{"id":1608597,"url":"https://alion.io/job/l3harris-technologies-lead-information-security-systems-engineer","title":"Lead, Information Security Systems Engineer","company":{"id":177017,"name":"L3Harris Technologies","domain":"l3harris.com","url":"https://alion.io/company/l3harris-technologies","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"SuccessFactors","truth_index":null},"role":"Security","role_family":"Security","seniority":"lead","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Greenville, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":121000,"max_usd":257000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":228},"experience_years_min":13,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Linux","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"SIEM","optional":false},{"name":"Splunk","optional":false},{"name":"Wazuh","optional":false},{"name":"Windows","optional":false}],"status":"live","first_seen_at":"2026-09-24T00:00:00Z","employer_posted_date":"2026-09-24","last_verified_at":"2026-10-03T00:30:39Z","board_verified":true,"closed_at":null,"days_open":9,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":9},"description":"Job Title: Lead, Information Security Systems Engineer\nJob Code: 44627\nJob Location: Greenville, TX\nSchedule: 9/80 - Employees work 9 out of every 14 days - totaling 80 hours worked - and have every other Friday off\nJob Description:\nThe Lead Incident Response and Security Operations Engineer establish, operates, and continuously improves the Enterprise Product and Services’ incident response and security operations capability across a government-owned, contractor-operated hybrid environment that includes Amazon Web Services (AWS), multiple data centers, and a corporate location.\nThe role leads monitoring, investigation, detection engineering, incident coordination, and risk escalation to strengthen the availability, integrity, and confidentiality of GSS services.\nInfrastructure, system, and application owners retain responsibility for technical remediation, patching, and platform repair.\nEssential Functions:\n15% travel based on business needs (CONUS or OCONUS).\nAbility to work a flexible schedule includes off-shift work, weekends, occasional overtime, and on-call duties.\nEstablish and maintain security information and event management operations, including Wazuh health, log ingestion, data-quality validation, alert rules, dashboards, and detection tuning.\nMonitor, triage, investigate, document, and coordinate response to security events across AWS, datacenter, network, endpoint, and corporate environments.\nCreate and manage security-incident tickets; preserve investigation evidence; document findings and actions; and validate closure with responsible technical owners.\nDevelop and maintain incident-response plans, escalation paths, severity criteria, playbooks, runbooks, and after-action reports.\nCoordinate remediation tracking for vulnerabilities, security findings, and incident corrective actions, escalating overdue or material risk.\nConduct AWS security-alert and exposure reviews, including identity and access management, privileged access, logging, and cloud-security findings within assigned authority.\nOnboard and maintain log sources and integrations needed to support monitoring, detection, incident investigation, and compliance evidence.\nConduct periodic reviews of privileged access, security-tool access, and operational logging coverage; support disaster-recovery and incident-response exercises.\nProduce security-operations metrics, risk reports, and stakeholder briefings, and maintain documentation supporting the Risk Management Framework, audit readiness, and continuous monitoring.\nQualifications:\nActive US Secret security clearance or higher.\nBachelor’s Degree and minimum 9 years of prior relevant experience.\nGraduate Degree and a minimum of 7 years of prior related experience.\nIn lieu of a degree, a minimum of 13 years of prior related experience.\nCurrent in at least one of the following; Certified Information Security Manager, Certified Information Systems Auditor, Certified Cloud Security Professional, Certificate of Cloud Security Knowledge, or comparable Department of Defense 8140 certification.\nMinimum 8 years of security operations, incident response, or security engineering experience.\nDemonstrated experience operating or engineering a security information and event management platform, developing detection rules, validating log ingestion, and tuning alerts.\nDemonstrated experience with incident triage, investigation, evidence handling, ticket management, stakeholder communications, and closure documentation.\nDemonstrated experience supporting hybrid-cloud environments, including AWS and on-premises data-center infrastructure.\nPreferred Additional Skills\nKnowledge of Windows, Linux, networking, identity and access management, security logging, and vulnerability-management processes.\nExperience with SIEM, Logging and Monitoring infrastructure design, operation management\nSplunk, Wazuh, SysAid, AWS security services, or comparable security information and event management, information technology service management, and cloud-security platforms.\nExperience with MITRE ATT&CK, detection engineering, threat hunting, and alert use-case development.\nExperience developing or maintaining incident-response and disaster-recovery plans, playbooks, tabletop exercises, or technical exercises.\nExperience with plans of action and milestones, audit evidence, security assessments, and government compliance environments.\nCISSP, CISM, CCSP, GCIH, GCIA, CySA+, Security+, AWS Certified Security - Specialty, or comparable certification.\nExperience supporting government-owned, contractor-operated systems and multi-site operations.\nExperience with Risk Management Framework assessment and authorization activities, National Institute of Standards and Technology Special Publication 800-53 controls, or Platform Information Technology environments.","description_format":"text","description_chars":4823,"description_truncated":false,"requirements":{"experience_years_min":13,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":true,"languages":[]},"benefits":["Flexible schedule"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Government","Military","Science & Engineering","National Security"],"lifecycle":[{"event":"open","at":"2026-10-01T20:02:36Z"}],"liveness":{"score":70,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.78,"p_room":0.9,"age_days":8,"expected_fill_days":20,"reasons":["conf:9","win:mid","comp:brand"],"computed_at":"2026-10-02T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/l3harris-technologies-lead-information-security-systems-engineer","json_url":"https://alion.io/job/l3harris-technologies-lead-information-security-systems-engineer.json","meta":{"generated_at":"2026-10-03T03:37:31Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3614,"day_limit":5000,"remaining_today":1386,"minute_limit":60,"resets_at":"2026-10-04T00:00:00Z"}}}