Leidos is seeking an Information Security Engineer for the ESA V program. The ESA V Security team supports multiple DOJ components (ATF, JMD, ATR). This position will primarily support the DOJ Alcohol Tobacco Firearms and Explosives (ATF) component.
This position is for an Information Security Engineer focused on managing the McAfee ePolicy Orchestrator server and console as well as security compliance reviews. The Information Security Engineer will be focused on daily ePO deployments, operations and maintenance of McAfee solutions in the customer environment. This includes but is not limited to annual audits (e.g. OMB, A123, FISMA) and maintenance of records in the compliance management system (e.g. POAMs, waivers, registered assets). The candidate will also mentor a Junior Information Security Engineer on how to manage and operate McAfee ePolicy Orchestrator.
The candidate may also be involved in other security assessment activities including but not limited to: Risk Management Framework elements, assessment of security controls, and assessment of new functions. The candidate may act as the interface between auditors and system subject matter experts. The candidate should understand how to document system compliance with government security controls (e.g. 800-53, FISMA). The candidate may also support Security Operations, e.g. conducting security scans.
Clear verbal and written communication skills are essential. This position also requires good project planning skills to identify how to meet schedules, maintain and update security SOP’s, identify dependencies, and identify risks and workarounds.
This position requires a security investigation completed by the ATF and other federal components to permit access to customer-sensitive information.
- Bachelor’s degree with 8+ years relevant work experience with managing McAfee ePolicy Orchestrator server and console. Four additional years of experience may be considered in lieu of a degree.
- Experience creating and troubleshooting McAfee ePolicy Orchestrator policy configurations
- Experience with supporting assessment of IT systems compliance with Federal IT Security standards (e.g. NIST 800-53, FISMA)
- Ability to respond to security audits and compliance assessments including decomposing auditor requests to actionable items, compiling and presenting security audit artifacts
- Ability to evaluate IT system compliance with government and commercial security practices (e.g. DISA STIGS, SANS Top 25)
- General knowledge of enterprise scale IT systems, architectures and components (servers, and virtualization, networking, security appliances, SAAS, IAAS) particularly the system integration challenges balancing secure operations with operational need.
- Solid communication and documentation skills
- Candidate selected will be subject to a Government Public Trust security investigation and must meet eligibility requirements for access to the customer’s information.
- Selected individual cannot start the assignment until the required security clearance is granted by the customer.
- US Citizenship is required.
- Experience with McAfee ePolicy Orchestrator (ePO)
- Reviewing and Responding to antivirus alerts
- Creating custom reports
- Installing and updating ePO agents and dat files
- Configuring ePO policies for endpoint systems and servers (On-perm and in the Cloud)
- McAfee ePolicy Orchestrator Certification
- Past experience with the Department of Justice
- DOJ or DOD Active Clearance
- Network knowledge and experience
- ITSM knowledge and experience, particularly with ServiceNow
- Experience with DOJ compliance environment and related tools (CSAM, Tenable Security Center, and BigFix)
- Ability to review, compile and update artifacts for system accreditation packages
- Direct experience or solid familiarity with cloud computing and applicable security practices (e.g. FedRAMP, SAAS, IAAS)
- Ability to recognize security risks, document risk, and clearly communicate findings and recommendations.
- Experience supporting Incident Response events
- Experience supporting review and certification of systems and applications
External Referral Bonus:Ineligible
External Referral Bonus $:
Potential for Telework:No
Clearance Level Required:None
Scheduled Weekly Hours:40
Job Family:Information Assurance
Leidos is a Fortune 500® information technology, engineering, and science solutions and services leader working to solve the world’s toughest challenges in the defense, intelligence, homeland security, civil, and health markets. The company’s 40,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Virginia, Leidos reported annual revenues of approximately $12.30 billion for the fiscal year ended January 1, 2021. For more information, visit www.Leidos.com.
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.
Securing Your Data
Leidos will never ask you to provide payment-related information at any part of the employment application process. And Leidos will communicate with you only through emails that are sent from a Leidos.com email address. If you receive an email purporting to be from Leidos that asks for payment-related information or any other personal information, please report the email to [email protected].
Commitment to Diversity
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.