1,117,799open jobs
64,450companies
190,648added this week
Browse all
Salary
≈ $121k – $257k per year (Estimated)
Location
In office (Greenville)
Seniority
Staff · 13+ years exp

Confirmed on the employer's own hiring board on Oct 3, 2026. First seen by Alion on Sep 24, 2026.

Overview
Company
Impact
Profile match
L3Harris builds defence electronics, uncrewed maritime vessels and space systems. Its unmanned surface vehicles run long autonomous naval missions. The company is one of the largest United States defence contractors.

Job Title: Lead, Information Security Systems Engineer

Job Code: 44627

Job Location: Greenville, TX

Schedule: 9/80 - Employees work 9 out of every 14 days - totaling 80 hours worked - and have every other Friday off

Job Description:

The Lead Incident Response and Security Operations Engineer establish, operates, and continuously improves the Enterprise Product and Services’ incident response and security operations capability across a government-owned, contractor-operated hybrid environment that includes Amazon Web Services (AWS), multiple data centers, and a corporate location.

The role leads monitoring, investigation, detection engineering, incident coordination, and risk escalation to strengthen the availability, integrity, and confidentiality of GSS services.

Infrastructure, system, and application owners retain responsibility for technical remediation, patching, and platform repair.

Essential Functions:

  • 15% travel based on business needs (CONUS or OCONUS).
  • Ability to work a flexible schedule includes off-shift work, weekends, occasional overtime, and on-call duties.
  • Establish and maintain security information and event management operations, including Wazuh health, log ingestion, data-quality validation, alert rules, dashboards, and detection tuning.
  • Monitor, triage, investigate, document, and coordinate response to security events across AWS, datacenter, network, endpoint, and corporate environments.
  • Create and manage security-incident tickets; preserve investigation evidence; document findings and actions; and validate closure with responsible technical owners.
  • Develop and maintain incident-response plans, escalation paths, severity criteria, playbooks, runbooks, and after-action reports.
  • Coordinate remediation tracking for vulnerabilities, security findings, and incident corrective actions, escalating overdue or material risk.
  • Conduct AWS security-alert and exposure reviews, including identity and access management, privileged access, logging, and cloud-security findings within assigned authority.
  • Onboard and maintain log sources and integrations needed to support monitoring, detection, incident investigation, and compliance evidence.
  • Conduct periodic reviews of privileged access, security-tool access, and operational logging coverage; support disaster-recovery and incident-response exercises.
  • Produce security-operations metrics, risk reports, and stakeholder briefings, and maintain documentation supporting the Risk Management Framework, audit readiness, and continuous monitoring.

Qualifications:

  • Active US Secret security clearance or higher.
  • Bachelor’s Degree and minimum 9 years of prior relevant experience.
  • Graduate Degree and a minimum of 7 years of prior related experience.
  • In lieu of a degree, a minimum of 13 years of prior related experience.
  • Current in at least one of the following; Certified Information Security Manager, Certified Information Systems Auditor, Certified Cloud Security Professional, Certificate of Cloud Security Knowledge, or comparable Department of Defense 8140 certification.
  • Minimum 8 years of security operations, incident response, or security engineering experience.
  • Demonstrated experience operating or engineering a security information and event management platform, developing detection rules, validating log ingestion, and tuning alerts.
  • Demonstrated experience with incident triage, investigation, evidence handling, ticket management, stakeholder communications, and closure documentation.
  • Demonstrated experience supporting hybrid-cloud environments, including AWS and on-premises data-center infrastructure.

Preferred Additional Skills

  • Knowledge of Windows, Linux, networking, identity and access management, security logging, and vulnerability-management processes.
  • Experience with SIEM, Logging and Monitoring infrastructure design, operation management
  • Splunk, Wazuh, SysAid, AWS security services, or comparable security information and event management, information technology service management, and cloud-security platforms.
  • Experience with MITRE ATT&CK, detection engineering, threat hunting, and alert use-case development.
  • Experience developing or maintaining incident-response and disaster-recovery plans, playbooks, tabletop exercises, or technical exercises.
  • Experience with plans of action and milestones, audit evidence, security assessments, and government compliance environments.
  • CISSP, CISM, CCSP, GCIH, GCIA, CySA+, Security+, AWS Certified Security - Specialty, or comparable certification.
  • Experience supporting government-owned, contractor-operated systems and multi-site operations.
  • Experience with Risk Management Framework assessment and authorization activities, National Institute of Standards and Technology Special Publication 800-53 controls, or Platform Information Technology environments.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,117,799 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
Greenville
$173k – $314k per year • In office • Public Trust • Full-Time • 7+ years exp • PhD • San Francisco
AI/ML
AI Agents
LLM
Agentforce
Cybersecurity
NIST CSF
SOC 2
FedRAMP
Apply
≈ $110k – $234k per year (Estimated) • In office • 5+ years exp • Plano
AI/ML
Machine Learning
Cybersecurity
Threat Modeling
Management
Agile
Apply
≈ $117k – $247k per year (Estimated) • In office • 10+ years exp • Jersey City
Apply
$146k – $198k per year • Remote (United States) • Full-Time • 10+ years exp • Bachelor's Degree • Minneapolis
Cybersecurity
PCI DSS
HIPAA
Management
ServiceNow
Apply
≈ $152k – $316k per year (Estimated) • In office • TS/SCI • 10+ years exp • Bachelor's Degree • Saint Louis
Cybersecurity
SIEM
Apply
API Engineer 1 day ago
≈ $92k – $185k per year (Estimated) • Equity • In office • 1+ year exp • Bachelor's Degree • Boulder
Python
Rust
R
R
Shiny
AI/ML
Structured Outputs
DevOps
Rest API
Terraform
GitHub Actions
CloudFormation
CI/CD
Git
AWS
Docker
Linux
Apply
≈ $112k – $221k per year (Estimated) • Equity • In office • Public Trust • 5+ years exp • Bachelor's Degree • United States
DevOps
Azure
AWS
Linux
Windows
Cybersecurity
Nessus
CIS Benchmarks
SIEM
Apply
$120k – $170k per year • In office • Bachelor's Degree • United States
DevOps
Terraform
Ansible
GCP
GitLab CI
Azure
CI/CD
Git
AWS
Cloudflare
DNS
VPN
BGP
Apply
≈ $105k – $192k per year (Estimated) • Remote (United States) • Full-Time • United States
TypeScript
SQL
C#
C#
.NET
AI/ML
Cursor
Claude Code
AI Agents
DevOps
CI/CD
AWS
Windows
Cybersecurity
Okta
Apply
≈ $77k – $145k per year (Estimated) • Equity • In office • 3+ years exp • Bachelor's Degree • Tuscaloosa
Python
Rust
AI/ML
NumPy
DevOps
Terraform
AWS CDK
CI/CD
AWS
Docker
Amazon EC2
Amazon S3
HPC
SpaceTech
GDAL
Apply
≈ $76k – $212k per year (Estimated) • In office • Internship • Bachelor's Degree • Salt Lake City
Java
SQL
Ruby
C#
C++
C#
.NET
C++
Qt
AI/ML
Hadoop
DevOps
RTOS
Linux
Windows
Unix
Apply
$125k – $232k per year • In office • TS/SCI • 13+ years exp • Clifton
Cybersecurity
NIST 800-53
Apply
≈ $105k – $207k per year (Estimated) • In office • 8+ years exp • Bachelor's Degree • Melbourne
Python
PowerShell
DevOps
Rest API
Terraform
CloudFormation
CI/CD
Jenkins
Git
AWS
Docker
Kubernetes
Amazon EKS
AWS Fargate
AWS Lambda
GitHub
GitLab
IAM
Amazon ECS
Cybersecurity
ISO 27001
SOC 2
GDPR
NIST 800-53
FedRAMP
Zero Trust
Threat Modeling
Management
Agile
Apply
$96k – $178k per year • In office • Secret • 10+ years exp • Anaheim
DevOps
Red Hat
Linux
Windows
VPN
Apply
≈ $79k – $219k per year (Estimated) • In office • Internship • Bachelor's Degree • Melbourne
DevOps
Rest API
CI/CD
Git
Docker
Cybersecurity
SIEM
Apply
$40k – $54k per year • In office • Part-Time • High School Diploma • Greenville
Apply
≈ $111k – $225k per year (Estimated) • In office • Top Secret • 9+ years exp • Bachelor's Degree • Greenville
Apply
≈ $39k – $68k per year (Estimated) • In office • Full-Time • 1+ year exp • High School Diploma • Greenville
Cybersecurity
HIPAA
Management
Microsoft Office
Apply
≈ $70k – $159k per year (Estimated) • In office • 3+ years exp • Greenville
Management
Outlook
Apply
≈ $34k – $68k per year (Estimated) • In office • 1+ year exp • High School Diploma • Greenville
Apply
See all jobs
This is one of many
1,117,799 more open roles from verified company boards, updated every day.