nCyber Security STIG Tester

Nabout Leidos
Meade, KS, United States
21 days ago
Apply on jobs.military.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$107,900.0 - $195,050.0
Working hours
Regular working hours

Tech stack

Xacta Network Administration Systems Development Life Cycle Security Content Automation Protocol Software Construction Information Technology Plan of Action and Milestones Vulnerability Analysis

Job description

u2022 Ensure STIG Checklists are up to date and settings are enforced with minimal operational impact for all systems (workstations, servers, network) within the environment. \n \u2022 Support systems within GMS to have an up to date and complete STIG Checklist; educate systems/network administrators regarding completion/edits as required. \n \u2022 Examine results of STIG testing and pass results to system owners and system administrators.\n \u2022 Track response times to STIG findings and report on the security briefing.\n \u2022 Support POA&M analysis and coordination efforts, as required, including eMASS updates.\n \u2022 Perform cybersecurity lab testing/hardening activities supporting deployment of/updates to computer systems and applications. \n \u2022 Review data from ACAS/ESS scans and set tickets to add new equipment into scans as necessary.\n \u2022 Maintain SOP’s for testing and reporting activities. \n \u2022 Support functional testing as necessary for new technology. \n \u2022 Support testing events and preparation for testing events.\n \u2022 Perform vulnerability/risk analyses of computer systems and applications during all phases of the system development life cycle.\n \u2022 Support Authorizing Official (AO) actions by ensuring all testing related security testing artifacts are presented in accordance with RMF as defined in NIST 800-37 revision 2 and related agency specific RMF requirements.\n \u2022 Have experience performing various types of vulnerability and assessment scans with multiple tools.\n \n

Requirements

u2022 Bachelor’s degree and 8+ years of experience; additional years of directly applicable experience may be accepted in lieu of a degree.\n \u2022 Prior relevant experience working with STIG Compliance, SCAP tools, vulnerability assessments and reporting.\n \u2022 Have experience performing various types of vulnerability and assessment scans with multiple tools.\n \u2022 Have experience using eMASS and/or Xacta.\n \u2022 Solid understanding of the Risk Management Framework (RMF) and the System Development Life Cycle (SDLC).\n \u2022 Understanding of hardware and software engineering best practices.\n \u2022 Demonstrated analytical and problem-solving skills.\n \u2022 Must meet eligibility requirements for work assignment on specified contract.\n \u2022 Applicants selected will be subject to a government security investigation and must meet eligibility requirements.\n \u2022 Current DoD 8570 IAT II Certification is required. (Sec+.)\n \n \nPREFERRED QUALIFICATIONS:\n \u2022 Ability to identify needed changes to processes and activities and help to implement continuous improvement solutions.\n \u2022 ACAS training completed.\n \u2022 Ability to work successfully as part of a virtual team.\n

About the company

If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 - and moving faster than anyone else dares.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.military.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:59 min

Navigating uncertain execution and expanding technical capabilities

Paul Adams Paul Adams · World Congress 2025

1:55 min

Decoupling network administration from application deployment pipelines

Duan Lightfoot Duan Lightfoot · World Congress 2023

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:38 min

Assembling the complete execution toolchain for local agents

Elaine Dias Batista Elaine Dias Batista · World Congress 2026 Europe

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:37 min

Demonstrating developer platform administration and automated workspace provisioning

Romano Roth Romano Roth · World Congress 2025

Videos

See all

Related articles

See all