Job was saved successfully.
Job was removed from Saved Jobs.

Job Details


Leidos

Information Security Analyst ( R-00057809 )

Law Enforcement and Security

Information Security

Yearly

No

Alexandria, Virginia, United States

Description

Job Description:

The Defense Group of Leidos has an exciting opportunity for an Information Security Analyst to support efforts for the Army Cloud Common Shared Service Provider (CCSSP) contract located in the Northern Virginia/National Capital Region. The InfoSec Security Engineer is responsible for providing technical and programmatic Information Assurance Services to customers in support of network and information security systems. The role designs, develops and implements security requirements as part of an Agile team. Assists the ISSOs with preparing documentation for RMF (Risk Management Framework). Responsible for developing test procedures and contingency plans as part of the assessment and authorization (A&A) process. Conducts/Perform complex risk and vulnerability assessments including development of risk mitigation strategies. Recommends system enhancements to improve security deficiencies. Develops, tests, and integrates/automates security tools. Assess system configurations and installs security tools, scans systems to determine compliancy and report results and evaluates products and various aspects of system administration. Conducts security program audits and develops solutions to minimize identified risks. Aids in computer incident investigations.

Primary Responsibilities

  • Serve as the principal Security Engineer to the information system owner (Deliver Owners) and the ISSO on all matters (technical and otherwise) involving the security of the information system.
  • Coordinate with the team’s Teams Tech Leads to provide technical direction and guidance to software developers and systems administrators for security related development and engineering tasks.
  • Assist the ISSO in gathering, preparing, and maintaining the information systems Body of Evidence (Systems Security Plans (SSP)) and other security related documentation.
  • Support Achievement of Authority to Operate (ATO) through development and execution of security policies, plans, and procedures. Initiate creation of A&A packages to support receipt of Authorizations to Operate (ATOs), collaborate with Engineers to gather required information for A&A packages, and update A&A packages as required.
  • Develop and implement Continuous Monitoring processes.
  • Assist project team with creating/maintaining and running automation scripts or manual steps for securely configuring systems, testing and ensuring cyber compliance of all systems..
  • Propose mitigation strategies for vulnerabilities identified in the system.
  • Investigate and mitigate cyber security incidents.
  • Verify and maintain security and technical configurations: Interpret and propose technical solutions for security requirements/controls.
  • Assess the impacts on system modifications and technological advances
  • Manage and review security logs and taking required actions.
  • Design computer security architecture and develop detailed cyber security design.
  • Prepare and document standard operating procedures and protocols.
  • Participate in the change management process.

Basic Qualifications

  • Bachelors’ degree in Computer Science, Information Systems, Cyber Security, or related field, or equivalent experience.
  • Minimum 8 years of prior relevant experience managing NIST RMF and DoD cyber security policies in accordance with program cybersecurity assessment and authorization (A&A) implementation.
  • Minimum of five years of experience (at least three year of experience in the past five years) managing a cyber-team in a DOD environment.
  • Documented experience information assurance and cyber security engineering.
  • Can work independently of direct supervision.
  • Ability to build strong customer relationships.
  • Experience with information assurance and cyber security engineering.
  • Experience with the Risk Management Framework (RMF) and ICD 503 Security Accreditation processes.
  • Have an active DoD Secret clearance.
  • Must have a DoD 8570 IAT Level II (or Level III) Certification (e.g. Sec+ CE).

Preferred Qualifications

  • Experienced with various security tools and processes such as Splunk, Tenable Security, Fortify.
  • Experience with the NIST Risk Management Framework (RMF).
  • Experience with operation of systems to an Amazon Web Services (AWS) and Azure cloud environment.
  • A professional background in Systems Engineering / Cloud Architecture / Software Development.
  • Experience with Cloud Computing Technologies.
  • Experience with Agile Software Development.
  • AWS/Azure Certifications.
  • Experience with scripting languages (Python, Power Shell).
  • Motivated self-starter with strong written and verbal communication skills, and the ability to create complex technical reports on analytic findings.

External Referral Bonus:Ineligible

External Referral Bonus $:

Potential for Telework:Yes, 100%

Clearance Level Required:Secret

Travel:Yes, 10% of the time

Scheduled Weekly Hours:40

Shift:Day

Requisition Category:Professional

Job Family:Information Assurance

Pay Range:

#Remote