Cyber Security STIG Tester

Leidos, Inc.
Gambrills, MD, United States
14 days ago
Apply on www.themuse.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$107,900.0 - $195,050.0
Working hours
Regular working hours

Tech stack

Xacta Computing Platforms Cyber Security Information Systems Network Administration Systems Development Life Cycle Security Content Automation Protocol Software Construction Information Technology Plan of Action and Milestones Vulnerability Analysis

Job description

The selected candidate shall perform (or review) technical security assessments using STIG Checklists, SCAP scans, and ACAS/ESS Scans of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) guidelines and regulations and recommend mitigation strategies. In this role, the candidate will ensure that the environments in which DoD information systems reside are secure and compliant, develop approaches to secure the environment, assess threats to the environment, provide inputs on the adequacy of security designs and architectures, perform RMF STIG and compliance testing related activities, and participate in risk assessment mitigation with the system administrators and providing relevant reporting for security briefing., * Ensure STIG Checklists are up to date and settings are enforced with minimal operational impact for all systems (workstations, servers, network) within the environment.

  • Support systems within GMS to have an up to date and complete STIG Checklist; educate systems/network administrators regarding completion/edits as required.
  • Examine results of STIG testing and pass results to system owners and system administrators.
  • Track response times to STIG findings and report on the security briefing.
  • Support POA&M analysis and coordination efforts, as required, including eMASS updates.
  • Perform cybersecurity lab testing/hardening activities supporting deployment of/updates to computer systems and applications.
  • Review data from ACAS/ESS scans and set tickets to add new equipment into scans as necessary.
  • Maintain SOP’s for testing and reporting activities.
  • Support functional testing as necessary for new technology.
  • Support testing events and preparation for testing events.
  • Perform vulnerability/risk analyses of computer systems and applications during all phases of the system development life cycle.
  • Support Authorizing Official (AO) actions by ensuring all testing related security testing artifacts are presented in accordance with RMF as defined in NIST 800-37 revision 2 and related agency specific RMF requirements.
  • Have experience performing various types of vulnerability and assessment scans with multiple tools.

Requirements

  • Bachelor’s degree and 8+ years of experience; additional years of directly applicable experience may be accepted in lieu of a degree.
  • Prior relevant experience working with STIG Compliance, SCAP tools, vulnerability assessments and reporting.
  • Have experience performing various types of vulnerability and assessment scans with multiple tools.
  • Have experience using eMASS and/or Xacta.
  • Solid understanding of the Risk Management Framework (RMF) and the System Development Life Cycle (SDLC).
  • Understanding of hardware and software engineering best practices.
  • Demonstrated analytical and problem-solving skills.
  • Must meet eligibility requirements for work assignment on specified contract.
  • Applicants selected will be subject to a government security investigation and must meet eligibility requirements.
  • Current DoD 8570 IAT II Certification is required. (Sec+.), * Ability to identify needed changes to processes and activities and help to implement continuous improvement solutions.
  • ACAS training completed.
  • Ability to work successfully as part of a virtual team.

If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 - and moving faster than anyone else dares.

Benefits & conditions

Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

About the company

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.themuse.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:53 min

Entering software development through retro computing platforms

Alex Soto Alex Soto · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:48 min

Limitations and missing features in edge compute platforms

Austin Gil · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all