HII
Information Systems Security Engineer (Engineer Info Assurance 3) - 26107
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About HII
Huntington Ingalls Industries (HII) is the largest military shipbuilder in the United States and a global defense provider, based in Newport News, Virginia. With over 135 years of experience, HII focuses on advancing national defense through shipbuilding, advanced technologies, and professional services. The company was established on March 31, 2011, as a spin-off from Northrop Grumman and operates three main divisions: Newport News Shipbuilding, Ingalls Shipbuilding, and Mission Technologies. HII employs more than 44,000 people, including over 9,000 engineers and designers. HII specializes in building nuclear-powered aircraft carriers, submarines, and advanced surface warships for the U.S. Navy and other defense customers. Its Mission Technologies division is known for offering AI and machine learning solutions, cyber data aggregation, and uncrewed underwater vehicles. HII serves a diverse range of clients, including the U.S. Navy, Coast Guard, Marine Corps, Air Force, and international defense partners, contributing to a robust backlog and significant annual revenue.
Security at HII
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
“Explicit AppSec team philosophy statements (developer enablement vs gatekeeping) are not publicly available.”
Security Team
- HII's leadership includes Jason Brown as CISO, who leads all aspects of the company's information security program.
- Chris Soong oversees all aspects of information technology, and Marc Sosa oversees all aspects of IT and cybersecurity for HII Mission Technologies.
- The company has a 44,000-strong team, including skilled tradespeople and AI/ML experts.
- However, no public, explicit 'Application Security' or 'AppSec Engineer' job postings were found, and explicit enterprise AppSec team descriptions were not found.
Key Initiatives
Evidence for AppSec-specific programs like security champions, shift-left IDE/CI practices, SAST/SCA tools, and AppSec team structure was not found in public pages reviewed. Details on security champions programs, documented 'shift-left' IDE/CI/CD practices, secure SDLC artifacts (e.g., mandatory security reviews, threat modeling), vulnerability triage SLAs/MTTR, and an AppSec toolstack are not publicly available.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.