Sr Systems Security Engineer
Sierra Nevada Corporation · Lone Tree, CO, United States
About The Role
The ISR (Intelligence, Surveillance & Reconnaissance), Aviation, and Security (IAS) business area is a leader in ISR and aviation, it is a leading prime manned and unmanned aircraft systems integrator for innovative, high-performance ISR and aviation systems. Its end-to-end Command, Control, Computers, Communications and Intelligence, Surveillance & Reconnaissance (C4ISR) capabilities encompass design, integration, test, certification, ground/flight training and complete logistics support. IAS tailors solutions to customer cost, performance, and schedule requirements and designs to consistently exceed expectations – with an unrivaled record of on time and on (or under) budget deliveries.
SNC has led thoughtful and disruptive change in the aerospace and defense industry for the past 60 years and now, we’re applying this tenacity and expertise to the U.S. Air Force’s (USAF) Survivable Airborne Operations Center (SAOC) mission. Join the SNC-led SAOC team and be a part of exciting and meaningful work to modernize and deliver the next-generation SAOC aircraft trusted by the President, Secretary of Defense and Chairs of the Joint Chiefs of Staff to ensure continued critical command, control and communication during national emergencies. If you’re passionate about building the airborne command post of the future, consider SNC for your next mission. Learn more about NC3 and SAOC here .
If you like solving complex IT and security problems using your deep analytical skills, this is the opportunity for you! As a Senior Systems Security Engineer, you will lead the design and implementation of our security infrastructure. You will manage complex security projects, provide strategic direction for security practices, and mentor junior engineers.
Responsibilities
DevSecOps & Enterprise Platform Administration
- CI/CD & Repositories: Govern GitHub/GitLab instances, configure runner infrastructure, and administer JFrog Artifactory repositories.
- Supply Chain Security: Integrate vulnerability scanning (Xray/SAST), secret detection, and compliance frameworks into delivery pipelines.
- High Availability: Maintain PostgreSQL backends, backup/restore workflows, and data replication across connected and air-gapped networks.
- Any Engineering Toolsets Experience: Administering Dassault 3DEXPERIENCE (3DX), Cameo Teamwork Cloud, and Jama Connect platforms organizations and projects, including concurrent license servers (FlexLM) and cross-tool API integrations.
Full-Stack Application & Frontend/Backend Delivery
- Lifecycle Management: Install, configure, upgrade, and retire critical DevOps and engineering platforms.
- Backend Administration: Tune and optimize Java EE application servers (Tomcat, WildFly/JBoss) including heap and connection pools.
- Frontend & Web Services: Configure Nginx and Apache HTTPD web servers, reverse proxies, load balancers, and SSL/TLS certificates.
- Performance Monitoring: Proactively track application health, analyze logs, and resolve performance bottlenecks.
RHEL / Linux Systems Engineering
- OS Administration: Provision, patch, and manage Red Hat Enterprise Linux (RHEL) systems using systemd, YUM/DNF, and shell scripting (Bash).
- Security & Hardening: Implement DISA STIG compliance, manage firewalls and SELinux, and provide artifacts for RMF/ATO packages.
- Infrastructure Optimization: Tune Linux kernel parameters, network stacks, storage mounts, and centralized identity management (LDAP/AD/SSSD).
Qualifications You Must Have
- Bachelor's degree in Systems Security, Network Engineering, Information Technology, or related Engineering discipline.
- 8+ years of experience in IT security or a related field.
- Relevant experience can be considered as a substitute for the required educational qualifications. In the absence of a degree, a minimum of 12 years of related experience is required.
- Higher level relevant degree may substitute for experience.
- Expert understanding of cybersecurity principles and practices.
- Experience with security frameworks and standards such as National Institute of Standards and Technology (NIST), ISO 27001.
- 5+ years of hands-on application administration experience in Linux/RHEL environments — including application installation, configuration, patching, and performance tuning in a production or program-of-record context.
- Demonstrated production experience administering GitLab and/or GitHub at an organizational or enterprise scale — including user/group management, CI/CD runner administration, access control governance, and platform upgrades.
- Demonstrated production experience administering JFrog Artifactory — including repository configuration, permission management, artifact lifecycle policies, and CI/CD pipeline integration.
- Hands-on experience administering at least two of the following engineering applications in a production or program environment: 3DEXPERIENCE (3DX), Cameo Systems Modeler / Teamwork Cloud, Jama Connect, or Siemens Teamcenter.
- Proficient Linux/RHEL system administration skills — RPM/YUM/DNF package management, system service management, user and group administration, shell scripting (Bash), and file system management.
- Experience troubleshooting complex multi-application integration failures — API connectivity, authentication chain issues, data synchronization failures, and middleware configuration problems.
- Working knowledge of SSL/TLS certificate management, network firewall rules, and application-layer security configuration in a Linux environment.
- Current/Active Top Secret U.S. Security Clearance is required.
Qualifications We Prefer
- Relevant certifications: Red Hat Certified System Administrator (RHCSA), Red Hat Certified Engineer (RHCE), GitLab Certified
- Associate, JFrog Certified Professional, or equivalent.
- Experience administering all four engineering applications — 3DEXPERIENCE (3DX), Cameo Systems Modeler/Teamwork
- Cloud, Jama Connect, and Siemens Teamcenter — simultaneously within a single program environment.
- Experience administering engineering applications in a classified or air-gapped environment — including managing software
- distribution, license servers, and integration connectivity across network boundaries.
- DISA STIG application experience for Linux (RHEL STIG) and application platforms — including finding categorization (CAT I/II/III), remediation, false positive documentation, and ATO package contribution.
- Experience with containerization and orchestration platforms (Docker, Kubernetes, OpenShift) for engineering application deployment and management.
- Experience with JFrog Xray for software composition analysis (SCA), vulnerability scanning, and license compliance enforcement integrated into CI/CD pipelines.
- Familiarity with Dassault Systemes 3DX platform architecture — ENOVIA, CATIA V6, VPM, 3DSpace, 3DDashboard — andmulti-tenant or multi-server 3DX deployment configurations.
- Experience administering Cameo Teamwork Cloud at scale — multi-server deployments, cluster configuration, model branching governance, and large-scale TWC migration projects.
- Experience with Identity and Access Management (IAM) integration — LDAP, Active Directory, Kerberos, SAML/SSO configuration for engineering application authentication.
- Scripting proficiency in Python or Ansible for application administration automation — configuration management, health check automation, and deployment scripting.
Essential Functions
- Ability to work primarily at a computer for extended periods.
- Capability to participate in on-call rotation for incident response.
- Must be able to lift up to 25 lbs occasionally.
- Ability to work in an office environment.
- Occasional travel may be required.
This posting will be open for application for a minimum of 5 days and may be extended based on business needs.
Estimated Starting Salary Range: $143,487.14 - $197,294.82. Compensation varies depending on a wide array of factors, such as candidates' key skills, relevant work experience, and education/training/certifications. The disclosed range estimate may be adjusted for any applicable geographic differential associated with the location at which the position may be filled.
SNC offers annual incentive pay based upon performance that is commensurate with the level of the position.
SNC offers a generous benefit package, including medical, dental, and vision plans, 401(k) with 150% match up to 6%, life insurance, 3 weeks paid time off, tuition reimbursement, and more .
IMPORTANT NOTICE
This position requires current/active Top Secret with SCI eligibility U.S. Security Clearance. U.S. Citizenship status is required as this position needs an active U.S. Security Clearance for employment. Non-U.S. Citizens may not be eligible to obtain a security clearance. The Department of Defense Consolidated Adjudications Facility (DoD CAF), a federal government agency, handles the adjudicative aspects of the security clearance eligibility process for industry applicants. Adjudicative factors which affect the outcome of the eligibility determination include, but are not limited to, allegiance to the U.S., foreign influence, foreign preference, criminal conduct, security violations and illegal drug use. Learn more about the background check process for Security Clearances.
SNC is a global leader in aerospace and national security committed to moving the American Dream forward. We’re known and respected for our mission and execution focus, agility, and disruptive and rapid innovation. We provide leading edge technologies and transformative solutions that support our nation’s most critical security needs. If you are mission-focused, thrive in collaborative environments, and want to make our country stronger with state-of-the-art technologies that safeguard freedom, join our team!
SNC is an Equal Opportunity Employer committed to an environment free of discrimination. Employment decisions are made based on merit without regard to race, color, age, religion, sex, national origin, disability, status as a protected veteran or other characteristics protected by law.
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
