Information Systems Security Engineer
Role details
Job location
Tech stack
Requirements
- Bachelor's degree in a related field (e.g., Computer Science, Information Systems, Business) \n
- 12+ years of experience in information security engineering or Masters with 10 + years of prior relevant experience. May possess a Doctorate in technical domain. Experience will be considered in lieu of degree.\n
- Deep expertise in AWS and Azure security services and architecture. \n
- Strong understanding of cloud-native security controls and shared responsibility models. \n
- Experience with configuration management and orchestration tools (e.g., Terraform, Ansible, Puppet). \n
- Hands-on experience with containerization and orchestration (e.g., Docker, Kubernetes). \n
- Certifications such as CCSP, AWS Certified Security - Specialty, or Azure Security Engineer required. \n
- Proven experience supporting ATO upgrade efforts from NIST RMF Rev4 to Rev5, including \n
- Control family transitions and mapping (e.g., PM, RA, PL, SR families). \n
- Develop and maintain SSPs, SARs, POA&Ms, and compliance artifacts. \n
- Updating system documentation and security architecture to Rev5 standards. \n
- Experience supporting continuous ATO (cATO) for federal systems. \n
- Excellent facilitation, communication, and stakeholder engagement skills. \n
- Ability to work in a fast-paced, mission-driven environment. \n
- Must be a U.S. Citizen and able to obtain and maintain a Public Trust and a DoD Secret Clearance. \n, * Familiarity with zero trust principles and secure multi-cloud strategies. \n
- Familiarity or experience with UiPath is a plus \n
- Experience with compliance frameworks (FedRAMP, SOC 2, HIPAA, PCI-DSS). \n
- Experience using automation platforms like RegScale for cATO \n
- Proficiency in scripting and automation (Python, Bash, PowerShell). \n
- Prior experience supporting DHS, USCG, or other federal cloud modernization efforts \n
- Experience working with technical teams in cloud, cybersecurity, or enterprise IT environments \n
Benefits & conditions
The Digital Sector at Leidos is seeking a dynamic Information Systems Security Engineer (ISSE) to support cloud modernization initiatives for the United States Coast Guard (USCG) at Command, Control, Communication, Computer, Cyber, and Intelligence Service Center (C5ISC) in the Alexandria, VA area. This role is part of a high-impact program focused on delivering secure, scalable cloud solutions that enable operational agility and resilience across the USCG enterprise. As the ISSE, you will lead the design, implementation, and governance of cloud security solutions across our enterprise environments. This role is pivotal in ensuring the confidentiality, integrity, and availability of cloud-hosted assets while enabling secure innovation at scale by working closely with cloud engineers, cybersecurity analysts, and program leadership to drive continuous improvement and deliver value to the mission. \n \n \nThe Mission\n \n \nPrimary Tasks:\n \n \n
- Architect and implement secure cloud infrastructure across AWS and Azure platforms. \n
- Define and enforce cloud security policies, standards, and automation frameworks. \n
- Lead threat modeling, risk assessments, and incident response for cloud-native applications and services. \n
- Integrate security into CI/CD pipelines and DevOps workflows. \n
- Support cloud identity and access management (ICAM), encryption, and key management systems. \n
- Monitor cloud environments using SIEM, CSPM, CWPP, and other security tools. \n
- Collaborate with engineering, compliance, and operations teams to ensure secure cloud adoption. \n
- Stay ahead of emerging cloud threats and recommend proactive mitigation strategies. \n
- Support cross-functional coordination across engineering, cybersecurity, and program management teams \n
- Promote continuous improvement through feedback loops and process refinement \n
- Ensure alignment with USCG mission priorities and Leidos delivery standards \n