Information System Security Officer

Leidos, Inc.
United States
1 day ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$87,100.0 - $157,450.0
Working hours
Regular working hours

Tech stack

Microsoft Azure Software as a Service Cloud Computing Communications Protocols Cyber Security Infrastructure as a Service (IaaS) Identity and Access Management Information Security Management Node.Js Platform as a Service (PAAS) Software Vulnerability Management SC Clearance
+4 more
Information Technology Nessus Splunk Vulnerability Analysis

Job description

The Decision Advantage within Defense at Leidos has an opening for a highly qualified Secret cleared Information System Security Officer. This is an exciting opportunity to bring your experience to support all-domain large-scale weapon systems, Information Technology Systems, and Command and Control Systems to realize the Department of Defense Joint All-Domain Command and Control (JADC2). In this role you will support the Advanced Battle Management System (ABMS) Digital Infrastructure (DI) Processing Node (PN) team to design and implement solutions that can be delivered at speed, scale, and with the necessary security to deliver operational advantages to the joint warfighter. ABMS is a top modernization priority for the Department of the Air Force and will be the backbone of a network-centric approach to battle management in partnership with all the services across JADC2. This position will work closely with Program Managers, domain engineers, and Government counterparts across Government and Industry partners.

Primary responsibilities:

  • Implement and enforce DoD, NIST, CNSS, and organizational cybersecurity policies, procedures, and standards.
  • Support the development, review, and maintenance of system security documentation (SSPs, POA&Ms, Security Assessment Reports, Continuous Monitoring Plans) within eMASS.
  • Conduct vulnerability assessments and assist in remediation of findings (e.g., STIGs, ACAS, Nessus).
  • Assist in preparing and submitting systems for Authorization to Operate (ATO) under the Risk Management Framework (RMF).
  • Identify and direct the remediation of technical problems encountered during testing and implementation of new systems (e.g., identify and find workarounds for communication protocols that are not interoperable).
  • Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials).
  • Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change.
  • Analyze design constraints, trade-offs and detailed system and security design, and consider lifecycle support.
  • Stay current on emerging threats, vulnerabilities, and compliance requirements.

Requirements

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field. Additional years of experience will be considered in lieu of degree.
  • Must be U.S. Citizen
  • Must possess an active and current Secret clearance.
  • 5+ years of experience in cybersecurity, with at least 2-3 years specifically as an ISSO or similar security role.
  • Working knowledge of:
  • DoD RMF process and NIST SP 800-53 controls
  • Security Technical Implementation Guides (STIGs)
  • Vulnerability management tools (ACAS, Nessus, HBSS, Splunk, etc.)
  • Monitor and evaluate system compliance with information technology (IT) security, resilience, and dependability requirements.
  • Experience supporting and developing required artifacts for the ATO/authorization processes within the DoD environment.
  • 2+ years of documented experience cybersecurity designs to meet specific operational needs and environmental factors (e.g., access controls, automated applications, networked operations, high integrity and availability requirements, multilevel security/processing of multiple classification levels, and processing Sensitive Compartmented Information).
  • DoD 8570/8140 IAT Level II or IAM Level I baseline certification (e.g., Security+ CE, CAP, CISM, CISSP).

Additional Qualifications/Certifications

  • TS/SCI clearance
  • Knowledge of cloud computing service models Software as Service (SaaS), Infrastructure as a Service (IaaS), and Platform as a Service (PaaS).
  • Experience with government cloud security environments ( GovCloud, Azure Government, Commercial Cloud Environment (C2E), Secret Commercial Cloud Environment (SC2E).
  • 2+ years of documented experience on information technology (IT) supply chain security and risk management policies, requirements, and procedures.

Benefits & conditions

Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .

About the company

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

45 sec

Working securely with Node.js path application programming interfaces

Sonya Moisset · World Congress 2023

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:55 min

Identifying underlying Node.js runtime vulnerabilities using fuzzing tools

Sonya Moisset · World Congress 2023

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

Videos

See all

Related articles

See all