Description
Job Description:
Leidos is looking for a full-time Senior Security Engineer to join its F-16 Aircraft Structural Integrity Program (ASIP).
Candidate will primarily support the F-16 ASIP Portal and PERFORMS Assessment and Authorization (A&A) process using Risk Management Framework (RMF) design. Candidate must be a self-starter with the ability to work independently with little supervision. Candidate must have good communication and interpersonal skills with the ability to work effectively in a team environment and communicate directly with the customer. Candidate will support the F-16 SPO at Hill AFB, UT, the Leidos Program Manager, and the Information System Security Officer (ISSO).
Responsibilities:
- Support the F-16 ASIP Portal and PERFORMS systems in following United States Air Force (USAF) A4 Logistics’ Assessment and Authorization (A&A) processes. This includes:
- Understanding, following, implementing USAF/A4 Chief Information Officer (CIO) Assessment and Authorization Guide processes
- Running Static Application Security Testing (SAST) Software Scans on developed code
- Providing security analysis feedback for STAT scan security vulnerabilities
- Review the code with development team lead to determine the state of STAT vulnerability scan results
- Tracking code vulnerabilities and participate in creating work tickets
- Setup Security Impact Assessment (SIA) meetings with all stakeholders
- Creating Security Test Plan (STP) for each production release for all upgrades to software, hardware, and development code releases
- Creating Mission Risk Assessment Brief (MRAB) in MS PowerPoint for the Authorizing Official Designated representative (AODR) to receive the USAF/A4 process approval
- Work closely with development lead and security lead to streamline USAF/A4 processes and compliances
- Support the F-16 ASIP Portal system in obtaining the Assessment and Authorization (A&A) Authority to Operate (ATO). This includes:
- Evaluating and entering security control assessments information into Enterprise Mission Assurance Support Service (eMASS) according to Risk Management Framework (RMF) requirements
- Updating Information Technology Investment Portfolio Suite (ITIPS) with budget and IT compliance information
- Evaluating weekly ACAS Scans and provide analysis and tracking for all priority I, II, III severity items
- Providing Excel tools to support efficient and effective reporting of security compliance information
- Support the Processing Evaluating and Reporting of Force Management Data Software (PERFORMS) system in obtaining the A&A ATO. This includes:
- Evaluating and entering security control assessments information into eMASS according to RMF requirements
- Evaluating and entering security control assessments information into Enterprise Mission Assurance Support Service (eMASS) according to Risk Management Framework (RMF) requirements for initial submission and all subsequent annual reviews and submissions
- Updating ITIPS with budget and IT compliance information
- Providing Excel tools to support efficient and effective reporting of security compliance information
- Recommend design changes and enhancements to applications and systems based on review of associated security controls and Security Technical Information Guides (STIGs) to ensure maximum security
- Collaborate with product managers, customers, and other team members to specify requirements, communicate status of system security related requirements and issues
- Facilitate the documenting of program logic, design, and system flow
- Recommend solutions to security related software design or hardware configuration issues
- Contribute to the preparation and presentation of documentation and system/software architecture
- Work in a team environment to accomplish tasks
- Recommend changes affecting short-term team growth and success
- Plan and lead on significant projects to completion
- Function as a technical expert across multiple project assignments
- Assist in providing updates for the Monthly Status Reports to Program Manager
Required Education and Certifications:
- B. S. Degree in computer science, information systems, or other IT discipline
Required Minimum Skills and Experience:
- 8+ years of experience
- Experience in C# programming language and development
- Experience in Static Application Security Testing (SAST) Software
- Experience in software ticket tracking systems
- Experience in Web Application security risk
- Experience in System architecture Security risk
- Experience with Security controls and Security Technical Information Guide (STIG), identification, review, reconciliation and Plan of Action and Milestone (POA&M) requirements and processes
- Experience in the preparation of technical documentation and procedures
Desired Skills and Experience:
- Current active Security+ certification
- Experience with Cloud migration and associated security and risk mitigation is highly desired
- Experience with Visual Basic, JavaScript, Perl and PL/SQL a plus
- Experience with Agile Methodology
- Current Secret Clearance a plus
Security Clearance Requirements:
- Must be able to pass a background check or obtain a DoD Secret Clearance
- U. S. Citizen
Pay Range:
Pay Range $94,250.00 - $145,000.00 - $195,750.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
#Remote
About Leidos
Leidos is a Fortune 500® technology, engineering, and science solutions and services leader working to solve the world’s toughest challenges in the defense, intelligence, civil, and health markets. The company’s 46,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Virginia, Leidos reported annual revenues of approximately $14.4 billion for the fiscal year ended December 30, 2022. For more information, visit www.Leidos.com.
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at [email protected].
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Commitment to Diversity
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.