Information Systems Security Manager

Leidos, Inc.
Concord, MA, United States
7 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$107,900.0 - $195,050.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Cloud Computing Configuration Management Cyber Security Information Systems Data Security Linux Firmware Identity and Access Management Issue Tracking Systems Information Security Management Internet Protocol
+10 more
Key Management Local Area Networks Network Security Network Connections Network Routers Computer Network Technologies Information Technology Tenable Nessus Cyber Warfare Vulnerability Analysis

Job description

Leidos Corporate Information Security Office (CISO), reporting through the Digital Sector, is seeking an Information Systems Security Manager to work in our Concord, MA office.

The ISSM is responsible for the management and technical administration of SIPRNET (Secret Internet Protocol Router Network) secure communication infrastructure within the organization. In this role, you will serve as the Subject Matter Expert (SME) within the Information Assurance technical domain and, more specifically, for organizational SIPRNET (Secret Internet Protocol Router Network) enclaves across the enterprise. You will oversee day-to-day information system security operations, resolve complex problems, and develop innovative solutions to meet changing security requirements. To be successful, you must have the ability to work independently as well as with a team of analysts, information technology management and staff, and site management. The ideal candidate will be adaptable to diverse office situations, procedures, and demands.

Primary Responsibilities

This role may include a combination of duties to protect information and maintain security controls for an entire system, site, or program in order to reduce risk.

  • Oversee and manage SIPRNet services across multiple sites and advise senior site leadership of established security policies and guidelines.
  • Coordinate and participate in security audits and assessments to ensure that site SIPRNET infrastructure meets the required security standards and complies with regulations.
  • Lead sites in establishing and sustaining the cybersecurity of SIPRNet enclave connections.
  • Coordinate SIPRNet connections for sites per guidance outlined in the Defense Information System Network Connection Process Guide.
  • Ensure SIPRNet systems are configured and sustained per the DoD, U.S. Cyber Command, and JFHQ-DODIN guidance.
  • Provide training and awareness on security protocols, best practices, and Command Cyber Readiness Inspection preparation for organizational and site leadership.
  • Conduct site CCRI self-assessments for all SIPRNet sites within the organization.
  • Develops and leads Information Security projects from conceptualization to full deployment and user acceptance.
  • Create comprehensive training programs focused on information assurance, data security, cybersecurity best practices, and relevant policies and procedures.
  • Design training materials, including manuals, operating procedures, presentations, assign online courses, and other resources.
  • Coordinate technical training on security tools, software, and technologies used within the organization to enhance the skills of IT staff and other relevant personnel.
  • Develop and lead training on how to respond to security incidents, including reporting procedures, containment, eradication, recovery, and post-incident analysis.
  • Develop and maintain a comprehensive onboarding plan for new hires, outlining the orientation process, training schedules, and integration into the team and company culture.
  • Develop and implement a robust tracking system to monitor the progress and completion of IA staff training programs, ensuring accurate and timely recording of training milestones, assessments, and certifications.
  • Implement and manage the Risk Management Framework (RMF) Continuous Monitoring process by utilizing an automated ticketing system, ensuring accurate tracking, monitoring, and reporting of security controls, vulnerabilities, and remediation efforts within the organization’s information systems.
  • Manages staff to deliver Cyber Operations, Cyber process improvements, and Cyber project execution.
  • Continuous monitoring, analysis, and response to Information System network and security events.
  • Documents compliance activities in accordance with the governing authority-approved authorization package.
  • Develop procedures and documentation to ensure compliance with Configuration Management (CM) for security-relevant Information System (IS) software, hardware, and firmware.
  • Ensures systems are operated, maintained, and disposed of in accordance with the governing authority-approved authorization package and customer directives.
  • Evaluate proposed changes or additions to the information system and advise senior site leadership of the security relevance.
  • Develop and conduct cybersecurity education and training.
  • Mentor other information assurance professionals in the art of cybersecurity and secure software development practices
  • Participate in internal/external security audits/assessments/inspections; participates in the risk management process; performs risk assessments and Continuous Monitoring
  • Lead investigations of computer security violations and incidents, reporting as necessary to both the Facility Security and Senior Program Managers.
  • Ensure proper protection and/or corrective measures have been taken when an incident or vulnerability has been discovered
  • Work with the Facility Security Officer (FSO), develop, implement, and manage a formal Information Security/Information Systems Security Program.
  • Develop, implement, and enforce Information Security Policies and Procedures.
  • Author, review, and update IS Authorization documentation (Body of Evidence) to support IS Assessment and Authorization activities

Requirements

  • An active DoD Top Secret clearance is required for consideration.
  • Bachelor’s degree in an IT-related subject matter area from an accredited college or university and 12+ years of experience in an IT-related position with at least 10 years being in an operational cyber security-specific role (e.g., information system security manager, information system security officer, cyber security specialist) or have 15+ years of experience in an IT related position with at least 10 of those years in an operational cyber security specific role.
  • At least 12 years of IT Team leadership and management experience, preferably 10 years of Cyber management experience.
  • DoD 8570 IAM Level I certified.
  • Detailed understanding of the Risk Management Framework (RMF), National Institute of Standards and Technology (NIST), and Committee on National Security Systems (CNSS) cyber security requirements and guidance, cybersecurity-related risk management techniques.
  • Familiarity with network technologies (LAN & WAN) and best practices within a classified environment, including crypto and key management.
  • Working knowledge of Microsoft Windows (workstation & server) and Linux operating systems in a secure network environment.
  • Experience with compliance scanning tools and vulnerability scanning tools (e.g., Tenable).
  • Must be able to work in a constantly changing regulatory environment with short-, mid-and long-term timelines for remediating any non-compliance.
  • Must be able to work well within a team environment and adapt quickly to change.
  • Excellent verbal and written communication skills.
  • Past or current ISSM/ISSO experience.
  • Extensive experience with Secret Internet Protocol Router Network (SIPRNet) enclaves and governing policies.

Preferred Qualifications

  • Proficient in using Microsoft Windows and Linux operating systems and cloud computing.
  • Experience with developing policies, procedures, and guidance to include providing artifacts for the RMF process.

Benefits & conditions

Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .

About the company

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:19 min

Orchestrating over-the-air firmware updates for vehicle modules

Denis Grahovac · WWC 2021

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

2:20 min

Utilizing custom firmware for variable torque manipulation

Daniel Meilak Daniel Meilak +1 · WWC Europe 2026

Videos

See all

Related articles

See all