Information Systems Security Manager

Leidos, Inc.
Lincoln Acres, CA, United States
2 days ago
Apply on www.thejobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$107,900.0 - $195,050.0
Working hours
Regular working hours

Tech stack

Microsoft Access Microsoft Windows Configuration Management Cyber Security Information Systems Linux Information Security Management Key Management Network Security Network Architecture Network Planning and Design PSOS
+11 more
SAP (Applications) SAP Project Management SAP Security Virtualization Technology Computer Network Technologies SAPBasis Atlassian Tools Nessus Splunk Plan of Action and Milestones Vulnerability Analysis

Job description

In this role, you will oversee Information Systems supporting Special Access Programs (SAPs) and maintain system authorization and cybersecurity compliance throughout the system lifecycle in accordance with the Joint Special Access Program Implementation Guide (JSIG), Risk Management Framework (RMF), applicable DoD SAP security requirements, and customer-specific guidance., As the ISSM, you will serve as a Subject Matter Expert (SME) within the Information Assurance (IA) technical domain, supporting SAP Information Systems and enclaves across the enterprise. You will oversee day-to-day information system security operations, manage IA and IT personnel supporting SAP environments, resolve complex cybersecurity challenges, and develop innovative solutions to meet evolving program, customer, and security requirements., Experience developing, maintaining, and managing RMF authorization packages and associated cybersecurity documentation, including SSPs, security control implementation statements, POA&Ms, risk assessments, continuous monitoring artifacts, and supporting Body of Evidence. \n

  • \n Experience preparing Information Systems for cybersecurity assessments and supporting Security Control Assessors (SCAs), Authorizing Officials (AOs), Program Security Officers (PSOs), and customer cybersecurity representatives throughout the authorization process. \n

  • \n Familiarity with network technologies (LAN and WAN), network architecture, encryption technologies, key management, and cybersecurity best practices within classified and SAP environments. \n

  • \n Working knowledge of Microsoft Windows workstation/server and Linux operating systems within secure network environments. \n

  • \n Experience implementing and validating DISA Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), security configuration baselines, and system hardening requirements. \n

  • \n Experience with compliance, security monitoring, and vulnerability assessment tools such as Tenable/Nessus, ACAS, Splunk, and STIG Viewer. \n

  • \n Experience with workflow, documentation, configuration management, and change management tools such as JIRA and Confluence, as well as applicable RMF authorization management tools. \n

  • \n Ability to evaluate vulnerabilities, system changes, security control deficiencies, and cybersecurity risks and develop appropriate mitigation and remediation strategies. \n

  • \n Must be able to work in a constantly changing regulatory and mission environment with short-, mid-, and long-term timelines for resolving cybersecurity risks and compliance deficiencies. \n

  • \n Must work effectively within multidisciplinary teams and adapt quickly to changing program, customer, and mission requirements. \n

  • \n Excellent verbal and written communication skills with the ability to communicate cybersecurity risks and technical information to technical and non-technical stakeholders. \n

Requirements

The ideal candidate must be able to work independently while effectively collaborating with cybersecurity analysts, system administrators, engineers, program management, security personnel, site leadership, Program Security Officers (PSOs), Security Control Assessors (SCAs), and Authorizing Official (AO) representatives., Bachelor’s degree in an IT-related subject matter area from an accredited college or university and 12+ years of experience in an operational cybersecurity-specific role (e.g., Information Systems Security Manager, Information Systems Security Officer, cybersecurity specialist), or 16+ years of experience in an IT-related position with at least 10 years in an operational cybersecurity-specific role., Experience working directly with PSOs, SCAs, AOs/DAOs, government cybersecurity representatives, and SAP program management. \n

  • \n Experience supporting SAP Information System Assessment and Authorization activities from initial system design through ATO and continuous monitoring. \n

  • \n Experience developing JSIG/RMF authorization documentation and providing supporting artifacts and evidence for security control assessments. \n

  • \n Experience with SAP cybersecurity assessments, compliance inspections, and remediation of assessment findings. \n

  • \n Proficient with Microsoft Windows and Linux operating systems, virtualization technologies, and secure computing environments. \n

  • \n Experience with network security architecture, classified network design, secure communications, encryption, and key management. \n

  • \n Experience developing cybersecurity policies, procedures, SOPs, CONOPS, and other technical documentation supporting SAP Information Systems. \n

  • \n Experience using JIRA and Confluence for cybersecurity workflow, continuous monitoring, vulnerability tracking, POA&M management, and documentation.

Benefits & conditions

Mentor ISSOs, system administrators, and other Information Assurance professionals regarding JSIG, RMF, secure system administration, vulnerability management, configuration management, and cybersecurity best practices. \n

  • \n Coordinate technical training on cybersecurity tools, software, technologies, and procedures used within SAP Information System environments. \n

  • \n Develop and lead training related to cybersecurity incident response, including identification, reporting, containment, remediation, recovery, documentation, and lessons learned. \n

  • \n Develop and lead Information Security projects from conceptualization through implementation, authorization, deployment, and operational acceptance. \n

  • \n Provide cybersecurity risk information and recommendations to program and senior site leadership to support risk-informed decisions regarding SAP Information Systems. \n

  • \n Demonstrated experience managing the cybersecurity and compliance posture of complex, multi-site Wide Area Networks (WANs), including interconnected systems across geographically dispersed locations. \n

  • \n Experience applying RMF, NIST, and applicable DoD security requirements to WAN architectures, boundary protections, network infrastructure, continuous monitoring, vulnerability management, and authorization activities. \n

\n

\n, Working knowledge of DoD Special Access Program cybersecurity requirements, policies, processes, and procedures applicable to the authorization and operation of SAP Information Systems., * \n Experience leading or mentoring ISSOs, system administrators, cybersecurity analysts, and other technical personnel supporting SAP Information Systems. \n

\n

If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 - and moving faster than anyone else dares.

Original Posting:September 17, 2026\n\n \n \n \n \n \n \n

\n

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

\n \n \n \n \n \n \n\n\n

Pay Range:Pay Range $107,900.00 - $195,050.00\n

\n

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

\n

\n

About Leidos

\n

\n

About the company

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.thejobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

2:38 min

Establishing comprehensive monitoring and log management

Michael Eder +1 · LIVE

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · World Congress 2025

2:47 min

Exploring career opportunities and recruitment open positions

Kurt Eder · LIVE

3:10 min

Correlating dispersed logs using structured request tracing

Michael Eder +1 · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all