Description
Job Description:
Leidos is seeking a Region Information Assurance (IA) Director based in the Northern Virginia or Capital Metro area with opportunity to telework 2-3 days per week. The director will oversee classified processing at all Leidos locations in the respective region ensuring compliance with government and company policies and regulations throughout the system life cycle. The IA Director will partner with program leadership as the primary business area IA lead to ensure that the programs are able to meet all of its committed requirements in a safe and timely manner. The director will partner with senior business area leadership to share performance details and to coordinate strategies to address business areas information assurance needs. The position includes management of Information Assurance personnel and governance of classified information systems maintained at Leidos locations within the Southeast Region which includes, Arlington VA., Chesapeake, VA, Orlando, FL, and Long Beach, MS. The director will equip and develop the workforce to address the business, technical and compliance requirements. The director will partner with other region IA leaders, Security, and other relevant functions to solve IA challenges and to facilitate creation of common secure, scalable practices and procedures. The director will maintain a partnership with FSOs, CPOs and Security leadership which is critical for secure, and compliant system environments. The director is responsible for developing, communicating, and executing financial/budget plans. Excellent oral and written communication skills are critical to this position to convey information to peers, other functions and various levels of leadership. Information systems are supported by full-time and part time Information Assurance and IT professionals. The IA director will ensure implementation of standard security procedures in accordance with the NIST RMF, NISPOM/DAAPM and JSIG requirements. The director will be responsible for maintaining RMF Information System ATOs; conduct periodic reviews to ensure compliance with established policies and procedures; investigate, document and report incidents, as well as provide protective and corrective measures in response to such incidents.
The director is responsible for managing risks related to the use of processing, storing, or transmitting information to reduce or eliminate impact to confidentiality, integrity, or availability of information and information systems. The Director performs a wide variety of information assurance related tasks each with a compliance or risk-based focus. Operating objectives are aligned to Information Assurance strategy while effectively meeting compliance demands (regulatory and non-regulatory) and contract obligations. Duties may include but are not limited to; managing and enforcing security policies, training and educating end-users on proper security practices, conducting security and risk assessments using security frameworks (e.g., NIST, RMF, Common Criteria, etc.), mitigating risk via security controls, testing and evaluation to certify and accredit commercial security products, ensuring protection of data throughout its lifecycle, vulnerability management (scanning, assessment, reporting, and mitigation verification), business continuity and disaster recovery.
The work requires a high degree of responsibility for resources, and a need to frequently influence organizational or operational decisions made by leadership. Problems are highly complex and typically involve multiple function, projects, or customers.
Primary Responsibilities
- Requires deep management and leadership knowledge to lead cross-family project or program teams or manage across multiple families.
- Responsible for creating workforce and staffing plans for project/family to ensure efficient use of resources.
- Has hiring, firing, promotion and reward authority within own area, in accordance with organizational guidelines.
- Manages a project or family which includes multiple teams led by managers and/or supervisors.
- Directs activities that have significant impact on the achievement of results for the project/function.
- Conducts extensive investigation to understand the root cause of problems.
- Communicates with parties within and outside of own project/family and has responsibility for communicating with diverse parties external to the organization.
- Negotiates and influences others to understand and accept new concepts, practices and approaches.
- Responsible for creating workforce and staffing plans for project/family to ensure efficient use of resources.
- Ensure system support needs are met for certification & accreditation, system implementation, operation & maintenance, and IA compliance.
- Engineer, implement, and enforce technical and administrative security measures and processes to ensure all system achieve and maintain government compliance with directives outline in the JAFAN 6/3, JSIG, ICD 503, DODIIS, NIST RMF and NISPOM / DAAPM.
- Responsible for maintaining System Security Plans (SSP) and all documentation associated with Federal Information System Management Act
- Assist with providing security solutions to optimize performance and ensure security measures are optimized.
- Install, configure and maintain network equipment such as switches, end point protection, patches, firewalls and intrusion detection systems.
- Support the Information Systems Certification and Accreditation process as needed.
- Responsible for implementing and maintaining security policies and procedures
- Responsible for ensuring proper protection or corrective measures have been taken when an incident or vulnerability has been discovered.
- Responsible for responding to security incidents and for investigating and reporting security violations and incidents, as appropriate.
- Assist with maintaining the information security education program, including leading training as required.
- Develop and implement security practices and procedures.
- Oversee and direct employees supporting multiple business activities and their competing needs.
- Implement and test system security controls and conduct system vulnerabilities assessments using the NIST
- Implement security Content Automation Protocol (SCAP) or similar industry standard.
Basic Qualifications
- Requires a BA/BS or equivalent experience and 12+ years of prior relevant experience or masters with 10+ years or prior relevant experience.
- Generally, has 7+ years of experience supervising or leading teams or projects.
- Has mastery within a specific technical discipline/area or broad expertise across multiple related disciplines.
- Strong experience with information security, supporting processes and procedures.
- Strong writing and verbal communications skills.
- Candidates must have an active Top Secret clearance.
- CISSP or other DoD IAM level III certification is required
Preferred Qualifications
- Additional desired certifications include CCNA, CCSP, MCSE, and/or SANS GIAC.
- Experience with Windows and Linux Administration.
- PMP Certification
Pay Range:
About Leidos
Leidos is a Fortune 500® technology, engineering, and science solutions and services leader working to solve the world’s toughest challenges in the defense, intelligence, civil, and health markets. The company’s 45,000 employees support vital missions for government and commercial customers. Headquartered in Reston, Virginia, Leidos reported annual revenues of approximately $14.4 billion for the fiscal year ended December 30, 2022. For more information, visit www.Leidos.com.
Pay and Benefits
Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.
Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at [email protected].
If you believe you are the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.
Commitment to Diversity
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.