Sr. Information Systems Security Engineer

Leidos Inc
Reston, VA, United States
$101.4K-$183.3K a year
Full-time

Description

This role provides information security solutions compliant with the Risk Management Framework (RMF) and ICD 503 Security Accreditation control as part of an Agile team.

Responsibilities include collaborating with the customer security organization to ensure RMF processes are followed, policy is translated to operational procedures, proper tools are leveraged in the DevSecOps CI / CD Pipeline, verification that security policy and procedures are enforced, and some work generating body of evidence (BOE) information for security approval processes.

This role installs and maintains security scanning tools, performs security scans, reviews scan results, and supports information system security officers (ISSOs).

Flexible cross-training to also provide systems engineering, software development, training, security, and testing is also desired.

Primary Responsibilities :

This role is responsible for protecting the organization's information and information systems from unauthorized access, use, disclosure, disruption, modification, perusal, inspection, recording and destruction.

Duties include managing and enforcing security strategies and policies within established guidelines and assisting in the generation of BOE information.

Cyber-Security and Compliance & Risk Management.

Identify and define system security requirements.

Design computer security architecture and develop detailed cyber security designs.

Prepare and document standard operating procedures and protocols.

Configure and troubleshoot security infrastructure devices.

Develop technical solutions and new security tools to help mitigate security vulnerabilities and automate repeatable tasks in a consultative role.

Basic Qualifications :

Requires BS degree and 8 or more years of prior relevant experience.

5 years of system engineering or system administration

Experience coordinating with RMF stakeholders (ISSMs, SCAs, etc.) in testing, documenting, and achieving accreditation of systems throughout the development process, and achieving operational acceptance.

Conducts vulnerability routine scanning, provides formal and informal reports to IT team and tracks remediation efforts

Proactively identify security flaws and vulnerabilities.

Continuously review security bulletins and related news; stay apprised of current threats and trends.

Track common vulnerabilities and exposures (CVE) based security threats and map to internal controls and remediation plans.

Audit systems for secure configuration.

Investigate and respond to cyber security incidents (system and / or network breaches, malware attacks) and implement forensic investigations.

System & network security monitoring with security information event management tools.

Participate in data and root cause analysis for each service impacting incident with all possible corrective actions for improvement.

Performs other duties as assigned.

At least 2 Certifications : CISSP, Splunk, Network+, Security+, OSCP, Windows, Cisco, CEH, Juniper, RHEL

Candidate must have an active TS / SCI with polygraph, to be considered.

Preferred Qualifications :

Experiences with at least one vulnerability scanning tool (AWS Inspector, Rapid 7 Nexpose, AppDetective, WebInspect, OWASP etc.)

Dynamic Application Security Testing (DAST) and Static Application Security Testing (SAST)

Familiar with SEIM and Cloud Computing Technologies (AWS)

Experience with Agile Software Development

Experienced with HBSS, IDS / IPS, VPNs, DISA STIGs

Experience with RHEL

Experience with system health tools (AppDynamics, SolarWinds)

Knowledge of potential attack vectors such as XSS, injection, hijacking, social engineering

Splunk end user experience with knowledge of how to create Splunk Dashboards are a plus

OS patching experience

Linux command line experience

Microsoft Windows experience

Automation experience

CABARESTON

Original Posting Date :

2024-09-26

While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range :

Pay Range $101,400.00 - $183,300.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

3 days ago
Related jobs
Promoted
Capital One
McLean, Virginia
Remote

Sr Distinguished Engineer, Generative AI Systems - (Remote- Eligible). Sr Distinguished Engineer, Generative AI Systems. We are looking for an experienced Senior Distinguished Engineer, AI Systems, to help us build the foundations of our enterprise AI Capabilities. Experience architecting cloud syst...

Promoted
The Aerospace Corporation
Chantilly, Virginia

Systems Cost Engineer to join a diverse, innovative, and highly productive team of cost and schedule professionals. CASA applies cost, schedule, and economic engineering expertise to improve customer cost and schedule related decision making and collects lessons learned from a wide variety of progra...

Promoted
Allegient Defense
Reston, Virginia

Allegient Defense (DBA BCS Allegient) provides technically-oriented services from program management to advanced systems integration and engineering. Systems Engineer for one of our DoD clients. Lead the systems engineering definition/executing activities within a project. Security Requirements: Act...

Next Step Systems – Recruiters for Information Technology Jobs Top IT Recruiting Firm
Herndon, Virginia

Data Engineer, TS/SCI with a Full Scope Polygraph Security Clearance Required, Herndon, VA. The ideal Data Engineer will have expertise in data engineering and modeling using tools such as NiFi, Python, and PySpark and some cloud skills. The qualified Data Engineer must have an active TS/SCI with a ...

Amazon Web Services, Inc.
Merrifield, Virginia

Amazon Web Services is looking for world class software developers with experience in machine learning to join the Security Innovation team in Global Services Security (GSS). In this role, you are a passionate, talented, and inventive Software Development Engineer (SDE) with strong experience in ML,...

General Dynamics Information Technology
Springfield, Virginia

The Systems Engineer designs and defines system architecture for new or existing computer systems. As a Systems Engineer, Mid you will help ensure today is safe and tomorrow is smarter. Our work depends on a TS/SCI cleared Systems Engineer, Mid joining our team to support our intelligence customer i...

Guidehouse
McLean, Virginia
Remote

Accountable for ensuring the day-to-day operations of Guidehouse Information Protection security systems, maintaining, and protecting Guidehouse and Client data within Azure and AWS to the NIST SP 800-171, NIST SP 800-53, ISO 27001, ISO 20000, HIPAA, and HITRUST standards, and managing Guidehouse an...

Amazon Development Center U.S., Inc.
DHS, VA, United States

Amazon is looking for highly motivated Senior Systems Development Engineers who can balance the day-to-day operations of AWS’ software systems with long-term software engineering to reduce operational toil. We need engineers who enjoy constantly learning and diving deep into the wide range of system...

Next Step Systems – Recruiters for Information Technology Jobs Top IT Recruiting Firm
Springfield, Virginia

The qualified Analytics and Visual Operations Specialist must have an active TS/SCI security clearance and be able to obtain a CI Polygraph security clearance. Atlanta Georgia IT Recruiters, Austin TX IT Recruiters, Baltimore Executive Staffing, Boston IT Recruiters, Charlotte IT Recruiters, Chicago...

WarCollar Industries
Chantilly, Virginia

The Information Systems Security Engineer is vital position that informs and advises all levels of the information security process when developing and certifying systems for secure operations on the customer's network. The ISSE first must determine the client’s security requirements and then take m...