The Intelligence Group at Leidos is looking for a Cyber Security Senior Information Security Analyst to work at our customer site in Stennis, MS or Reston, VA for a near future award. The Senior Information Security Analyst is responsible for ensuring IT compliance with security policies, guidance, and regulations while adhering to security best practices. This position will monitor, detect, and respond to cyber security events, while providing technical leadership to engineer and build secure computing platforms within the DHS hybrid computing environment (HCE).
We are excited to start a new effort supporting a federal agency’s datacenter optimization and modernization. Upon award, we will provide seamless support while transforming the service management to the most modern frameworks, standards, and methodologies.
The successful candidate will report directly to the Security Manager in executing a large-scale, several billion dollar effort, and enterprise contract. The Senior Information Security Analyst shall interface with DHS DCCO’s COR who will interface with DHS officials on all cybersecurity matters, to include physical, personnel, and protection of all sensitive documents.
As the Senior Information Security Analyst, you are responsible for maintaining computer and information security incident, damage and threat assessment programs. Duties include investigating computer and information security incidents to determine extent of compromise to information and automated information systems, providing computer forensic and intrusion support to high technology investigations in the form of computer evidence seizure, computer forensic analysis, data recovery, and network assessments, researching and maintaining proficiency in tools, techniques, countermeasures, and trends in computer network vulnerabilities, data hiding and network security and encryption. In our client’s Hybrid Computing Environment with Data Center, Cloud Service Providers, and remote Data Centers call Co-Location sites will require designing, developing or recommending integrated system solutions ensuring proprietary/confidential data and systems are protected, participating with the client in the strategic design process to translate security and business requirements into technical designs, and configuring and validating secure systems, testing security products/systems to detect computer and information security weakness. Some of the duties entail:
- Responsible for evaluating current processes and procedures for opportunities to enhance and improve the organization's security posture and services and ensuring approved processes and procedures are followed through review and audit activities. Lastly, the person selected will be responsible for identifying and establishing metrics to measure the effectiveness of the Security Monitoring and Incident Response programs.
- Deploying, configuring, and integrating IT security technologies to enhance the HCE security posture.
- Identifying, analyzing, and assessing technical and operational vulnerabilities, emerging technologies, and risks to HCE computing environments.
- Analyzing security logs and identifying/investigating potential vulnerabilities and malicious activity with computer systems.
- Executing and reviewing IT security vulnerability and compliance scans and assessments.
- Working with system administrators to develop risk mitigation strategies and implement corrective security controls and solutions.
- Providing continuous security monitoring, analysis, and trending of security log data.
- Providing Tier 3 technical support for endpoint, continuous monitoring, and privileged account management security tools.
- Maintaining the IT security posture of operating system templates (gold/baseline images) through monthly security patching and compliance updates.
- Performing incident response activities to include initial examination and triage, declaring events/incidents, creating incident cases, gathering evidence, tracking, and updating incident statuses, and identifying additional action items as related to security events.
- Documenting security requirements, procedures, and processes as required.
- Conducting penetration tests on hosted systems to validate resiliency and identify vulnerabilities.
- Creating trouble tickets as a result of security scans, assessments, and events.
- Makes recommendations based on trend analysis for enhancements to software and hardware solutions to enhance customer experience.
- Performs security reviews, identify gaps in security architecture, and develop a security risk management plan.
- Properly documents all systems security implementation, operations, and maintenance activities and update as necessary.
Leadership & Talent Management:
* Leads from 1 or more personnel supporting engineering activities
- Education and Experience:
- Master’s degree or higher in Information Technology, Computer Science, Business Administration Science, Mathematics or Engineering
- 15+ Years of IT Experience, 8 of which are in Cybersecurity Management.
- Certified Information Systems Security Professional (CISSP) and Certified Cloud Security Professional (CCSP)
- In lieu of CISSP and CCSP, Global Information Assurance Certification (GIAC) and Cloud Security Automation
- Experience with Data Center management systems, applications, and data security
- Experience with cloud-based Data Center offerings such as IaaS, SaaS, PaaS
- Understanding of private and hybrid cloud architectures and technologies and Federal Risk and Authorization Management Program (FedRAMP)
- Preferred Certifications:
- ITILv4 Foundation, CISSP, CISM, CCSP,
External Referral Bonus:Eligible
External Referral Bonus $:5000
Potential for Telework:No
Clearance Level Required:Public Trust
Scheduled Weekly Hours:40
Job Family:Information Assurance
Please note that effective October 1, to enter Leidos facilities in the U.S. and to attend Leidos business events outside of our facilities, employees, vendors, subcontractors, and visitors will be required to be vaccinated or maintain proof of a weekly negative COVID-19 test. In addition, we are receiving guidance from certain customers that onsite contractor personnel will need to be fully vaccinated or able to show negative COVID-19 test results to access facilities. If you are not vaccinated, please consider getting your COVID-19 vaccination as soon as possible.
Leidos is a Fortune 500® information technology, engineering, and science solutions and services leader working to solve the world’s toughest challenges in the defense, intelligence, civil, and health markets. The company’s 43,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Virginia, Leidos reported annual revenues of approximately $12.30 billion for the fiscal year ended January 1, 2021. For more information, visit www.Leidos.com.
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.
Securing Your Data
Leidos will never ask you to provide payment-related information at any part of the employment application process. And Leidos will communicate with you only through emails that are sent from a Leidos.com email address. If you receive an email purporting to be from Leidos that asks for payment-related information or any other personal information, please report the email to [email protected].
Commitment to Diversity
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.