Principal Cyber Security Analyst - Software Engineering
Nevada National Security SitesAbout the role
Mission Support and Test Services, LLC (MSTS) manages and operates the Nevada National Security Site (NNSS) for the U.S. National Nuclear Security Administration (NNSA). Our MISSION is to help ensure the security of the United States and its allies by providing high-hazard experimentation and incident response capabilities through operations, engineering, education, field, and integration services and by acting as environmental stewards to the Site’s Cold War legacy. Our VISION is to be the user site of choice for large-scale, high-hazard, national security experimentation, with premier facilities and capabilities below ground, on the ground, and in the air. (See NNSS.gov for our unique capabilities.) Our 2,750+ professional, craft, and support employees are called upon to innovate, collaborate, and deliver on some of the more difficult nuclear security challenges facing the world today.
- MSTS offers our full-time employees highly competitive salaries and benefits packages including medical, dental, and vision; both a pension and a 401k; paid time off and 96 hours of paid holidays; relocation (if located more than 75 miles from work location); tuition assistance and reimbursement; and more.
- MSTS is a limited liability company consisting of Honeywell International Inc. (Honeywell), Jacobs Engineering Group Inc. (Jacobs), and HII Nuclear Inc.
MSTS is seeking a highly experienced Cybersecurity professional for a Principal Software Security Engineer. The software engineer in this role (Principal Cyber Security Analyst) will be responsible for leading the testing, implementation, operation, and maintenance of secure software solutions, ensuring confidentiality, integrity, and the availability of sensitive data.
Key Responsibilities
- Implement, test, and operate advanced software security in compliance with federal security requirements.
- Perform on-going security testing and code review to improve software security.
- Provide engineering designs for new software applications to help mitigate security vulnerabilities.
- Automate application scanning and vulnerability assessment processes to support CI/CD releases.
- Validate identified security issues within applications and recommend fixes.
- Train team members on secure coding practices.
- Maintain technical documentation.
- Assist in researching, compiling, and analyzing technical data.
- Perform Security Test and Evaluations of information systems in support of a security plan.
- Write complex information system security plans (ISSPs) for classified and unclassified systems.
- Complete certification and accreditation of information systems on unclassified and classified networks, assist with the completion and mitigation of security testing and evaluation results, and is a resource for MSTS and other NvE enterprises for the Certification & Accreditation (C & A) process.
- Review current Cyber Security threat information and assist the Threat Evaluation team with mitigating vulnerabilities identified.
- Assist with data calls, FISMA reporting, compliance scanning and reporting, continuous monitoring and compiling reports for auditors.
- Provide training in Cyber Security to non-technical and technical individuals.
- Participate in business development by defining customer needs, developing proposals and planning projects that will produce results meeting customer needs.
- Develop standards, practices, and procedures as well as an increasing technical knowledge to solve problems and complete projects.
- Contribute to an overall productive and respectful work environment by providing excellent customer service and working in a positive, collegial manner.
- Maintain cooperative and respectful working relationships with Cyber Security staff, other divisions, and other customers.
- Bachelor’s degree or equivalent training and experience in a computer-related field and at least 8 years of related experience.
- Detailed technical knowledge of techniques, standards, and state-of-the-art capabilities for authentication and authorization, applied cryptography, security vulnerabilities and remediation.
- Adequate knowledge of web related technologies (web applications, web services and services-oriented architectures) and of network/web related protocols.
- Strong understanding of secure web application design principles and frameworks such as OWASP.
- Experience with development security scanning tools such as static and dynamic analysis.
- Experience with containerization security practices is a plus.
- Experience with scripting or code development using the following languages: C#, Node.js, Java, jQuery, .Net, ASP .Net, Cold Fusion, SQL, PHO, and HTML.
- Experience working with developers and devel
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s