CompTIA Cybersecurity Analyst

CareerCircle
Arlington, VA, United States
1 day ago
Apply on www.careercircle.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Compensation
$87,100.0 - $157,450.0
Working hours
Regular working hours

Tech stack

Java (Programming Language) Agile Methodology Artificial Intelligence Amazon Web Services Proxy Servers Systems Engineering Automated Storage and Retrieval Systems Audit Trail User Authentication Cloud Computing Configuration Management Software Quality
+75 more
Signals Intelligence CompTIA Security+ Cyber Security Information Systems Databases Continuous Integration Information Leak Prevention Linux Digital Forensics Distributed Systems Federal Information Processing Standards (FIPS) Github Monitoring of Systems Hardware Security Module Identity and Access Management Networking Hardware Internet Protocol Security (IP SEC) Intrusion Detection and Prevention Virtual Private Networks (VPN) Information Systems Security Architecture Professional JavaScript Libraries Python (Programming Language) Key Management Network Security Microsoft Security Essentials OAuth OpenID Ping (Networking Utility) Public Key Infrastructure Windows PowerShell Role-Based Access Control Red Hat Enterprise Linux Openid Connect Azure Active Directory Ansible Zero Trust Network Access Security Assertion Markup Language (SAML) Web Application Security Session Management Security Information and Event Management Software Engineering SonarQube Software Vulnerability Management Data Logging Network Routers Scripting Google Cloud Enterprise Software Applications Computer Network Operations Okta ReactJS Istio Cyber Threat Analysis HybridCloud Apigee Firewalls (Computer Science) Gitlab Cloudformation Build Management Kubernetes Infrastructure Automation Frameworks Information Technology Nessus Linkerd (Service Mesh) Cloud Migration Api Gateway Oracle Cloud Infrastructure Splunk Devsecops Api Management Cisco Plan of Action and Milestones Vulnerability Analysis Golang Programming Languages

Job description

OAuth Istio OpenID Apigee Auditing Aviation Equities, Leidos is seeking an ICAM / Identity Engineer to join the Air Traffic Business Area within the Homeland Sector, supporting the development of the Leidos Common Automation Platform (L-CAP). L-CAP is a mission-critical, future-ready automation platform built on a hybrid cloud data mesh architecture, enabling next-generation air traffic management capabilities. We are building with an AI-first engineering mindset, embracing emerging AI capabilities and modern development practices to accelerate delivery, improve software quality, and continuously evolve how we design and build mission-critical systems. This role operates within a SAFe/Agile framework as part of an Agile Release Train (ART) delivering iterative value across the program. This position supports government programs and requires the ability to obtain and maintain a favorable Public Trust investigation.

This is a hybrid position requiring 3 days onsite and 2 days working from home, if you are located within a commutable distance (Less than 1 hour’s drive one-way during normal traffic) from Gaithersburg, MD; Eagan, MN; or Egg Harbor Township, NJ. However, if you do not reside within a commutable distance, you may be considered for a 100% remote role.

In this role, you will implement the identity, credential, and access management (ICAM) layer that governs every user and service interaction with L-CAP. You will integrate the platform with government-provided ICAM services, enforce per-session authorization across distributed mission services, and build the access control and audit foundations that operational and support users depend on.

What You’ll Do:

  • Integrate L-CAP services with government-provided ICAM services using OAuth 2.0 and OpenID Connect, including token issuance, validation, and claims mapping.
  • Implement and maintain identity federation and user stores (Keycloak or equivalent), including role-based test account provisioning.
  • Implement per-session authentication and authorization for user-to-service and service-to-service requests, enforcing default-deny access regardless of network location.
  • Implement mutual TLS (mTLS), service mesh/workload identity, and certificate lifecycle management, including issuance, rotation, expiration monitoring, and revocation.
  • Design and implement role-based (RBAC) and attribute-based (ABAC) access controls aligned to operational and support roles.
  • Implement authentication and session management for operational users, including sign-in/sign-out and time-on-position logging.
  • Implement authentication and authorization audit logging, including event capture, storage, and retrieval.
  • Implement API gateway authorization and ensure external-facing endpoints are registered and protected through the API management layer.
  • Support security authorization and continuous monitoring by producing ICAM control evidence, resolving identity integration issues across distributed services, and leveraging AI-assisted development and automation to improve quality and delivery., Equities DevSecOps Operations Management Automation Market Data Consolidation Cyber Security Self-Motivation Working Capital Cloud Migration Service Catalog Virtual Routers Ancient History Customer Service CompTIA Security+ Security Clearance Service Management Security Solutions Technology Roadmaps Networking Hardware Information Sharing GIAC Certifications Palo Alto Firewalls CompTIA Security+ CE Continuous Integration Continuous Development Web Application Security IAT Level II Certification Virtual Private Networks (VPN) Internet Protocol Security (IP SEC) CompTIA Cybersecurity Analyst (CySA+) Systems Security Certified Practitioner Information Technology Infrastructure Library GIAC Security Essentials Certification (GSEC) Counter Intelligence Polygraph (CI Clearance) GIAC Global Industrial Cyber Security Professional Cisco Certified Network Associate Security (CCNA Security) Top Secret-Sensitive Compartmented Information (TS/SCI Clearance) +0 Cybersecurity Engineer SME Leidos

Bethesda, MD*On-Site

Linux CI/CD Splunk Nessus Rapid7 Ansible Auditing Firewall Equities Scripting SonarQube DevSecOps Pipelines Operations Automation Purchasing Upskilling Market Data Coordinating Oracle Cloud Cryptography Investigation Cyber Security Key Management Risk Management Authentications Cloud Computing Ancient History Network Security Security Controls Incident Response CompTIA Security+ Digital Forensics System Monitoring Endpoint Security Cyber Engineering Analytical Method Windows PowerShell AWS CloudFormation Systems Engineering Amazon Web Services Time Off Management Security Engineering Software Development Contingency Planning Signals Intelligence Programming Languages Regulatory Frameworks Vulnerability Scanning Security Configuration, Splunk Gitlab Github Ansible Auditing Firewall Equities Scripting DevSecOps Pipelines Operations Leadership Management Automation Mentorship Purchasing Upskilling

Requirements

Management Automation Kubernetes SAFe Agile Market Data NIST 800-53 API Gateway Cryptography ANSYS Meshing Accountability Cyber Security API Management Responsible AI Authentications Access Controls Computer Science Agile Methodology CompTIA Security+ Lifecycle Management Continuous Monitoring Information Technology Hybrid Cloud Computing Air Traffic Management Education and Training Hardware Security Module Authorization (Computing) Go (Programming Language) Public Key Infrastructure Software Quality (SQA/SQC) IAT Level II Certification Session (Computer Science) Java (Programming Language) Privileged Access Management Python (Programming Language) Federal Aviation Administration Role-Based Access Control (RBAC) CompTIA Cybersecurity Analyst (CySA+) Security Assertion Markup Language (SAML) Federal Information Processing Standards (FIPS), * Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or related field with 4+ years of relevant experience. (additional experience, education and training may be considered in lieu of degree)

  • Hands-on experience with OAuth 2.0 and OpenID Connect, including token validation, introspection, and claims mapping.
  • Experience with enterprise identity providers and federation such as Keycloak, Okta, Ping, Microsoft Entra ID, or equivalent.
  • Experience implementing RBAC and/or ABAC within distributed applications.
  • Working knowledge of PKI, certificate lifecycle management, mutual TLS (mTLS), and/or service mesh identity.
  • Understanding of Zero Trust principles, including per-session authorization and default-deny service communication.
  • Experience implementing audit logging for access and authorization events.
  • Proficiency in Java, Python, Go, or a comparable programming/scripting language.
  • Working knowledge of NIST SP 800-53 Access Control (AC) and Audit and Accountability (AU) controls.
  • Experience with Kubernetes and containerized service deployments.
  • U.S. citizenship required, with the ability to obtain and maintain a Public Trust and successfully complete required government background investigations.
  • Must meet FAA facility and information system access requirements, including continuous U.S. residency for at least 3 of the previous 5 years.

Preferred / Desired Qualifications:

  • Security+ CE, CySA+, or equivalent DoD 8570 IAT Level II certification.
  • Federal ICAM/FICAM experience, including PIV/CAC or agency ICAM integrations.
  • Experience with SAML 2.0 and SCIM provisioning.
  • Experience with Kubernetes RBAC and workload identity (SPIFFE/SPIRE).
  • Experience with service mesh implementation (Istio, Linkerd).
  • Experience with API gateway authorization policy (Kong, Apigee, or equivalent).
  • Familiarity with FIPS 140-3 validated cryptographic modules, hardware security modules, or enterprise key management.
  • Knowledge of privileged access management practices.
  • Experience in aviation, FAA, or other safety-critical environments.
  • Experience with SAFe or large-scale Agile delivery.

Why Leidos?

You’ll work on systems where performance, precision, and reliability matter - every second. This is not experimental AI for prototypes. This is disciplined, responsible AI applied to mission-critical software that supports national infrastructure.

If you’re excited by solving complex problems in regulated, real-world environments - and using AI as a force multiplier rather than a shortcut - we’d like to talk., Cyber Security Policies Configuration Management Vulnerability Management Certified Ethical Hacker Cyber Security Standards Cybersecurity Compliance Risk Management Framework Authorization (Computing) Cyber Threat Intelligence Cyber Security Assessment IT Security Documentation Agile Software Development Splunk Enterprise Security Google Cloud Platform (GCP) Computer Network Operations Change Management Processes Information Systems Security Customer Information Systems React.js (Javascript Library) Python (Programming Language) Enterprise Application Software Endpoint Detection And Response Troubleshooting (Problem Solving) Host Based Security System (HBSS) Intrusion Detection And Prevention CompTIA Cybersecurity Analyst (CySA+) Plan Of Action And Milestones (POA&M) Security Information And Event Management (SIEM) Certified Information Systems Security Professional, Market Data Cyberattack Coordinating Cryptography Player Coach Proxy Servers Cyber Security Key Management Security Tools Attack Vectors Detail Oriented Problem Solving Cloud Computing Ancient History Database Systems Network Security Security Controls Incident Response Digital Forensics Endpoint Security Cyber Engineering Analytical Method Windows PowerShell AWS CloudFormation Medical Monitoring Amazon Web Services Time Off Management Security Engineering Technical Leadership Data Loss Prevention Signals Intelligence Programming Languages Technical Engineering Vulnerability Scanning Text Retrieval Systems Education and Training Red Hat Enterprise Linux Cyber Threat Intelligence Agile Software Development Computer Network Operations Change Management Processes Customer Information Systems React.js (Javascript Library) Python (Programming Language) Virtual Private Networks (VPN) Enterprise Application Software Troubleshooting (Problem Solving) Host Based Security System (HBSS) Security Information And Event Management (SIEM)

Benefits & conditions

Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits .

About the company

If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 - and moving faster than anyone else dares., Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com .

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careercircle.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all