Employer Active
Job Alert
You will be updated with latest job alerts via emailJob Alert
You will be updated with latest job alerts via email$ 126100 - 227950
1 Vacancy
Leidos is seeking an Information System Security Officer (ISSO). The ISSO will be responsible for managing the authorizations and risks related to the processing storage and transmission of information for one or more programs within the Dissemination Task Order on the FS2 Program. The ISSO is responsible for meeting regulatory and nonregulatory compliance (security best practices) demands providing leadership over security assessment activities working across system ownership and management organizations to test security controls policies and procedures providing program management support team leadership and participating in and coordinating the support as needed for security assessment and activities The ISSO also manages and enforces government and corporate information security policies provides training and educates end users and program staff about proper security practices.
The ISSO conducts security and risk assessments as required using a range of security accreditation frameworks (e.g. NIST RMF Common Criteria DoD the Intelligence Community Directives (ICDs) and works to mitigate risks by applying security controls effectively to achieve an acceptable degree of operational part of this process the ISSO performs testing and security assessments to sustain required ISSO promotes the use of secure hardware and software within the systems affected by government and corporate approval ISSO works to ensure all required security policies and practices are effectively applied to systems and ensures security controls implementing these policies are applied and achieve the proper levels of confidentiality integrity availability and privacy protection throughout the system life cycle.
The ISSO also assists with the analysis and remediation activities for the vulnerability management program (scanning assessment reporting and mitigation verification) that spans different accreditation entities three distinct classification domain enclaves (U) (S) and (TS) using the Nessus and TenableACAS vulnerability scanning tools.
Primary Responsibilities:
Develops risk mitigation strategies that contribute to the effectiveness efficiencies and performance outcomes for strategic projects program goals and business processes.
Must be able to quickly respond to the needs for updates and maintenance of security documentation especially System Security Plans Plans of Actions and Milestones (POA&Ms); Security Impact Assessment for proposed system changes and Concept of Operations that identify and explain how each system satisfies its assigned security control baselines.
Maintains system security plans and related configuration records in customer Service (ServiceNow) XACTA360 platform and LeidosCIO security tools.
Drives necessary security changes through steering groups and control (review) boards to meet Risk Management milestones.
Can work independently as well as collaboratively to drive security process improvements especially to address gaps in meeting customer or Leidos security requirements and meet due diligence responsibilities.
Provides guidance and engages the program lab team to implement secure software and hardware processes apply government security standards and commercial best security practices.
Resolves highly complex security problems by applying technical knowledge conceptualizing reasoning and interpretation of requirements.
Communicating with Leidos and NGA leadership (internally or client) regarding matters of significant importance to the organization/project.
Apply indepth understanding of information security technical principles theories concepts and their application across a range of programs.
Develop and maintain security documentation per NGA/IC/DoDDISA/NIST/Industry standards and policies.
Initiate and coordinate all Assessment and Authorization (A&A) and renewal activities working with the NGA Designated Authorization Officials (DAO or DAOR).
Address any Information Assurance or Cybersecurity notices orders tasking or directives as required following the NGA operations vulnerability and patch management processes.
Measure effectiveness of defenseindepth architecture and Zero Trust policy implementations against known vulnerabilities.
Perform security audits and assessments including creating tracking and assisting in remediation of Plan of Action and Milestones (POA&Ms).
Coordinate with System Administrators and others to remediate all vulnerabilities and report results. Track open vulnerabilities and obtain and document approvals while managing POA&M status.
Update Security CONOPS and Information Technology Disaster Recovery (ITDR) plans for each Security Plan.
Manage security profiles and implementation for systems and services scheduled for Assessment and Authorization (A&A).
Work with the Systems Engineers and Administrators Senior ISSO ISSMs Lab Team and Leidos Corporate Security as required to develop and maintain security plans and associated documentation.
Maintain records and documentation on program IT systems upgrades patches and connectivity configurations.
Evaluate security solutions and implementation strategies for program IT systems and services and maintains operational security posture of development integration and deployed capabilities.
Provide training and approve user access and IAA (identification authorization and authentication) mechanisms for information systems.
Basic Qualifications:
US citizen
BS degree and 12 years of prior relevant experience to operate within the scope of responsibilities.
TS/SCI required with ability to obtain a CI Poly. Will consider upgrading a Secret clearance but must have the TS/SCI to start.
Sec or higher certification
NGA experience.
Experience that demonstrates an understanding and application of the ICD503 and NIST risk management framework.
Experience desired with the following systems/platforms/tools: XACTA; XACTA 360 (preferred); HBSS; ACAS; Nessus SPLUNK.
Preferred Qualifications:
Has 3 years of experience operating analyzing and resolving vulnerability scan results using tools such as Nessus Tenable Security Center or a comparable commercial or GOTs product.
Intelligence Community experience preferred.
For U.S. Positions: While subject to change based on business needs Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job education experience knowledge skills and abilities as well as internal equity alignment with market data applicable bargaining agreement (if any) or other law.
Required Experience:
Unclear Seniority
Full-Time