nInformation Systems Security Engineer
Nabout Leidos
United States
4 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on jobs.military.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Compensation
$107,900.0 - $195,050.0
Working hours
Regular working hours
Job source
Tech stack
Data Analysis
Systems Engineering
Complex Networks
Computer Data Storage
Federal Information Processing Standards (FIPS)
InfiniBand
Information Security Management
IPv6
Intrusion Detection and Prevention
Remote Direct Memory Access
High Performance Computing
Plan of Action and Milestones
+1 more
Vulnerability Analysis
Job description
- Ensure that the SSP and related artifacts comply with NASA and U.S. Government security requirements, including NPR 2810.1F, NIST 800-53/53B, FISMA, and the NIST HPC Security Overlay guidance.\n
- Provide expert technical consultation for internal and external stakeholders on HPC-specific security issues, including system hardening for MPI-based workloads, GPU/accelerator nodes, high-speed fabrics (InfiniBand, Slingshot), and performance-critical parallel filesystems.\n
- Identify solutions that balance high-performance computing usability with robust security ensuring that protective measures do not inhibit large-scale simulation workflows, mission operations, or research productivity.\n
- Provide regular HPC-specific data analytics and reporting - including vulnerability summaries, risk evaluations, security telemetry, and compliance findings - to Division and Branch leadership.\n
- Support Plan of Action and Milestones (POA&M) development, tracking, updating, and remediation for all HPC systems. Coordinate POA&M resolution activities across HPC systems engineering, networking, storage, and operations teams.\n
- Conduct targeted compliance assessments for large-scale HPC environments and report findings to NAS leadership. Assessments may include HPCc-cspecific topics such as high-speed interconnect configurations, MPI-node exposure risks, GPU driver-level vulnerabilities, and specialized HPC authentication/authorization workflows.\n
- Coordinate with other subtasks to implement, enforce, and maintain compliance with Government cybersecurity policies, including - but not limited to - NPR 2810.1F, NIST 800-53/800-53B, NIST SP 800-234 (HPC Security Overlay), DHS directives, FIPS standards, OMB guidance, and FISMA requirements.\n
- Coordinate participation in NASA Assessment & Authorization (A&A) activities for large-scale HPC systems, including data calls, technical evaluations, security control inheritance definitions, and documentation updates.\n
- Conduct credentialed and performance-aware vulnerability scans across HPC assets, ensuring scanning methods accommodate specialized hardware (GPU nodes, high-speed fabrics, parallel filesystems) without degrading mission workloads. Report results to NAS leadership and Information System Security Officials (ISSOs).\n
- Report potential or actual HPC security incidents to the appropriate NAS or Agency personnel. Support investigations in partnership with NASA SOC, Incident Response Teams, and NAS Management.\n
- Support Root Cause Analysis (RCA) investigations and remediation actions related to HPC security issues - especially those involving system performance anomalies, distributed job failures, and parallel-environment attack surfaces.\n
- Assist in the development of policies, procedures, and guidelines ensuring that HPC computational, storage, networking, and data-analysis systems comply with all applicable NASA and government security requirements.\n
- Maintain expertise in HPC security by monitoring NASA, NIST, DOE, and industry HPC security advisories. Communicate emerging HPC-specific threats - such as accelerator-specific vulnerabilities, MPI/RDMA protocol risks, and job-scheduler exploitation vectors - to facility staff.\n
- Coordinate security compliance activities related to Section 508, Supply Chain Risk Management (SCRM), IPv6 adoption, and cybersecurity reviews for all HPC IT acquisitions, including compute clusters, interconnects, accelerators, and data-storage hardware.\n
- Supports vulnerability assessment and design of intrusion detection tools for complex network architecture.\n
Requirements
- Bachelor’s degree and 8 years of prior relevant experience.\n
- Experience managing project work.\n
- Possess in-depth technical knowledge of Cybersecurity principles.\n
- Ability to delegate and track multiple projects at the same time.\n
- Ability to develop, motivate, and effectively manage the workforce.\n
- Strong work ethic and willingness to work as a team.\n
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on jobs.military.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
IK
Igor Khokhriakov
about 2 months ago
KD
Krissy Davis
Best Paying Jobs in Technology
over 3 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
LM
Luis Minvielle
What’s the Difference between a Junior, Mid, and Senior Developer?
over 3 years ago
KD
Krissy Davis
What is Software Engineering?
about 3 years ago
AF
Ava Faulkner
7 Important Tips That Every Software Developer Should Know
over 4 years ago