Sr. Information Systems Security Engineer

Leidos Inc
Reston, VA, United States
$101.4K-$183.3K a year
Full-time

Description

This role provides information security solutions compliant with the Risk Management Framework (RMF) and ICD 503 Security Accreditation control as part of an Agile team.

Responsibilities include collaborating with the customer security organization to ensure RMF processes are followed, policy is translated to operational procedures, proper tools are leveraged in the DevSecOps CI / CD Pipeline, verification that security policy and procedures are enforced, and some work generating body of evidence (BOE) information for security approval processes.

This role installs and maintains security scanning tools, performs security scans, reviews scan results, and supports information system security officers (ISSOs).

Flexible cross-training to also provide systems engineering, software development, training, security, and testing is also desired.

Primary Responsibilities :

This role is responsible for protecting the organization's information and information systems from unauthorized access, use, disclosure, disruption, modification, perusal, inspection, recording and destruction.

Duties include managing and enforcing security strategies and policies within established guidelines and assisting in the generation of BOE information.

Cyber-Security and Compliance & Risk Management.

Identify and define system security requirements.

Design computer security architecture and develop detailed cyber security designs.

Prepare and document standard operating procedures and protocols.

Configure and troubleshoot security infrastructure devices.

Develop technical solutions and new security tools to help mitigate security vulnerabilities and automate repeatable tasks in a consultative role.

Basic Qualifications :

Requires BS degree and 8 or more years of prior relevant experience.

5 years of system engineering or system administration

Experience coordinating with RMF stakeholders (ISSMs, SCAs, etc.) in testing, documenting, and achieving accreditation of systems throughout the development process, and achieving operational acceptance.

Conducts vulnerability routine scanning, provides formal and informal reports to IT team and tracks remediation efforts

Proactively identify security flaws and vulnerabilities.

Continuously review security bulletins and related news; stay apprised of current threats and trends.

Track common vulnerabilities and exposures (CVE) based security threats and map to internal controls and remediation plans.

Audit systems for secure configuration.

Investigate and respond to cyber security incidents (system and / or network breaches, malware attacks) and implement forensic investigations.

System & network security monitoring with security information event management tools.

Participate in data and root cause analysis for each service impacting incident with all possible corrective actions for improvement.

Performs other duties as assigned.

At least 2 Certifications : CISSP, Splunk, Network+, Security+, OSCP, Windows, Cisco, CEH, Juniper, RHEL

Candidate must have an active TS / SCI with polygraph, to be considered.

Preferred Qualifications :

Experiences with at least one vulnerability scanning tool (AWS Inspector, Rapid 7 Nexpose, AppDetective, WebInspect, OWASP etc.)

Dynamic Application Security Testing (DAST) and Static Application Security Testing (SAST)

Familiar with SEIM and Cloud Computing Technologies (AWS)

Experience with Agile Software Development

Experienced with HBSS, IDS / IPS, VPNs, DISA STIGs

Experience with RHEL

Experience with system health tools (AppDynamics, SolarWinds)

Knowledge of potential attack vectors such as XSS, injection, hijacking, social engineering

Splunk end user experience with knowledge of how to create Splunk Dashboards are a plus

OS patching experience

Linux command line experience

Microsoft Windows experience

Automation experience

CABARESTON

Original Posting Date :

2024-09-26

While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range :

Pay Range $101,400.00 - $183,300.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

3 days ago
Related jobs
Promoted
Arcfield
Chantilly, Virginia

Arcfield is hiring a Senior GEOINT Systems Engineer to lead a dynamic team providing end-to-end Systems Engineering and Integration (SE&I) services to a National Customer. Strong Systems Engineering background with a focus on core systems engineering processes in support of end-to-end mission and se...

Promoted
Sciolex Corporation
Chantilly, Virginia

Provide subject matter expertise and agile best practices to our team; as well as perform the following functions as a SIGINT Systems Engineer, by using a holistic approach and providing end-to-end systems engineering throughout our systems’ lifecycle:. You will also be a technical member of a dynam...

Promoted
Piper Companies
McLean, Virginia

Cloud Security Engineer include:. Collaborate with engineering team to provide unique engineering solutions. Cloud Security Engineer include:. Cloud Security Engineer includes:. ...

Promoted
CACI
Chantilly, Virginia

Computer security experience: systems administration, network security, network recon, security products administration. Technical and analytic support, including software reverse engineering, network reverse engineering, and systems architecture. Cyber Operational Systems Engineer. Candidate must b...

Promoted
The Aerospace Corporation
Chantilly, Virginia

The Systems Engineering Division (SED) provides unmatched experience in systems engineering to the U. Systems of Systems Engineer - Engineering Specialist. Strong knowledge of systems-of-systems (SoS) engineering and enterprise architecting and model-based system engineering (MBSE) discipline (e. Sy...

Promoted
Northrop Grumman
Dulles, Virginia

At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. You will interface with customers, vendors, and with NGSC Manufacturing, Integration & Test, and Engineering organizat...

Promoted
Two Six Technologies
Vienna, Virginia

The successful candidate will have requisite cyber security experience with methods and tools used to improve the security posture of critical systems such as identifying risks, vulnerabilities, anomalies, patching, auditing, automation, security hardening, best practices, and evaluating system chan...

Promoted
booz allen hamilton
Reston, Virginia

Information Systems Security Officer. Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; Top Secret clearance is required. The following information aims to provide potential candidates with a better und...

Promoted
Redtracetech
Fairfax, Virginia

Senior Information Systems Security Officer (ISSO) - (TS required, eligible for SCI)**. Services to support IS Security performed by the Senior Information System Security Officer (ISSO) at a minimum, shall consist of to the following activities:. Provide baseline security controls to the system own...

Promoted
Capital One
VA, United States
Remote

Sr Distinguished Engineer, Generative AI Systems - (Remote- Eligible). Sr Distinguished Engineer, Generative AI Systems. We are looking for an experienced Senior Distinguished Engineer, AI Systems, to help us build the foundations of our enterprise AI Capabilities. Experience architecting cloud syst...