The mission of the DHS Chief Information Security Officer Directorate (DHS CISOD) is to support the Department’s implementation of all applicable regulatory requirements including the Federal Information Security Modernization Act of 2014 (FISMA), relevant Office of Management and Budget (OMB) Circulars, Executive Orders, Federal laws, directives, policies, and regulations. The DHS CISOD’s mission is to also provide the Department of Homeland Security (DHS) a secure and trusted computing environment. The DHS CISOD assists in ensuring Department compliance with information security requirements. Information security is an essential business function, critical to enabling DHS to conduct its operations and deliver service to the public.
Leidos has a critical need for an Enterprise Risk Reporting Specialist
Duties include assisting with program planning and execution Cyber Risk and Reporting Analysis for FISMA Reporting. Knowledge of NIST 800 series, RMF and CSAM are needed to be successful in this role.
- Directs and manages annual FISMA reporting, and coordinates Program Reviews with the OIG and the Senior Agency Official for Privacy (SAOP), in accordance with OMB guidance.
- Provide research and development support of data analytic and data management technologies including those associated with collecting, analyzing, parsing, and reporting large volumes of data that may support the DHS CISOD FISMA Reporting team, as well as DHS Component FISMA Reporting teams.
- Generate the draft and final versions of the annual FISMA Report and memos for delivery to senior DHS Management, Congress, and OMB.
- Generate draft and final versions of three (3) formal quarterly FISMA reports for the 1st 3 quarters of each year for delivery to senior DHS Management.
- Generate trending and ad-hoc reports as requested. Reporting includes extracting data from the OCISO databases, designing, developing, and implementing automated reports. Data being reported may represent subsets of the overall Performance reporting or new/unique data sets based on entire compliance data stored within the supporting tools.
- Contractor shall validate the Components and non-Components data, prepare the data call and the consolidation sheet and adjudicate Components justifications for discrepancies
- Update the data call in the tools (SharePoint, SNOW etc) to reflect the most recent OMB and Federal CIO FISMA metrics.
- Contribute to one-on-one meetings through validation POCs who are also will be in charge of the executive order sections.
- Develop, update, maintain, and report on cybersecurity metrics to measure the effectiveness of the DHS CISO’s Cybersecurity Program.
- Develop Governance, Risk, and Compliance Dashboards to leverage centralized program and system data to support analytics for managing and reporting security posture.
- The contractor shall actively develop and support in the compliance monitoring/reporting activities as related to DHS FISMA and other official reporting (both internal and external to DHS (ex. Cyberscope reporting).
- Must be able to obtain a DHS Security Clearance.
- Bachelor’s degree with 10 or more years’ experience in A&A with RMF, DCID 6/3, ICD 503, and/or NIST Framework; additional years of related work experience may be considered in lieu of degree
- Three (3) or more years’ experience in Project Management
- Experience with DHS, DoDIIS, and IC tools, systems, and reporting mechanisms/requirements for A&A..
- Practical knowledge of IC, DoD, and DHS Cybersecurity initiatives, and secure information/networking technologies.
- Demonstrated experience as an ISSO, ISSE, Package Submission Officer (PSO), Validators, and /or Security Controls Assessor (SCA)
- Experience shepherding projects through the RMF process in XACTA and EMASS
- Ensure compliance with DHS Standards and procedures.
- Good familiarity with and understanding of all relevant government and agency policies and procedures to ensure system documentation is compliance with relevant guidelines, e.g., FedRAMP, RMF, FISMA, FIPS-II, NIST, etc.
- U.S. Citizenship is required.
Pay Range:Pay Range $97,500.00 - $150,000.00 - $202,500.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Leidos is a Fortune 500® technology, engineering, and science solutions and services leader working to solve the world’s toughest challenges in the defense, intelligence, civil, and health markets. The company’s 46,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Virginia, Leidos reported annual revenues of approximately $14.4 billion for the fiscal year ended December 30, 2022. For more information, visit www.Leidos.com.
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at [email protected].
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Commitment to Diversity
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.