Senior Security Engineer
Bethesda, MD - USA
Job Summary
General program information and/or position overview.
Leidos is seeking a Senior Security Engineer to serve as the technical lead for day-to-day security activities supporting enterprise and isolated environments. This position will provide technical leadership and oversight for security operations vulnerability management RMF/ATO support and continuous monitoring activities.
The individual will lead and mentor security personnel establish priorities and coordinate security activities across infrastructure and engineering teams. This is a hands-on technical lead position and the individual will be expected to directly support security engineering and operational security activities as needed.
The individual will work closely with the ISSM customer program leadership and technical teams to translate security requirements into actionable work and maintain the overall security posture of the environment.
This is a 100% on-site position. All work must be performed at the customer site.
Primary Responsibilities
Lead and coordinate day-to-day security operations establish priorities and assign and track activities across the security team.
Provide technical leadership and guidance to security personnel system administrators engineers and other technical teams.
Lead vulnerability management from identification through closure including analysis prioritization remediation validation and documentation.
Coordinate vulnerability remediation across Windows Linux network desktop support and other engineering teams and provide hands-on support for complex or high-priority issues as needed.
Oversee and perform vulnerability scanning and analysis using ACAS Tenable/Nessus or equivalent technologies.
Oversee implementation and validation of DISA STIGs and approved security configuration baselines across infrastructure systems.
Ensure recurring security activities are performed including audit log and account reviews vulnerability reviews security control validation and continuous monitoring.
Support and oversee RMF/ATO activities including security documentation control evidence Body of Evidence (BoE) POA&Ms and compliance with NIST SP 800-53 ICD 503 and applicable security directives.
Work with the ISSM to translate security and compliance requirements into technical and operational activities and evaluate system or configuration changes for potential security impact.
Provide security oversight and technical support for isolated or restricted environments including vulnerability scanning logging patching hardening and security monitoring.
Review security logs and events using Splunk or equivalent SIEM/log-management technologies and ensure identified issues are appropriately addressed.
Develop and maintain repeatable security processes and procedures for vulnerability management compliance monitoring evidence collection and security operations.
Track security risks deficiencies remediation activities and compliance status and communicate status risks and recommendations to customer and program leadership.
Participate in Technical Exchange Meetings (TEMs) security reviews engineering meetings and customer discussions related to system security and accreditation.
Manage supervise and mentor security and technical staff as assigned.
Basic Qualifications
Bachelors degree in Computer Science Information Technology or a related field or equivalent work experience.
Experience with application performance and latency problems related to security requirements from front middle and back end
Working experience with Windows Server 2016/2019 Active Directory IIS DNS DHCP Exchange DFS
Experience implementing security controls on common network services such as file email and active directory across multiple geographically dispersed sites.
Experience with networking technologies and security assessment to include but not limited to STIGs.
Experience implementing and supporting enterprise system security and malware monitoring and prevention tools such as Splunk McAfee HBSS and ACAS
Solid network and systems troubleshooting experience with TCP/IP Internet security and encryption (data at rest data in transit)
Ability to produce clear and concise documents and diagrams capturing networking and operational procedures and LAN/WAN topology using MS Visio MS Project MS Excel and MS Word.
Candidate must at a minimum meet DoD 8570.11- IAT Level II certification requirements (currently Security CE CCNA-Security GSEC or SSCP along with an appropriate computing environment (CE) certification)
Education/Experience Requirements
Candidate must have a Bachelors with at least 8 years of relevant experience. Additional years of experience may be considered in lieu of degree.
Clearance
Active TS/SCI clearance with Polygraph required OR active TS/SCI and willingness to get a Poly.
US Citizenship is required due to the nature of the government contracts we support.
Preferred Qualifications
Experience managing and/or supervising a team of technical professionals
CISSP or CASP Certification
If youre looking for comfort keep scrolling. At Leidos we outthink outbuild and outpace the status quo because the mission demands it. Were not hiring followers. Were recruiting the ones who disrupt provoke and refuse to fail. Step 10 is ancient history. Were already at step 30 and moving faster than anyone else dares.
For U.S. Positions: While subject to change based on business needs Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job education experience knowledge skills and abilities as well as internal equity alignment with market data applicable bargaining agreement (if any) or other law.
Required Experience:
Senior IC
About Company
Leidos is an innovation company rapidly addressing the world's most vexing challenges in national security and health. Our 47,000 employees collaborate to create smarter technology solutions for customers in these critical markets.