Information System Security Engineer

Leidos, Inc.
Chula Vista, CA, United States
1 day ago
Apply on www.thejobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$107,900.0 - $195,050.0
Working hours
Regular working hours

Tech stack

Microsoft Access Microsoft Windows Active Directory User Authentication Configuration Management Information Systems Linux Domain Name System (DNS) Information Security Management Information Systems Security Engineering Professional Network Security Routing
+16 more
Network Segmentation Systems Development Life Cycle Red Hat Enterprise Linux SAP (Applications) Security Content Automation Protocol Security Information and Event Management TCP/IP Virtual Local Area Networks Virtualization Technology Software Vulnerability Management Data Logging Firewalls (Computer Science) Build Management Nessus Data Management Splunk

Job description

  • Serve as the Information System Security Engineer (ISSE) for Special Access Program information systems, providing security engineering support throughout the full system lifecycle from research and development through deployment, accreditation, operations, maintenance, and decommissioning. \n

  • Design, develop, integrate, and maintain secure classified information systems and architectures in accordance with the Joint Special Access Program Implementation Guide (JSIG), Risk Management Framework (RMF), applicable DoW policies, and program-specific security requirements. \n

  • Develop and maintain system security architecture, including network segmentation, boundary protections, authentication, privileged access, encryption, auditing, logging, secure communications, virtualization, storage, and data protection solutions. \n

  • Implement and validate DISA Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), vendor security guidance, and program specific hardening requirements across Windows, Linux, network, virtualization, storage, and supporting infrastructure. \n

  • Coordinate with ISSMs, ISSOs, System Administrators, and Program Management to resolve technical and compliance issues. \n

  • Develop secure configuration baselines, build procedures, automation, scripts, and configuration management processes to improve repeatability and compliance across classified systems. \n

  • Support troubleshooting and resolution of complex security and infrastructure issues involving a variety of information systems. \n

  • Support the preparation for and execution of government security assessments, authorization reviews, inspections, and audits, including collection and presentation of objective evidence demonstrating control implementation. \n

  • Provide technical cybersecurity guidance and mentoring to system administrators, ISSOs, and other program personnel. \n

Requirements

  • Bachelor’s Degree with 8-12 years of experience, Master’s degree with 6-10 years of experience, or equivalent relevant experience and/or industry-standard certifications may be considered in lieu of degree. \n

  • Must hold a current Active Top Secret security clearance to be considered along with sustained ability to be cleared to Special Access Programs and ability to obtain Top Secret/SCI security clearance. \n

  • Must have a DoD 8140/8570 IAT level II or higher certification such as CompTIA Security+. \n

  • Professional-level knowledge and hands-on experience administering, engineering, or securing Windows and Linux operating systems, including enterprise server and workstation environments. \n

  • Expert-level knowledge of virtualization technologies, enterprise storage platforms, and backup/recovery solutions, including the security considerations associated with each. \n

  • Working knowledge of enterprise networking concepts and technologies, including TCP/IP, routing, switching, VLANs, firewalls, network segmentation, DNS, authentication, and secure network architecture. \n

  • 3+ years of demonstrated experience supporting Special Access Program (SAP) environments and applying applicable cybersecurity requirements, including the RMF and JSIG. \n

  • Experience interpreting cybersecurity requirements and translating security controls into technical configurations, engineering requirements, and system implementations. \n

  • Experience implementing, assessing, and maintaining technical security controls across operating systems, networks, virtualization platforms, storage, and supporting infrastructure. \n

  • Hands-on experience implementing and maintaining DISA STIGs, SRGs, Nessus, and secure configuration baselines. \n

  • Knowledge of enterprise security technologies and concepts, including Active Directory, Group Policy, endpoint security, centralized logging, auditing, privileged access, encryption, and access control. \n

  • Experience supporting the system development and security lifecycle, including design, integration, testing, deployment, authorization, continuous monitoring, maintenance, and decommissioning. \n

  • Ability to troubleshoot complex technical and cybersecurity issues spanning operating systems, networking, or other information system components. \n

  • Strong technical documentation and communication skills with the ability to clearly communicate security risks, technical requirements, remediation strategies, and engineering recommendations to both technical and nontechnical stakeholders. \n

  • Experience with the Risk Management Framework (RMF) and maintaining compliance artifacts such as SCAP scans, STIGs, and Nessus Vulnerability reports. \n

  • Experience developing or maintaining technical procedures, system build documentation, configuration baselines, work instructions, scripts, or automation used to support secure and repeatable system deployments. \n

  • Experience designing or securing air-gapped environments including offline patching, software repositories, vulnerability management, and configuration management. \n, * ISC(2) Certification Information System Security Professional (CISSP) or Information System Security Engineering Professional (CISSP-ISSEP) certification. \n

  • RedHat Certified System Administrator (RHCSA) certification. \n

  • Demonstrated ability to independently interpret JSIG/RMF controls and translate them into practical technical architectures, configurations, implementation guidance, and validation procedures. \n

  • Experience developing and maintaining SIEM/log-management platforms such as Splunk, and endpoint security technologies to include DLP. \n

About the company

If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo - because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 - and moving faster than anyone else dares.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.thejobnetwork.com
Prepare application

Good distractions

Loading talks and stories from around this role…