordinate review(s) and approvals; Must be able to discern the program policies and procedures, identify areas that need work and bring up to management for resolution; Identify IA vulnerabilities and coordinate with the Infrastructure and Development teams to correct, mitigated or apply for an exception via the
POA&M processes; Review vulnerability (i.e., patches, updates, etc.) and compliance (i.e., Security Content Automation Protocol (SCAP) and/or Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG)) scans on the infrastructure and applications to ensure patch and configuration compliance (on-premises and in the cloud (AWS preferred)) Prepares SAA package(s) to obtain and maintain an authority-to-operate
(ATO), authority-to-test (ATT), or other SAA authority types for all systems and applications; Attend Configuration Control Board (CCB) meetings and review all change requests for impact to the system/application security posture(s) and applicable Federal and PD and PG compliance requirements; and document decisions
within the CMP; Coordinate security incident and high priority compliance responses with the Enterprise Security Operations Center (ESOC); Represent program security interests in various meetings within and outside
of the program; Schedule and conduct meetings with pertinent program personnel to address findings to determine appropriate path forward and document within the CMP and, if necessary, POA&M; Coordinates with other system Information System Security Officers (ISSO) to ensure that their requirements for interconnection, policy and procedures are met and all documentation is provided and updated as necessary; Ability to assess current and evolving security threats in an operational environment; With an appropriate amount of Government PM guidance, works independently to carry out all technical requirements as directed by the Government PM, Information System Security Representative, Information System Security Manager, and Authorizing Official in a timely manner.
Ten (10) years of experience performing security requirement analysis, system
design, of computer systems.
Bachelor of Science (B.S.) Degree in Computer Security or related field of study; (ISC)2 Information Security Certification(s) (e.g., CISSP, CAP, etc.); or in lieu of education, an additional five (5) years of relevant
experience that addresses all requirements of the position.
Preferred Education, Experience, & Skills
Experience in a cyber-risk and compliance management system (e.g., Xacta, RiskVision, etc.); One (1) year experience or more configuring, performing, scheduling, reviewing, and assessing vulnerability (i.e., patches, updates, etc.) and compliance (i.e., Security Content Automation Protocol (SCAP) and/or Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG)) scans on the infrastructure and applications to ensure patch and configuration compliance on-premises and in the cloud (AWS preferred); Technical background that will assist in assessing the NIST SP 800-53 security controls and gather evidence to support conclusions; and Knowledge of operating systems, network and application security to aid implementation of information security and assurance principle; and Knowledge of SPLUNK software and tools.
Pay Information
Full-Time Salary Range: $136000 - $231200
Please note: This range is based on our market pay structures. However, individual salaries are determined by a variety of factors including, but not limited to: business considerations, local market conditions, and internal equity, as well as candidate qualifications, such as skills, education, and experience.
Employee Benefits: At BAE Systems, we support our employees in all aspects of their life, including their health and financial well-being. Regular employees scheduled to work 20+ hours per week are offered: health, dental, and vision insurance; health savings accounts; a 401(k) savings plan; disability coverage; and life and accident insurance. We also have an employee assistance program, a legal plan, and other perks including discounts on things like home, auto, and pet insurance. Our leave programs include paid time off, paid holidays, as well as other types of leave, including paid parental, military, bereavement, and any applicable federal and state sick leave. Employees may participate in the company recognition program to receive monetary or non-monetary recognition awards. Other incentives may be available based on position level and/or job specifics.
About BAE Systems Intelligence & Security
BAE Systems, Inc. is a defense, aerospace, and security company headquartered in Falls Church, Virginia, with more than 40,000 employees worldwide. We serve, supply, and protect those who protect us. As one of the most geographically diverse international defense companies, we deliver a full range of products and services spanning air, land, maritime, space, and cyber, including advanced electronics, intelligence solutions, and dedicated customer support.
Our culture is performance-driven and values-led, built on curiosity, creativity, and collaboration. Purpose isn't a tagline here. It's what drives us. We're developing breakthrough technologies that defend national security and make a lasting impact on our communities and our planet. When you join BAE Systems, you're not just building a career. You're contributing to a mission that truly matters.
This position will be posted for at least 5 calendar days. The posting will remain active until the position is filled, or a qualified pool of candidates is identified.
Senior level capabilities regarding Information system security. Knowledgeable of current Information Assurance (IA) technologies to the architecture, design, development, evaluation, and integration of applications, systems,
and networks to maintain the system security posture. Develops compliancy and standardization within policies regarding various information systems. Work closely with Government customers to ensure the confidentiality, integrity, and availability of systems, applications, networks, and data through the planning, analysis,
development, implementation, maintenance, and enhancement of information systems security programs; infrastructure; application; Security Assessment and Authorization (SAA), policy directives (PD) and guides (PG); and IA Security tools (e.g., Tenable.io, Nessus Pro, NMap, etc.).
Required Education, Experience, & Skills
Have excellent verbal and written communication skills to be able toaccurat ely relate requirements and document all within the appropriate security document and/or within the RMF system and coordinate with program, other
system(s), and security personnel; Prepare documentation from templates such as, but not limited to,
Configuration Management Plan (CMP), Incident Response Plan (IRP), Information System Contingency Plan (ISCP), and Plan of Action and Milestones (POA&M) to ensure compliance with PDs and PGs and Federal IA
requirements as well as coordinate review(s) and approvals; Must be able to discern the program policies and procedures, identify areas that need work and bring up to management for resolution; Identify IA vulnerabilities and coordinate with the Infrastructure and Development teams to correct, mitigated or apply for an exception via the
POA&M processes; Review vulnerability (i.e., patches, updates, etc.) and compliance (i.e., Security Content Automation Protocol (SCAP) and/or Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG)) scans on the infrastructure and applications to ensure patch and configuration compliance (on-premises and in the cloud (AWS preferred)) Prepares SAA package(s) to obtain and maintain an authority-to-operate
(ATO), authority-to-test (ATT), or other SAA authority types for all systems and applications; Attend Configuration Control Board (CCB) meetings and review all change requests for impact to the system/application security posture(s) and applicable Federal and PD and PG compliance requirements; and document decisions
within the CMP; Coordinate security incident and high priority compliance responses with the Enterprise Security Operations Center (ESOC); Represent program security interests in various meetings within and outside
of the program; Schedule and conduct meetings with pertinent program personnel to address findings to determine appropriate path forward and document within the CMP and, if necessary, POA&M; Coordinates with other system Information System Security Officers (ISSO) to ensure that their requirements for interconnection, policy and procedures are met and all documentation is provided and updated as necessary; Ability to assess current and evolving security threats in an operational environment; With an appropriate amount of Government PM guidance, works independently to carry out all technical requirements as directed by the Government PM, Information System Security Representative, Information System Security Manager, and Authorizing Official in a timely manner.
Ten (10) years of experience performing security requirement analysis, system
design, of computer systems.
Bachelor of Science (B.S.) Degree in Computer Security or related field of study; (ISC)2 Information Security Certification(s) (e.g., CISSP, CAP, etc.); or in lieu of education, an additional five (5) years of relevant
experience that addresses all requirements of the position.
Preferred Education, Experience, & Skills
Experience in a cyber-risk and compliance management system (e.g., Xacta, RiskVision, etc.); One (1) year experience or more configuring, performing, scheduling, reviewing, and assessing vulnerability (i.e., patches, updates, etc.) and compliance (i.e., Security Content Automation Protocol (SCAP) and/or Defense Information Systems Agency (DISA) Security Technical Implementation Guide (STIG)) scans on the infrastructure and applications to ensure patch and configuration compliance on-premises and in the cloud (AWS preferred); Technical background that will assist in assessing the NIST SP 800-53 security controls and gather evidence to support conclusions; and Knowledge of operating systems, network and application security to aid implementation of information security and assurance principle; and Knowledge of SPLUNK software and tools.
Pay Information
Full-Time Salary Range: $136000 - $231200
Please note: This range is based on our market pay structures. However, individual salaries are determined by a variety of factors including, but not limited to: business considerations, local market conditions, and internal equity, as well as candidate qualifications, such as skills, education, and experience.
Employee Benefits: At BAE Systems, we support our employees in all aspects of their life, including their health and financial well-being. Regular employees scheduled to work 20+ hours per week are offered: health, dental, and vision insurance; health savings accounts; a 401(k) savings plan; disability coverage; and life and accident insurance. We also have an employee assistance program, a legal plan, and other perks including discounts on things like home, auto, and pet insurance. Our leave programs include paid time off, paid holidays, as well as other types of leave, including paid parental, military, bereavement, and any applicable federal and state sick leave. Employees may participate in the company recognition program to receive monetary or non-monetary recognition awards. Other incentives may be available based on position level and/or job specifics.
About BAE Systems Intelligence & Security
BAE Systems, Inc. is a defense, aerospace, and security company headquartered in Falls Church, Virginia, with more than 40,000 employees worldwide. We serve, supply, and protect those who protect us. As one of the most geographically diverse international defense companies, we deliver a full range of products and services spanning air, land, maritime, space, and cyber, including advanced electronics, intelligence solutions, and dedicated customer support.
Our culture is performance-driven and values-led, built on curiosity, creativity, and collaboration. Purpose isn't a tagline here. It's what drives us. We're developing breakthrough technologies that defend national security and make a lasting impact on our communities and our planet. When you join BAE Systems, you're not just building a career. You're contributing to a mission that truly matters.
This position will be posted for at least 5 calendar days. The posting will remain active until the position is filled, or a qualified pool of candidates is identified.
BAE Systems, Inc. San Jose, California, USA Office
6331 San Ignacio Avenue, San Jose, CA, United States, 95119
Similar Jobs at BAE Systems, Inc.
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Develops and executes business development strategies for BAE Systems’ Assured Position, Navigation and Timing portfolio. Builds relationships with Department of Defense, international FMS customers, government officials, platform primes, and industry partners; identifies and qualifies opportunities; develops win strategies and market assessments; supports bid/no-bid decisions, customer engagement, proposal turnover, and export licensing. Requires extensive defense acquisition expertise, active Secret clearance, and approximately 75% travel.
Top Skills:
Anti-JamAssured Position Navigation And Timing (Apnt)Dcs Export LicensingFmsMilitary GpsNavwarWeapons Systems Conops
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Performs electrical and mechanical component analysis, selection, qualification, and procurement support for aerospace and space products. Evaluates piece-part requirements, supplier offerings, testing, screening, certification, and reliability standards. Develops procurement specifications, non-standard parts approval requests, source control documents, and related qualification documentation while coordinating with procurement, quality, manufacturers, suppliers, and engineering teams.
Top Skills:
Aerospace Tor StandardsDataviewMS OfficeMil-StdNasa Space Parts StandardsProduct Data Manager
Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Leads software architecture and development for RF seeker and guidance systems across the full tactical embedded-system lifecycle. Defines interfaces among RF front ends, DSP layers, and flight-control software; guides requirements, trade studies, technical strategy, integration, verification, scope, schedules, and budgets. Serves as a subject matter expert, collaborates with customers and technical leadership, and mentors software and systems engineers. Requires expertise in RF/Radar seeker architectures and an active Secret clearance.
Top Skills:
Active Rf/RadarDigital Signal Processing (Dsp)Flight Control SoftwareImaging Infrared (Iir)Passive RfRf Seeker SystemsRf/Radar SensorsSemi-Active Laser (Sal)Tactical Embedded Systems
What you need to know about the San Francisco Tech Scene
San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.
Key Facts About San Francisco Tech
- Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Google, Apple, Salesforce, Meta
- Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
- Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
- Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

