nInformation Assurance Security Engineer (IASE) / Information Systems Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+7 more
Requirements
- Bachelor’s degree in Cybersecurity, Electrical Engineering, Information Technology, Information Assurance, or a related field with 8+ or 12+ years of experience; Master’s degree with 8+ or 10+ years of experience. Additional relevant experience may be considered in lieu of a degree.\n
- Active TS/SCI security clearance.\n
- 8+ years of security engineering experience, including experience with DoD RMF, ICD 503, and/or the NIST Risk Management Framework.\n
- Extensive experience with Intelligence Community (IC), Department of Defense (DoD), Defense Information Systems Agency (DISA), NAVINTEL Cybersecurity, Fleet Cyber Command (FLTCYBERCOM), and DoDIIS processes, tools, systems, reporting mechanisms, and requirements supporting Assessment and Authorization (A&A).\n
- 5+ years of software development experience using Java, C, C++, or other programming or scripting languages, including experience designing and developing host based and network based scanning tools.\n
- Experience with Security Content Automation Protocol (SCAP) based tools and specifications.\n
- Experience installing, configuring, testing, deploying, operating, and maintaining enterprise network based scanning and reporting tools such as Trellix/ESS, ACAS, RedSeal, Evaluate STIG, SteelCloud ConfigOS, and STIG Manager.\n
- Extensive experience hardening modern Unix operating systems, such as Oracle Solaris 10/11 and RHEL, as well as Microsoft Windows environments using Security Technical Implementation Guides (STIGs).\n
- Extensive experience securing systems and software in accordance with IC, DoD, and industry security best practices.\n
- Experience developing security controls, testing methodologies, and test procedures for systems, cloud based architectures, and Cross Domain Solutions (CDS).\n
- 2+ years of project management experience.\n
- Demonstrated ability to take a proactive, results oriented approach while building effective customer and team relationships.\n
Benefits & conditions
n \nLocation: Suitland, MD\n \nClearance: Active TS/SCI\n \n Leidos is hiring a hands-on \nInformation Assurance Security Engineer (IASE) / Information Systems Security Engineer (ISSE) to support a complex, mission-driven enterprise environment in \nSuitland, MD.\n \n In this engineering-focused role, you will actively secure, administer, harden, and maintain critical systems and infrastructure while collaborating across network, systems, cybersecurity, and architecture teams to continuously strengthen and evolve the organization’s overall security posture. You will combine deep technical security expertise with hands on engineering, vulnerability remediation, security testing, and architecture support to help protect mission critical systems and capabilities.\n \n This posting is for multiple opportunities ranging in years of experience. Level of opportunity, including compensation, will be matched to a candidate’s experience.\n \n \nResponsibilities\n \n \n
- Serve as a primary security engineering resource for enterprise infrastructure, providing hands on administration, configuration, security hardening, troubleshooting, and vulnerability remediation.\n
- Research and evaluate cybersecurity tools, technologies, and methodologies to identify opportunities to strengthen enterprise security.\n
- Participate in architecture and engineering reviews and provide security recommendations for new capabilities, technologies, and infrastructure changes.\n
- Troubleshoot complex security issues across storage, networking, operating systems, authentication, and enterprise infrastructure.\n
- Conduct vulnerability assessments, ethical hacking, and penetration testing to identify and address security risks.\n
- Review and harden storage protocols and services, including NFS, SMB/CIFS, iSCSI, and management interfaces, based on operational and security requirements.\n
- Apply and validate applicable DISA Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), vendor security guidance, and industry security best practices.\n
- Configure and maintain secure administrative access using technologies and principles such as SSH, HTTPS/TLS, role based access control (RBAC), centralized authentication, and least privilege.\n
- Develop and deliver training on cybersecurity tools, technologies, and processes.\n
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What’s the Difference between a Junior, Mid, and Senior Developer?
Best Paying Jobs in Technology
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
7 Important Tips That Every Software Developer Should Know