Skip to main content

Information Systems Security Engineer - Entry to Mid Level (Maryland)

National Security AgencySecurity
Pay
$87K–$153K
per year
Work mode
On-site
Full Time
Education
Associate's

Fort Meade, Maryland, MD at a glance

Rent
#7 of 51
1-bedroom+23% vs US avg
Weather
#29 of 51
165 mild daysstatewide median
Income tax
#14 of 51
6.5% top rateMaryland

What you need

  • Associate's degree plus 2 yrs, or Bachelor's degree
  • Degree in Computer Science or related field
  • Understanding of security frameworks such as NIST 800-53
  • Cloud security knowledge for AWS, Azure, Google Cloud
  • Understanding of container security with Kubernetes, Docker

What you'll do

  • Design system and network architectures to enforce security
  • Define and manage remediation plans across systems
  • Assess and mitigate risks in legacy systems
  • Implement security engineering and hardening of operating systems
  • Monitor cybersecurity hygiene and direct remediation activities

Are you a cyber professional with the drive and expertise to be on the forefront of the cyber fight; tackling NSA's complex mission to defend against cyber threats of today and tomorrow? NSA, the nation's leading cyber agency, has exciting and challenging positions in Cyber Security Engineering and Cyber and TEMPEST vulnerability analysis/mitigation. Are you ready to help secure our Nation's critical Infrastructure? If so, NSA is the place for you!

Major Duties

Information System Security Professionals at NSA play a vital role in in the architecting, designing, operating, defending, and maintaining secure state of the art Information Technology (IT) systems executing NSA's SIGINT and Cybersecurity missions. NSA is advancing technology to deliver mission outcomes. As such, Cybersecurity Professionals have the opportunity to work across a broad set of technologies including commercial cloud fabrics, artificial intelligence, high performance computing, and advanced cryptographic systems. These personnel are involved in the full life cycle of systems: designing, maintaining and monitoring the systems so they can be protected from the most sophisticated nation-state adversaries. Some examples of tasks include: - Design system/network architectures to enforce levels of confidentiality, integrity and availability - Ability to implement systems engineering principles/methodology - Define and manage remediation plans across applications, infrastructure, and cloud - Ensure compliance with cybersecurity standards and regulatory requirements (e.g. NIST) - Assess and mitigate risks in legacy systems, misconfigurations, and vulnerabilities - Analyze and prioritize vulnerabilities with cross functional teams - Lead and provide oversight to activities to patch and harden infrastructure systems - Define information system security requirements and functionality - Review security configuration options of cloud services and recommend security configurations - Understand cryptography and the ability to program (Python, Java, etc.) - Assess effectiveness of security solutions against cybersecurity frameworks (e.g. MITRE ATT&CK) - Monitor the cybersecurity hygiene for a family of IT systems directing remediation of configuration and vulnerability findings to reduce the adversary risks to systems - Understand concepts, principles, structure and standards used to design, implement, monitor and secure operating systems, equipment, networks, applications and controls - Operate within teams focused on implementing and evolving procedures and security settings designed to protect data and applications in cloud environments - Conduct security engineering/hardening of the latest operating systems, tailoring them for use in the specific mission area - Ability to implement automation and artificial intelligence across the RMF authorization life cycle and into continuous monitoring

Qualifications

The qualifications listed are the minimum acceptable to be considered for the position. Relevant experience must be in one or more of the following areas: computer or information systems design/development; programming; information/ cyber/network security; system or network administration; vulnerability analysis; penetration testing; computer forensics; systems engineering; computer systems research; reverse engineering; or updating information assurance documentation (for example System Security Plans, Risk Assessment Reports, Certification and Accreditation packages, and System Requirements Traceability Matrices). Completion of military training in a relevant area such as JCAC (Joint Cyber Analysis course), Undergraduate Cyber Training (UCT), Network Warfare Bridge Course (NWBC)/Intermediate Network Warfare Training (INWT), or Cyber Defense Operations will be considered towards the relevant experience requirement (i.e., 20-24 weeks course will count as 6 months of experience, 10-14 weeks will count as 3 months of experience). Cybersecurity Certifications (e.g., NET+, Security+, Certified Information System Security Professional (CISSP), and Certification Accreditation Professional (CAP)) may count as a total of 1 year of experience. ENTRY/DEVELOPMENTAL Entry is with an Associate's degree plus 2 years of relevant experience, or a Bachelor's degree and no experience. FULL PERFORMANCE Entry is with an Associate's degree plus 5 years of relevant experience, or a Bachelor's degree plus 3 years of relevant experience, or a Master's degree plus 1 year of relevant experience, or a Doctoral degree and no experience.

Education

Degree must be in Computer Science or a related field (for example Engineering, Mathematics, Data Science, Artificial Intelligence, Computer Forensics, Cybersecurity, Information Technology, Information Assurance, Information Security, Information Systems, Informatics, Cyber Operations, and Cyber Defense).

Promotion Potential

GG-None

How You Will Be Evaluated

- Understanding of security frameworks (e.g. NIST 800-53, ISO 27001, CIS) - Understanding and experience prioritizing and remediating vulnerabilities across hybrid network environments - Cloud Security Knowledge for commercial cloud environments such as Amazon Web Services, Microsoft Azure, Oracle or Google cloud environments - Familiarity with secure coding, DevSecOps, and CI/CD pipelines - Ability to translate complex security issues into actionable guidance - Understanding of vulnerability scanning tools - Understanding of container security with knowledge of Kubernetes, Docker, and container hardening practices - Understanding of threat modeling and how to design mitigation strategies - Critical thinking and ability to break large complex problems into manageable parts

Who Can Apply

  • Current federal employees — excepted service
  • Individuals with disabilities
  • Military spouses
  • Open to the public
  • Veterans

Required Documents

The National Security Agency (NSA) is part of the DoD Intelligence Community Defense Civilian Intelligence Personnel System (DCIPS). All positions in the NSA are in the Excepted Services under 10 United States Codes (USC) 1601 appointment authority. DoD Components with DCIPS positions apply Veterans' Preference to eligible candidates as defined by Section 2108 of Title 5 USC, in accordance with the procedures provided in DoD Instruction 1400.25, Volume 2005, DCIPS Employment and Placement. If you are a veteran claiming veterans' preference, as defined by Section 2108 of Title 5 U.S.C., you may be asked to submit documents verifying your eligibility.

How to Apply

https://apply.intelligencecareers.gov/job-description/1262886

What to Expect Next

https://apply.intelligencecareers.gov/job-description/1262886

Other Information

Pay: Salary offers are based on candidates' education level and years of experience relevant to the position and also take into account information provided by the hiring manager/organization regarding the work level for the position. Salary Range: $87,362 - $153,082 (Entry/Developmental, Full Performance) Salary range varies by location, work level, and relevant experience to the position. Training will be provided based on the selectee's needs and experience. Benefits: NSA offers a comprehensive benefits package. Work Schedule: This is a full-time position, Monday - Friday, with basic 8hr/day work requirement between 6:00 a.m. and 6:00 p.m. (flexible).

Optimize your resume for this job

Get a match score and the keywords you're missing

Optimize resume

About National Security Agency

The National Security Agency (NSA) is the U.S. intelligence agency responsible for signals intelligence (SIGINT), cybersecurity, and information assurance for U.S. national security systems. Established in 1952 under the Department of Defense, NSA collects and analyzes foreign communications and signals data, develops cryptographic systems, and defends U.S. classified networks against cyber threats.

Similar Security roles

Information Systems Security Engineer - Entry to Mid Level (Maryland)
$87K–$153K · National Security Agency
Apply