Information Systems Security Officer, AD&S

2 days, 23 hours ago
Full-time
Senior
DevOps and Infrastructure
Anduril Industries

Anduril Industries

Anduril Industries is an American defense technology firm that specializes in developing advanced autonomous systems for integrated awareness and security across land, sea, and air, utilizing its proprietary Lattice platform to enhance intelligence, su...

Aerospace & Defense
1K-5K
Founded 2017
$2200M raised

Description

  • Document security controls for systems to satisfy cybersecurity framework requirements.
  • Perform iterative security activities to meet compliance requirements and deliver results.
  • Apply commercial technology standards in classified and air-gapped environments.
  • Support the ISSM, other ISSOs, and the Classified Infrastructure team in solving complex technical and contractual security needs.
  • Tailor NIST 800-53 controls for the network environment and oversee continuous monitoring programs.
  • Define, document, and conduct security scanning for Anduril products and accredited information systems.
  • Scope, shape, and coordinate feature development to ensure products meet compliance goals.
  • Maintain security posture through audits, risk assessments, vulnerability assessments, and incident response activities.
  • Maintain SSPs, POA&Ms, and other accreditation documentation.
  • Collaborate with government security officials, stakeholders, and internal teams to close security gaps and improve controls.

Requirements

  • Design, develop, and implement secure systems and networks per NIST RMF, JSIG, and other industry standards.
  • Experience participating in security risk assessments, vulnerability assessments, and audits.
  • Knowledge of security solutions such as IDS/IPS, encryption protocols, and secure communications technologies.
  • Experience developing and enforcing access controls, encryption strategies, and other technical safeguards.
  • Experience maintaining System Security Plans (SSPs), POA&Ms, and accreditation documentation.
  • Experience managing security posture and ensuring compliance with internal policies and external regulatory frameworks.
  • Experience supporting Authorization and Accreditation (A&A) processes to obtain or maintain system Authority to Operate (ATO).
  • Ability to assist with or lead incident response efforts, including investigation, root cause analysis, containment, and reporting.
  • Experience conducting regular audits, continuous monitoring, and risk assessments.
  • Ability to collaborate with government security officials, stakeholders, and teams.
  • Must currently possess and be able to maintain an active U.S. Top Secret security clearance.
  • Preferred: experience with Splunk, DISA STIGs, and SCC.
  • Preferred: ability to understand programming or scripting languages such as Python, PowerShell, or Bash.
  • Preferred: understanding of Linux Red Hat operating systems and SELinux policy.

Benefits

  • US salary range of $97,000 to $129,000.
  • Highly competitive equity grants included in the majority of full-time offers.
  • Top-tier benefits for full-time employees.
  • Comprehensive, competitive benefits package available at little to no cost to employees.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Security Engineer

Buildkite 51-250 Commercial Services & Supplies

Buildkite is hiring a Staff Security Engineer to shape and scale security across its platform, infrastructure, and developer workflows in a hands-on technical leadership role.

AWS CI/CD Go Kubernetes Penetration Testing Ruby Secrets Management Terraform
8 minutes ago

Director / Vice President, IT/OT (Global)

Submer 51-250 IT Services

Rubix is hiring a Director or VP of IT/OT to lead the convergence of information and operational technologies across its global AI data center portfolio and drive reliable, scalable, and secure infrastructure growth.

Cybersecurity
38 minutes ago

Microsoft 365 Security Engineer

qode Internet Software & Services

Microsoft is hiring a contract Microsoft 365 Security Engineer to implement enterprise data protection, device management, and access security solutions for a remote-first project.

53 minutes ago

Saviynt IAM Specialist

The Missing Link 51-250 Internet Software & Services

The Missing Link is seeking a Security Engineer - Saviynt to support large enterprise identity governance initiatives, design and deliver Saviynt-based solutions, and strengthen its growing cyber security practice.

Active Directory Azure Cybersecurity JavaScript PowerShell REST API SAP SQL
1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers