To our valued Leidos candidates:

Coronavirus is on everyone's mind with the effects being felt around the world. The markets are volatile, and we're all concerned for the health and safety of our families, friends, and colleagues. Please know that we're taking all necessary measures to safeguard our employees, customers and the communities in which we live, including following all recommended best practices around social distancing.

With that in mind, in an abundance of caution, we are canceling all face to face career events, such as job fairs and open house events. In the coming days and weeks, we will be hosting career events virtually, using our online chat tools so that we may continue our hiring practice safely and securely. You can find available virtual career events at https://career-events.leidos.com.

We are using telephone meetings and online chats via Brazen to conduct interviews and hiring discussions, and we are offering options for video interviews so that you can have a virtual face to face meeting with your potential new leader. We do not conduct interviews or extend offers via text or chat based social media, such as WhatsApp or MySpace.

Leidos will never ask you to provide payment-related information at any part of the employment application process, nor will Leidos ever advance money as part of the hiring process. And Leidos will communicate with you only through emails that are generated by Leidos.com automated system. If you receive an email purporting to be from Leidos that asks for payment-related information or any other personal information, please report the email to Chris Scalia, Leidos’ Senior Vice President of Talent Acquisition, at [email protected].

As a company, as a country, as a world, we have confronted challenging moments before. We are confident that, guided by our values and the strength of our community as well as the commitment we have to the important work we do each day, we will find our way through this time together. We will do this with the care and concern for one another and the common good that defines. Please keep those impacted by the virus in your thoughts.

Close Window
Join our talent network

Job #: R-00035162
Location: Centennial, CO
Category: Information Assurance
Schedule (FT/PT): Full Time
Travel Required: Yes, 10% of the time
Shift: Day
Potential for Telework: Yes
Clearance Required: None
Referral Eligibility: Ineligible
Group: Civil

This job posting is no longer active.

Share: mail twitter linkedin

Description

Job Description:

Our team within the Integrated Missions Operation support Group at Leidos, in support of the United States Antarctic Program (USAP), currently has an opening for a Senior Information Assurance Security Analyst in Centennial, Colorado.

The Senior Information Assurance Security Analyst will serve as a senior member of the Leidos – Antarctic Support Contract (ASC) Information Security (InfoSec) team that is responsible for applying cybersecurity principles and best practices to proactively protect and maintain the confidentiality, integrity, and availability, of USAP data, information systems, and enterprise network. Personnel in this position must have an elevated level of trust, with access to sensitive and private information, which must be handled with integrity and respect in accordance with USAP policies and procedures.

The Senior Information Assurance Security Analyst will be responsible for coordination, oversight, execution and enhancement of consistent security practices for all information systems within the USAP. The Senior Information Assurance Security Analyst will apply the NIST Risk Management Framework (RMF) to ensure effective information security controls are documented and delivered to safeguard USAP business operations, prevent unauthorized system access, and to protect sensitive information.

This position leads analysis and assessment of compliance with security and privacy laws, regulations, guidance, and direction, including the Federal Information Security Management Act (FISMA); National Institute of Standards and Technology (NIST) guidance; Federal Information Processing Standards (FIPS); applicable Office of Management and Budget (OMB) memoranda; National Science Foundation (NSF); and United States Antarctic Program (USAP) policies and instructions.

Provides leadership and support for all security compliance initiatives, such as:

  • Manages and coordinates both external Office of Inspector General (OIG) and internal Security Controls Assessment (SCA) audits, and creation and delivery of audit artifacts.
  • Coordinates with Security Engineers, IT Operations teams and customers to develop and maintain the Plan of Actions and Milestones (POA&M), Acceptance of Risk (AOR) and other required security documentation, processes, and procedures.
  • Evaluates proposed enhancements and changes to the operational / business systems, and develops appropriate security requirements.
  • Develops privacy impact assessments, information categorization and sensitivity assessments, security test and evaluation assessments.
  • Ensures configuration control over Security Assessment and Authorization (SA&A) and Certification & Accreditation (C&A) packages.
  • Identifies and documents applicable security controls in the System Security Plan in accordance with NIST SP 800-53 rev 4, Security and Privacy Controls for Federal Information Systems and Organizations, and NIST SP 800-37, Risk Management Framework.
  • Conducts and documents security assessments to determine the effectives and compliance of planned and implemented security controls.
  • Performs systems security evaluations, audits, and server logging reviews to verify secure operations and recommends mitigation's and corrective actions.
  • Organizes and facilitates contingency planning and incident response exercises.
  • Supports Incident Response activities to mitigate damage, determine impact, document activities, and implement corrective actions.
  • Creates, publishes and manages content for the information security awareness and training program.
  • Develops and presents information security reports for stakeholders, customers and management based on Information Security operational metrics, security assessments and security reviews.
  • Researches and proposes emerging security technologies.

Required Qualifications:

  • Bachelor's degree (preferably in a technology related field) and 8 years' relevant experience. Additional years of experience and relevant certifications will be considered in lieu of degree.
  • Current Information Security certification(s) (e.g. CISM, CISSP, CISA, Security+)
  • Current general IT certification(s): (e.g., MCSE, RHCE, CCNA)

  • Experience in system vulnerability assessments and developing certification and accreditation packages. 

  • Experience with Federal Information Security Management Act (FISMA) requirements and National Institute of Standards and Technology (NIST) Risk Management Framework.

  • Experienced with Governance, Risk and Compliance (GRC) Tools.
  • Solid understanding and application of IT Infrastructure Library (ITIL).
  • Capable of managing project within an established project management framework.
  • Proficient in validating baseline security configurations and policies (e.g., DISA, CIS Benchmarks).
  • Understanding and application of the TCP/IP networking / OSI model.
  • Effective at interacting with compliance auditors and managing delivery of audit artifacts.
  • Solid written and verbal communication skills.

Experience with the following Technologies:

  • Governance, Risk and Compliance (GRC) tools
  • Patch and vulnerability management tools (e.g. Tenable Nessus)
  • Network routing and segmentation
  • Firewalls
  • Linux
  • Microsoft Windows
  • Active Directory Infrastructure
  • Group Policy
  • Antimalware tools
  • Public Key Infrastructure
  • Packet Capturing
  • Virtual Infrastructure
  • Backup Technologies
  • Cloud services (Azure, AWS, O365)

Deployment to Antarctica may be required at the discretion of management. The individual in the position must successfully complete the physical and dental examinations as required by the NSF for deploying to Antarctica. Failure to meet these requirements may result in withdrawal of employment offer or other employment action.

External Referral Bonus:

Ineligible

Potential for Telework:

Yes

Clearance Level Required:

None

Travel:

Yes, 10% of the time

Scheduled Weekly Hours:

40

Shift:

Day

Requisition Category:

Professional

Job Family:

Information Assurance

Leidos

Leidos is a Fortune 500® information technology, engineering, and science solutions and services leader working to solve the world's toughest challenges in the defense, intelligence, homeland security, civil, and health markets. The company's 33,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Virginia, Leidos reported annual revenues of approximately $10.19 billion for the fiscal year ended December 28, 2018. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.

Securing Your Data

Leidos will never ask you to provide payment-related information at any part of the employment application process. And Leidos will communicate with you only through emails that are sent from a Leidos.com email address. If you receive an email purporting to be from Leidos that asks for payment-related information or any other personal information, please report the email to [email protected].

Commitment to Diversity

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

This job posting is no longer active.

Talent Community

Join our Talent Community to create a profile, enabling a streamlined application process and to help our recruiters better understand your areas of expertise and interest.

Join our Talent Community