Upon receiving the requisite funding, the Leidos Intelligence Group will have a career opening for a TS/SCI with poly cleared Information Systems Security Engineer (ISSE) III on our Leidos led prime contract in Columbia, MD.
This program is a Leidos sole sourced prime contract responsible for providing Information Assurance (IA) Architecture Analysis and Security Engineering Support for the implementation and fielding of the National Leadership Command Capability in support of Nuclear Command, Control, and Communications (NC3), Continuity of Government (COG), and Senior Leader communications.
Pending funding, the ISSE III will perform in a consultant like role providing technical knowledge, expertise and advice to our customer. They shall perform, or review, technical security assessments of computing environments to identify points of vulnerability, non-compliance with established IA standards and regulations and recommended mitigation strategies.
Primary responsibilities include but are not limited to the following:
- Validates and verifies system security requirements definitions and analysis and establishes system security design
- Designs, develops, implements and/or integrates IA and security systems and system components including those for networking, computing and enclave environment to include those with multiple enclaves and with differing data protection/classification requirements
- Builds IA into systems deployed to operation environments
- Assist architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of Agency security policy and enterprise solutions
- Supports the building of security architectures
- Enforces the design and implementation of trusted relations among external systems and architecture
- Assesses and mitigates system security threats/risk throughout the program life cycle
- Contributes to the security planning, assessment, risk analysis, risk management, certification and awareness activities for system and networking operations
- Reviews C&A documentation, providing feedback on completeness and compliance of its content
- Applies system security engineering expertise in one or more of the following:
- System security design process Engineering life cycle
- Information domain
- Cross domain solutions
- COTS and GOTS cryptographyIdentification, authentication and authorization
- Systems integration
- Risk management
- Intrusion detection
- Contingency planning
- Incident handling
- Configuration control
- Change management
- C&A process
- Principles of IA (confidentiality, integrity, non-repudiation, availability, and access control)
- Security testing
- Support security authorization activities in compliance with DoD Information System Certification and Accreditation Processes and DoD Information Assurance Certification and Accreditation Process (DIACAP) process, the NIST Risk Management Framework (RMF) process, and prescribed DoD business process for security engineering.
- TS/SCI with polygraph
- Bachelor of Science Degree from an accredited university in Computer Science, Information Assurance, Information Security System Engineering or related field with a minimum of 20 years of experience as an Information Systems Security Engineer (ISSE) on programs and/or contracts within the customer space. A Masters Degree in Computer Science, Information Assurance, Information Security System Engineering or related field reduces the experience requirement to 18 years.
- CISSP-ISSEP DoD approved 8570 baseline certification is a firm requirement
Additionally, the candidate must also possess the following knowledge, skills and abilities:
• Expertise in network technology and systems security engineering
• Experience in identifying, researching, characterizing, and documenting security weaknesses related to operating systems, software applications, firmware, network hardware components, as well as network architecture design and documented policies and procedures.
• Experience developing and documenting system security requirements and conducting requirements gap analysis.
• Knowledge of, and practical experience with the NIST Special Publications 800 Series, CNSSI 1253, and DoD 8500.
• Experience with network technologies and the ability to demonstrate knowledge of network protocols, communications systems and architectures.
• Should have significant hands on experience implementing security and/or network components, i.e. routers, firewalls, IPS, IDS, etc. Ability to work independently within a schedule and with little direction
• Strong writing skills.
• Confidence and ability to present briefing to senior level DoD officials in both prepared briefings and/or in ad hoc discussions
• Experience and understanding of active cyber defense techniques, products and architectures
• Experience or knowledge of cross domain device implementation Experience with virtual desktop environments
• Experience or knowledge of the Nuclear Command & Control (NC2) community
• Working knowledge of MS Visio to include development of detailed network diagrams