Description
At Leidos, everything we do is built on our commitment to do the right thing for our customers, our employees, and our communities. Learn more about the values and culture that are the foundations of our business. Our mission is to make the world safer, healthier, and more efficient through information technology, engineering, and science. We offer a robust benefits package including competitive salaries; 401K Retirement Plan; comprehensive medical, dental and vision coverage; flexible work schedule to allow for life/work balance; tuition reimbursement and more.
We are currently looking for a talented Cybersecurity Officer to work as part of the Leidos team which provides IT repair, maintenance, and operation services to ensure secure, reliable, and uninterrupted availability of Army North G2 Joint Mobile Intelligence Communications Systems (JMICS) and other command systems. Cybersecurity Officer will work with IA Certifiers to obtain and maintain Type Accreditation or ATO/ATC. You will work directly with customer Cyber team and JMICS System Administrators to ensure any changes to the JMICS systems are done in accordance with ICD-503 and NIST 800-53v4 standards. In this role, you will monitor programs for unauthorized vulnerabilities and work with the JMICS customer Cyber team and JMICS System Administrators to close them. Cybersecurity Officer will also work with the customer Cyber team to create and maintain all ATO/ATC and system security documentation.
In order to be considered for the position, you must hold an active Top Secret SCI (TS SCI) US government security clearance.
Primary Responsibilities
Create the Information Assurance documentation, polices, and procedures and ensure they are properly aligned to the standards set forth by DIA, DISA, DoD and Army Policy.
Verify the documentation is updated as required when Policies change.
Conduct routine system risk assessments. Risk assessments include full system scans using ACAS, SCC, Nessus or other tools, comparing system security settings to the applicable IAVA and STIG checklists as they are updated by DISA.
Work with JMICS System Administrators to create, maintain, and deploy JMICS Secure Baseline images.
Ensure the JMICS Secure Baseline is properly maintained and secured as required by DIA, DISA, DoD, and Army policy. Verify said baselines are adjusted, adapted, and upgraded to ensure that all unauthorized vulnerabilities found during the risk assessments are properly removed or mitigated to an acceptable level and to ensure the software used within the JMICS program is approved IAW the APL.
Conduct site level certification tests, site surveys, and risk analysis.
Perform Research and Development to ensure all new software and hardware to be deployed to the system meets all the security and configuration requirements that governs the JMICS Program.
Provide technological responses that prevent, detect, and respond to cyber threats and conduct research and analysis of actionable cyber threats requiring a rapid response.
Support all IA officer responsibilities in accordance with the Risk Management Framework (RMF) and the IC Directive (ICD) 503, IC Information Technology Systems Security, Risk Management, Certification, and Accreditation.
Provide IA support to the customer for classified activities, establish and maintain accreditation for all information systems or equipment operating within a classified environment, and develop and maintain System Security Plans outlining security operating procedures in accordance with all applicable DoD cybersecurity policies and standards.
Develop Cybersecurity Plan, Security Assessment Report (SAR), and Plan of Actions and Milestones (POA&M) in collaboration with the customer. These documents shall be incorporated with a Risk Assessment Report into a Security Authorization Package, which shall provide the Authorizing Official (AO) with the essential information needed to make a risk-based decision as to whether systems are able to meet the requirements for granting Authority to Operate (ATO) /Authority to Connect (ATC).
Provide day-to-day security management and oversight for classified activities performed by the program personnel, including maintaining sensitive documents, data, and equipment; performing routine data updates and required security patches; and providing monthly reports on security updates and patching activities.
Maintain continuous control and accountability of all hardware and software operated and maintained by the program personnel that is entered into and removed from classified facilities and shall provide an inventory report for all Communications Security (COMSEC), hardware, and software while in programs possession during working hours.
Assist the customer with developing sanitation and secure data extraction programs for all media, security incident cleanup plans, system certification testing plans, vulnerability testing, and protection measure procedures.
Provide System Vulnerability Assessment Reports.
Basic Qualifications
Bachelor's degree in a relevant field with at least eight to twelve years of related Information Assurance/Cybersecurity experience. Additional years of experience may be considered in lieu of a degree.
Specific experience with the following: Developing\maintaining IA Policy and Procedures, RMF A&A process, DISA STIGS, system vulnerability scanning software (ACAS\Nessus and SCC preferred, and other tools); Securing and Configuring Windows 10 and Server 2016/2019, system virtualization (VMWare preferred), vulnerability management and remediation, cybersecurity incident response and handling, and Change Management processes.
Active DoD 8140/8570.1-M IAT/IAM Baseline Certification – CISSP or higher
Active CompTIA Server+ or related (DoD 8570 Computing Environment Certification
Active TS SCI security clearance
Preferred Qualifications
Experience with Baseline Creation and Deployment (Sysprepping, SHB, Ghost, and virtual importing and exporting preferred.)
Experience maintaining, Windows 10, Windows Server 2016/2019, and RedHat Enterprise Linux platforms.
Experience with any of the following: Cisco Unified Communications, Powershell Scripting, VMware vSphere 6, Security Technical Implementation Guides (STIG) implementation, Vulnerability Scanning, Windows image creation and maintenance. Backup and restoration of virtual and physical machines, Group Policy creation, Active Directory, and/or DNS server.
Microsoft Certified IT Professional (MCITP), MCITP: Enterprise Administrator on Windows Server
Pay Range:
Pay Range $97,500.00 - $150,000.00 - $202,500.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
About Leidos
Leidos is a Fortune 500® technology, engineering, and science solutions and services leader working to solve the world’s toughest challenges in the defense, intelligence, civil, and health markets. The company’s 46,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Virginia, Leidos reported annual revenues of approximately $14.4 billion for the fiscal year ended December 30, 2022. For more information, visit www.Leidos.com.
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at [email protected].
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Commitment to Diversity
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.