AppSec Jobs
← Back to all jobs

L3Harris Technologies

Specialist, Information Security Systems Engineer (ISSE)

Onsite
Palm Bay, FLPosted 2 weeks agoWebsite
Apply on LinkedIn →

At a Glance

CI/CDNISTDevSecOpsCISSPCS/Security DegreeTS/SCI

About This Role

L3Harris is looking for an experienced Information Security Systems Engineer (ISSE) to join the Engineering team in Palm Bay, FL supporting the design, implementation, and sustainment of secure information systems across enterprise and program environments. This role is responsible for applying cybersecurity engineering principles throughout the system lifecycle, helping ensure systems meet security, compliance, and mission requirements. The ideal candidate will be able to prepare and manage the Assessment & Authorization documentation using NIST Risk Management Framework (RMF) to achieve system Authorization to Operate (ATO).

Responsibilities

  • Prepare and manage Assessment and Authorization documentation using RMF and derivative processes (e.g., DOD 8510, JSIG, ICD-503, CNSSI 1253) to achieve security authorization of supported systems.
  • Support the design, integration, and maintenance of secure system architectures for on-premises environments.
  • Apply cybersecurity principles and security-by-design practices throughout the system development lifecycle.
  • Analyze system requirements and derive security requirements, controls, and technical solutions.
  • Perform security assessments, gap analyses, and risk evaluations for information systems and supporting infrastructure.
  • Perform research required to identify vulnerability details and solutions to assist other cyber disciplines with their correction or mitigation.
  • Support implementation and validation of security controls in alignment with applicable regulatory, contractual, and organizational requirements.
  • Participate in Linux & Windows system hardening, secure configuration, patch management, and vulnerability remediation activities.
  • Contribute to development of policies, standards, procedures, and technical documentation related to information security engineering.
  • Support audits, inspections, and customer assessments by providing technical evidence and responses.
  • Communicate technical risks, findings, and recommendations to both technical and non-technical stakeholders.

Requirements

CISSPDevSecOpsCI/CD
  • Bachelor's Degree and minimum 4 years of prior relevant experience. Graduate Degree and a minimum of 2 years of prior related experience. In lieu of a degree, minimum of 8 years of prior related experience.
  • Active clearance: TS/SCI w/CI Poly.
  • Must have or be able to obtain and maintain IAT Level II minimum (Security+ CE, CCNA Security, or equivalent) within 3-months of start.
  • Familiarity with emerging technologies such as cloud computing, containerization, and microservices, and their security implications (e.g. Understanding of security control inheritance in cloud-based systems.)
  • Familiarity with STIG/SRG compliance validation and automated compliance scanning tools.
  • Experience with security tools such as IDS/IPS, vulnerability scanners, and endpoint protection solutions.
  • Professional certifications such as Security+, CISSP, or similar.
  • Familiarity with DevSecOps practices, CI/CD pipeline security, and infrastructure as code security principles.
  • Experience in regulated environments such as defense, aerospace, government contracting, or critical infrastructure.

About L3Harris Technologies

L3Harris Technologies, Inc. is an American technology company and defense contractor based in Melbourne, Florida. Formed in 2019 from the merger of L3 Technologies and Harris Corporation, it has a rich history of innovation dating back over a century. The company is recognized as the sixth-largest U.S. defense contractor, focusing on aerospace and defense solutions. In fiscal year 2023, L3Harris reported $19.4 billion in revenue. L3Harris provides a wide range of solutions for mission-critical needs across government, defense, and commercial sectors. Their offerings include command, control, communications, intelligence, surveillance, and reconnaissance (C4ISR) systems, avionics, electronic systems, and specialized defense technologies. The company emphasizes tailored solutions and agile technology to address complex challenges, ensuring operational efficiency and high standards of integrity and excellence. L3Harris serves a global customer base, with a strong focus on U.S. government and defense clients.

Industry

defense & space

Employees

47,000

10206 engineers

Revenue

$21B

Website

Visit →

Security at L3Harris Technologies

Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.

3 Intel Signals

Security Philosophy

L3Harris's AppSec philosophy is centered on addressing current cyber threats through its cybersecurity expertise. It emphasizes a Secure Development Lifecycle (SDL) and a Defense-in-Depth security strategy. Key pain points or goals include the use of Static Application Security Testing (SAST), Software Composition Analysis (SCA), and Dynamic Application Security Testing (DAST. However, explicit statements about a 'developer-first' or 'security sign-off' posture, security champions, or AppSec mission statements beyond generic cyber capability pages are not publicly available.

Security Team

L3Harris's AppSec team structure and reporting lines are not fully public, though the enterprise cybersecurity organization is led by Michael Higgins, Vice President and Chief Information Security Officer, who is responsible for enterprise-wide cybersecurity. Allen Westley is also identified as a Director Cybersecurity. No explicit AppSec job postings were found, and team size estimates are not publicly available. Common skill patterns observed in public materials include SAST, SCA, and DAST.

Key Initiatives

L3Harris implements a Secure Development Lifecycle (SDL) as part of its 'shift left' practices, which includes SAST, SCA, and DAST. Vulnerability management involves 'vulnerability and exploit research'. However, details on a security champions program, explicit SLAs for vulnerability triage/remediation, annual penetration testing, or threat modeling statements are not publicly available. Recent initiatives include achieving NSA Cybersecurity Directorate certification for its KSV-650, which is a product certification rather than an AppSec team-specific program rollout.

Preparing for an AppSec interview?

Get the weekly briefing 2,000+ security pros trust.

Interested in this role?

Apply on LinkedIn