1,227,840open jobs
69,546companies
213,293added this week
Browse all
Salary
$150k – $185k per year
Location
In office (El Segundo)
Seniority
Senior · 5+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 4, 2026. First seen by Alion on Sep 30, 2026.

Overview
Company
Impact
Profile match

KBR

KBR is an engineering, science and technology company headquartered in Houston, Texas, delivering government services, defense and space mission support, process technology licensing and engineering for energy, chemicals and infrastructure projects. Listed on the New York Stock Exchange, it works across the United States, the United Kingdom, Australia and the Middle East, and in September 2025 announced the spin-off of its Mission Technology Solutions business into a separate public company. It hires process, piping, instrumentation, structural and HSE engineers, project and construction managers, logistics and commercial specialists, and finance, tax and IT staff.

Title:

Cyber System Security Engineer (CSSE)

Belong. Connect. Grow. with KBR!

KBR’s National Security Solutions team provides high-end engineering and advanced technology solutions to our customers in the intelligence and national security communities. In this position, your work will have a profound impact on the country’s most critical role - protecting our national security.

KBR is seeking a Cyber Security Engineer to join our team in El Segundo, CA. An active TS/SCI is required to be considered for this position.

Why Join Us?

Innovative Projects: KBR’s work is at the forefront of engineering, logistics, operations, science, program management, mission IT and cybersecurity solutions.

Collaborative Environment: Be part of a dynamic team that thrives on collaboration and innovation, fostering a supportive and intellectually stimulating workplace.

Impactful Work: Your contributions will be pivotal in designing and optimizing defense systems that ensure national security and shape the future of space defense.

We are seeking an experienced Space Systems, Cyber System Security Engineer (SSE) to support the integration of cybersecurity, systems security engineering, information assurance, program protection, and risk-management activities for defense-critical systems and information-network environments.

The SSE will ensure cybersecurity is engineered throughout the system life cycle from requirements definition, architecture, design, integration, and test through deployment, authorization, sustainment, modernization, and disposal. The SSE will support systems pursuing and maintaining an Authority to Operate (ATO) through the Risk Management Framework (RMF) process.

The SSE serves as a principal cybersecurity and RMF Subject Matter Expert (SME) to the program manager, chief engineer, Information System Security Manager (ISSM), Information System Security Officer (ISSO), system owner, Authorizing Official (AO), configuration-control authorities, and program leadership.

Key Responsibilities

Systems Security Engineering and RMF

- Apply systems security engineering principles across the system development life cycle in accordance with NIST SP 800-160 and applicable DoD acquisition and cybersecurity requirements.

- Translate mission, cybersecurity, privacy, program-protection, cryptographic, supply-chain, and compliance requirements into system specifications, architecture artifacts, interface-control requirements, verification criteria, and test procedures.

- Responsible for RMF activities, including system registration, categorization support, control selection and tailoring, control implementation, assessment support, authorization-package development, risk response, and continuous monitoring.

- Develop, maintain, and update authorization artifacts in eMASS or other approved governance, risk, and compliance tools, including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Security Control Traceability Matrices (SCTMs), Contingency Plans, Configuration Management Plans, and supporting evidence.

- Provide technical cybersecurity risk assessments and recommendations to the ISSM, AO, program manager, and chief engineer regarding control deficiencies, residual risk, authorization dependencies, and risk-treatment options.

- Participate in technical and program reviews, including requirements reviews, design reviews, test-readiness reviews, production-readiness reviews, and deployment decisions.

SOW, CDRL, and Acquisition Support

- Draft, review, and maintain cybersecurity and systems-security-engineering requirements for Statements of Work (SOWs), Performance Work Statements (PWSs), Statements of Objectives (SOOs), task orders, and acquisition documentation.

- Develop and manage Contract Data Requirements List (CDRL) requirements for cybersecurity deliverables, including RMF packages, vulnerability reports, STIG checklists, cybersecurity test reports, software and firmware inventories, supply-chain documentation, and incident reports.

- Ensure cybersecurity requirements are measurable, traceable, technically feasible, and aligned with program milestones, acceptance criteria, engineering baselines, and sustainment requirements.

- Review contractor cybersecurity deliverables for completeness, technical adequacy, compliance, traceability, and readiness for government acceptance.

- Support acquisition planning and source-selection activities by identifying cybersecurity risks, engineering dependencies, resource needs, and compliance requirements.

Program Protection, Supply-Chain Risk, and Cryptography

- Support Program Protection Plan development and execution, including identification and mitigation of threats to critical technologies, mission-critical functions, hardware, software, interfaces, and data.

- Coordinate cybersecurity engineering with program protection, anti-tamper, software assurance, hardware assurance, supply-chain risk management, configuration management, and mission-assurance activities.

- Identify attack surfaces, trust boundaries, critical assets, cybersecurity dependencies, and protective measures across system architectures and interfaces.

- Support approved cryptographic solutions, encryption implementations, Public Key Infrastructure (PKI), certificate lifecycle management, key-management requirements, secure communications, and cryptographic modernization activities.

- Coordinate with designated communications-security, cryptographic, engineering, cybersecurity, and program-protection personnel to document and manage cryptographic dependencies and associated risks.

- Support compliance with applicable CNSS, NSA, DoD, DAF, and program requirements governing cryptographic products, services, key management, and secure communications.

Continuous Monitoring, Vulnerability Management, and STIG Compliance

- Conduct and oversee continuous-monitoring activities, vulnerability assessments, configuration assessments, security scans, compliance validation, and remediation tracking.

- Use DISA STIGs, SRGs, SCAP Compliance Checker (SCC), ACAS/Nessus, endpoint-security tools, and manual validation procedures to assess system compliance.

- Analyze Windows, Linux, network devices, applications, databases, cloud services, and enterprise infrastructure against approved security baselines.

- Develop, document, coordinate, and validate remediation actions, compensating controls, mitigations, exceptions, and risk decisions for vulnerabilities and non-compliant security controls.

- Create, maintain, and report Plans of Action and Milestones (POA&Ms), including risk ratings, milestones, accountable owners, remediation evidence, dependencies, and closure documentation.

- Maintain continuous-monitoring plans, scan schedules, security metrics, compliance dashboards, and recurring cybersecurity status reports.

Configuration Management, Audit, and Incident Support

- Serve as the cybersecurity and systems-security-engineering representative on the Configuration Control Board (CCB) and other engineering governance forums.

- Assess proposed hardware, software, firmware, network, interface, and operational changes for cybersecurity, RMF, STIG, cryptographic, supply-chain, and program-protection impacts before deployment.

- Ensure approved changes are tested, documented, authorized as required, and reflected in system baselines, inventories, configuration-management records, and authorization artifacts.

- Review audit logs, cybersecurity dashboards, and Security Information and Event Management (SIEM) reports, including Splunk reports where applicable, for unauthorized activity, anomalous behavior, and indicators of compromise.

- Support cybersecurity incident identification, triage, containment, reporting, remediation, evidence preservation, and lessons-learned activities in accordance with applicable DoD and organizational procedures.

IT Governance, eMASS, ITIPS, and FISMA Reporting

- Demonstrate hands-on proficiency using **eMASS** to create, maintain, update, route, and track RMF authorization packages, control implementation statements, assessment evidence, POA&Ms, and continuous-monitoring artifacts.

- Demonstrate working knowledge of **Information Technology Investment Portfolio Suite (ITIPS)**, the Department of the Air Force’s central database repository for tracking IT compliance and budgeting information.

- Maintain accurate ITIPS records supporting IT investment management, IT compliance, budgeting, system inventories, and applicable FISMA reporting requirements.

- Reconcile cybersecurity, authorization, inventory, budget, engineering, and compliance data among eMASS, ITIPS, program-management artifacts, CDRLs, configuration-management records, and other authoritative repositories.

- Apply working knowledge of the **Clinger-Cohen Act**, FISMA, and associated DAF and DoD IT governance, portfolio-management, cybersecurity, and reporting processes. DAF reporting has used DITPR-related processes to capture compliance and investment information.

Physical and Classified-System Security

- Support applicable physical, environmental, access-control, media-protection, personnel-security, and system-security requirements.

- Support security-control implementation for sensitive or classified environments, including secure facilities, controlled areas, removable media, system interconnections, and Cross Domain Solutions (CDS), when applicable.

- Ensure account management, privileged access, audit logging, media handling, and operational security procedures remain aligned with approved system-security documentation.

Required Qualifications

Must have 5-10+ years of experience.

- Active U.S. Government **Secret** security clearance required.

- Top Secret eligibility or active Top Secret/Sensitive Compartmented Information eligibility preferred, based on program requirements.

DoD 8140 Compliance

- The candidate **must meet and maintain applicable DoD 8140 qualification requirements** for the assigned DCWF work role(s), workforce element, and proficiency level.

- The candidate must maintain required foundational qualification, training, certification, education, and continuing professional development requirements applicable to the formally assigned role.

- Relevant certifications may include CISSP, CISM, CGRC/CAP, Security+ CE, or other credentials recognized for the assigned work role; however, the specific qualification path must align with the position’s designated DCWF role and proficiency level.

Compliance and Regulatory Framework:

DoDI 8500.01; DoDI 8510.01; DoD 8140 and applicable DoD Cyber Workforce Framework (DCWF) qualification requirements; NIST SP 800-37; NIST SP 800-53; NIST SP 800-160, Volume 1; DoDI 5000.83; DoDI 5000.90; DoDI 8531.01; DISA Security Requirements Guides (SRGs) and Security Technical Implementation Guides (STIGs); Federal Information Security Modernization Act (FISMA); Clinger-Cohen Act; applicable Committee on National Security Systems (CNSS), National Security Agency (NSA), Department of Defense (DoD), Department of the Air Force (DAF), and program-specific requirements.

Education and Experience

- Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, Systems Engineering, Electrical Engineering, or a related discipline; additional directly relevant DoD cybersecurity, systems-engineering, or information-assurance experience may substitute for degree requirements.

- At least 5 years of direct experience implementing RMF in accordance with DoDI 8510.01, NIST SP 800-37, NIST SP 800-53, and applicable DoD authorization processes.

- Experience integrating cybersecurity requirements into system engineering, architecture, design, software development, integration, test, acquisition, configuration management, or sustainment activities.

- Experience developing cybersecurity documentation, engineering analysis, SOW/PWS language, CDRLs, test requirements, security plans, assessment artifacts, and executive-level risk briefings.

- Experience with vulnerability management, POA&M development, risk analysis, remediation planning, and compliance reporting.

- Experience analyzing and securing Windows, Linux, network infrastructure, applications, databases, cloud services, or hybrid enterprise environments.

Required Tools and Technical Knowledge

- eMASS experience required.

- Experience with ACAS/Nessus, SCC, DISA STIGs, SRGs, and vulnerability-management processes.

- Familiarity with Splunk or comparable SIEM platforms, audit-log review, and incident-support processes.

- Working knowledge of FISMA, Clinger-Cohen Act requirements, RMF, DoD cybersecurity governance, and DAF IT investment and portfolio-management processes.

- Working knowledge of secure architecture, encryption, PKI, certificate management, access control, logging, boundary protection, secure configuration, and security testing.

Preferred Qualifications

- Experience supporting DAF, DoD, Intelligence Community, or other federal cybersecurity and systems-engineering programs.

- Experience with Program Protection Plans, supply-chain risk management, anti-tamper, software assurance, hardware assurance, or critical-technology protection.

- Experience with CMMC, FedRAMP, cloud-security authorization, Zero Trust implementation, DevSecOps, or container-security environments.

- Familiarity with SCIF security operations, NISPOM requirements, ICD 503, Cross Domain Solutions, and classified-system authorization processes.

- Experience participating in integrated product teams, engineering technical reviews, CCBs, cybersecurity working groups, or contractor performance reviews.

- Strong technical writing and briefing skills, including the ability to communicate cybersecurity posture, engineering risk, compliance status, remediation priorities, and authorization recommendations to senior leaders.

Scheduled Weekly Hours: 40

Basic Compensation: $150 -185k

The offered rate will be based on the selected candidate’s knowledge, skills, abilities and/or experience and in consideration of internal parity.

Additional Compensation:

KBR may offer bonuses, commissions, or other forms of compensation to certain job titles or levels, per internal policy or contractual designation. Additional compensation may be in the form of sign on bonus, relocation benefits, short term incentives, long term incentives, or discretionary payments for exceptional performance.

KBR offers a selection of competitive lifestyle benefits which could include 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development.

Ready to Make a Difference?

If you’re excited about making a significant impact in the field of space defense and working on projects that matter, we encourage you to apply and join our team at KBR. Let's shape the future together.

Belong, Connect and Grow at KBR

At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver - Together.

KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,227,840 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

DevOps
Similar stack
Same company
El Segundo
≈ $117k – $214k per year (Estimated) • Remote (United States) • Full-Time
Python
Bash
AI/ML
AI Agents
Machine Learning
DevOps
Terraform
CloudFormation
Prometheus
CI/CD
Jenkins
AWS
Docker
Kubernetes
Grafana
Bitbucket
AWS Lambda
Amazon EC2
Amazon S3
IAM
Amazon ECS
Amazon CloudWatch
Linux
Cybersecurity
SOC 2
Management
Agile
Apply
$96k – $178k per year • In office • TS/SCI • King of Prussia
Python
Management
Agile
Scrum
Apply
≈ $103k – $201k per year (Estimated) • Hybrid • 7+ years exp • Bachelor's Degree • Memphis
Python
AI/ML
Ray
Apply
$145k – $230k per year • Equity • Hybrid • 7+ years exp • Bachelor's Degree • Palo Alto
Python
AI/ML
Ray
Apply
≈ $125k – $243k per year (Estimated) • Hybrid • 7+ years exp • Bachelor's Degree • Bastrop
Python
AI/ML
Ray
Apply
$17k per year (net) • In office • Saint Petersburg
DevOps
Linux
Windows
TCP/IP
DNS
DHCP
Cybersecurity
Active Directory
Apply
$17k per year (net) • In office • Kazan
DevOps
Linux
Windows
TCP/IP
DNS
DHCP
Cybersecurity
Active Directory
Apply
≈ $19k – $38k per year (Estimated) • In office • 3+ years exp • Bachelor's Degree • Moscow
JavaScript
Java
TypeScript
Frontend
Angular
DevOps
Rest API
Linux
SOAP
Analytics
ETL/ELT
DataStage
Apply
≈ $61k – $159k per year (Estimated) • In office • Full-Time • 7+ years exp • Cairo
Python
Assembly
Databases
Oracle
AI/ML
InfiniBand
DevOps
Rest API
Terraform
Incident Management
IAM
Linux
Cybersecurity
CIS Benchmarks
Cryptography
Vault
Management
ITIL
Apply
Стажер DevOps 3 days ago
In office • Internship • Tolyatti
Python
SQL
DevOps
Ansible
GitLab CI
CI/CD
Docker
Linux
Astra Linux
TCP/IP
DNS
Apply
$130k – $170k per year • In office • Top Secret • Full-Time • 10+ years exp • Bachelor's Degree • Palmdale • Chandler • Aberdeen
Bash
DevOps
Ansible
Red Hat
OpenShift
Podman
VMWare
Windows Server
Docker
Kubernetes
Configuration Management
CentOS Stream
Linux
Windows
DNS
Cybersecurity
Nessus
Active Directory
PKI
Apply
Cloud Engineer 6 days ago
$94k – $141k per year • In office • TS/SCI • Full-Time • 2+ years exp • Bachelor's Degree • Colorado Springs
DevOps
Terraform
Azure
AWS
Kubernetes
Bicep
Azure AKS
GitHub
GitLab
Linux
Cybersecurity
Microsoft Entra ID
Management
Agile
Apply
≈ $58k – $149k per year (Estimated) • Equity • In office • Full-Time • Canberra
Apply
≈ $49k – $121k per year (Estimated) • Equity • In office • Full-Time • Melbourne
Management
Microsoft Office
Apply
≈ $102k – $238k per year (Estimated) • In office • Full-Time • Adelaide
Apply
$99k – $133k per year • In office • Secret • Full-Time • 5+ years exp • Bachelor's Degree • El Segundo
Python
Perl
Apply
$120k – $162k per year • In office • TS/SCI • Full-Time • 14+ years exp • Bachelor's Degree • El Segundo
Management
Agile
Apply
$146k per year • Hybrid • 15+ years exp • El Segundo
Apply
$114k – $171k per year • In office • TS/SCI • Full-Time • 5+ years exp • Bachelor's Degree • San Diego • Palmdale • El Segundo
Apply
$79k – $119k per year • In office • TS/SCI • Full-Time • 6+ years exp • Bachelor's Degree • San Diego • Palmdale • El Segundo
Management
Confluence
Power Automate
SharePoint
Agile
Apply
See all jobs
This is one of many
1,227,840 more open roles from verified company boards, updated every day.