Information System Security Engineer
Job description
About the role
You will architect and oversee the implementation of a zero-trust security framework that spans our hybrid cloud and on-premises infrastructure, ensuring alignment with our rigorous aerospace mission assurance requirements. You will lead the design of network security controls and identity management solutions that protect critical engineering data and intellectual property across distributed development environments. In this capacity, you will own the end-to-end security lifecycle for key systems, from initial design reviews and threat modeling through deployment, monitoring, and continuous improvement initiatives. You will establish and drive the adoption of security best practices, standards, and procedures across engineering and operations teams to reduce risk and improve resilience. You will mentor and elevate the capabilities of junior security and IT staff through hands-on guidance, code reviews, and collaborative problem-solving sessions. You will partner with external vendors and integration partners to ensure that third-party solutions meet our stringent security, reliability, and compliance expectations. You will translate complex technical risks into clear executive-level reporting, enabling informed decisions on security investments and trade-offs without compromising operational tempo. You will champion a culture of security excellence by integrating security thinking into every phase of the software development lifecycle and infrastructure deployment.
Key facts
What you'll do
Define and enforce enterprise security architecture standards, ensuring that infrastructure, applications, and data assets are designed and operated in accordance with defense-in-depth principles.
Perform threat modeling, risk assessments, and security gap analyses for new programs and legacy systems, prioritizing remediation efforts based on impact to mission and data integrity.
Lead the implementation and hardening of identity and access management controls, including multi-factor authentication, privileged access management, and role-based access policies.
Design and configure secure network segments, firewall rules, and monitoring capabilities to protect critical engineering tools, research data, and manufacturing environments.
Develop and maintain security policies, procedures, and playbooks that align with industry frameworks and regulatory requirements relevant to aerospace and defense operations.
Coordinate with system administrators, network engineers, and application developers to integrate security controls into day-to-day operations and incident response processes.
Implement and tune security monitoring solutions, analyze alerts, and lead investigations of suspicious activity to detect and respond to potential threats quickly.
Collaborate with procurement and vendor management teams to evaluate the security posture of new tools and services before they are introduced into the environment.
Drive the execution of security testing activities, including vulnerability scans, configuration reviews, and penetration test coordination, to validate the effectiveness of controls.
Serve as the technical liaison for cybersecurity audits, assessments, and regulatory engagements, ensuring that evidence and documentation are current and accurate.
Promote security awareness and training across the organization, translating complex topics into practical guidance for engineers and non-technical staff.
Track emerging threats, vulnerabilities, and industry trends, and recommend improvements to security tools, processes, and architectures as needed.
Support the development and execution of disaster recovery and business continuity plans, validating recovery objectives and testing procedures on a regular basis.
Champion the adoption of secure DevOps practices, integrating security checks and controls into CI/CD pipelines without impeding development velocity.
Requirements
Demonstrate a strong foundational knowledge of information security principles, technologies, and best practices, with a proven ability to apply them in complex, mission-critical environments.
Possess a solid understanding of network security concepts, including firewalls, intrusion detection and prevention systems, virtual private networks, and secure routing and switching fundamentals.
Have hands-on experience with identity and access management technologies, including directory services, single sign-on, multi-factor authentication, and privileged access management solutions.
Showcase experience with security monitoring tools, log analysis platforms, and security information and event management techniques to detect and respond to incidents effectively.
Exhibit familiarity with major security frameworks and standards, such as NIST, ISO 27001, and relevant defense or aerospace compliance requirements.
Bring a strong understanding of vulnerability management processes, including scanning, assessment, prioritization, and remediation tracking across diverse systems.
Possess excellent problem-solving skills and the ability to analyze complex situations, make sound technical decisions, and communicate recommendations to both technical and executive audiences.
Demonstrate the ability to work independently and collaboratively in a fast-paced, dynamic environment, managing multiple priorities while maintaining attention to detail and accuracy.
Nice to have
Experience with cloud security platforms and infrastructure-as-security practices on major public cloud providers.
Familiarity with DevSecOps tools and pipelines, including infrastructure-as-code security, container scanning, and automated compliance validation.
Knowledge of aerospace, defense, or regulated industry security requirements and mission assurance practices.
Experience with security orchestration, automation, and response platforms to streamline incident response operations.
Background in mentoring or leading technical teams, with a demonstrated ability to develop others and foster a collaborative security culture.
Practical notes
This is a full-time, exempt position based in Houston, Texas. The role may require occasional travel to support program reviews, vendor assessments, or audit activities as needed. Employment eligibility to work in the United States is required, and candidates must pass applicable background checks as part of the hiring process.