ISSO

Leidos, Inc.
Arlington, VA, United States
about 2 months ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$87,100.0 - $157,450.0
Working hours
Regular working hours

Tech stack

Cyber Security Information Systems Information Security Management Systems Development Life Cycle SAP (Applications) Information Technology Security Auditing Information Security Management System Nessus Splunk

Job description

Leidos’ Digital sector is seeking an IA professional to join our team in Arlington, VA - this position is 100% on-site in a secure environment. The ISSO will be responsible for managing the authorizations and risk related to the processing, storage, and transmission of information for one or more programs within the DISA Special Access Program (SAP) portfolio. The ISSO is responsible for meeting regulatory and non-regulatory compliance (security best practices) demands, providing leadership over security assessment activities, working across system ownership and management organizations to test security controls, policies, and procedures, and participating in and coordinating the support as needed for security assessments and activities. The ISSO also manages and enforces government and corporate information security policies, provides training, and educates end users and program staff about proper security practices., * Establish and implement security procedures and practices in support of Customer goals and current DoD regulations.

  • Develop and update Assessment & Authorization (A&A) documentation (Body of Evidence) for management and continuous monitoring of information systems.
  • Using knowledge of the Information System (IS) and understanding of established Information Assurance (IA) and Cybersecurity requirements validate security policies and procedures outlined in the System Security Plan (SSP), customer policies & regulations, and ensure local policies are followed.
  • Initiate the authorization or re-authorization efforts and process for new or expiring systems and coordinate, schedule, and attend required meetings
  • Serve as the System Information System Security Officer (ISSO) for various systems
  • Take corrective action to resolve problems identified and ensure systems are operated, maintained, and disposed of in accordance with established policies and procedures.
  • Perform security audits IAW established procedures. Develop process for the management, review, and retention of security audit data. Make decisions and implement corrective action as required to resolve audit discrepancies.
  • Author and review IS security-related documentation and submit to Enterprise Mission Assurance Support Service (eMASS).
  • As an IA Subject Matter Expert (SME), provide critical thinking to ensure system security requirements are addressed during all phases of the System Development Life Cycle (SDLC).
  • Conduct ongoing security reviews and tests of systems to verify security features and controls are functional and effective. Take corrective action to resolve identified vulnerabilities.
  • Provide security engineering review of proposed changes or additions to the IS (including hardware, software, or connectivity), and advise the Information System Security Manager (ISSM) of the security relevance.
  • Create and maintain processes and procedures for use by members of the ISSO team
  • Support the ISSO Team Lead in conducting lessons learned activities to improve the overall productivity and efficiency of the ISSO team
  • Communicates with internal team members across multiple areas and customer team members
  • Reviewing manual STIGs (ckls) utilizing STIGViewer
  • Reviewing ACAS Scans
  • Developing Project Management Plan to attain ATO

Requirements

  • DoD 8570 IAT Level II Certification
  • BS and 4+ of prior relevant experience, add’l experience may be considered in lieu of degree
  • 2+ years of experience working with eMASS, RMF, and STIGs
  • Active Top Secret/SCI clearance and ability to successfully pass a Polygraph exam
  • Experience with the following systems/platform tool(s): eMASS

Preferred Qualifications:

  • Experience with the following tools: ESS, ACAS, Nessus, Splunk

If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 - and moving faster than anyone else dares. Original Posting: July 6, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Benefits & conditions

Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .

About the company

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:52 min

Addressing junior hiring bottlenecks and mitigating widespread employee burnout

Hung Lee Hung Lee +3 · World Congress 2026 Europe

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

Videos

See all

Related articles

See all