Assessment & Authorization Analyst

Leidos

Ashburn (VA)

On-site

USD 87,000 - 157,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
Paid leave
Retirement plan

Job summary

Leidos in Ashburn, VA is seeking an Assessment and Authorization Analyst to evaluate CBP information systems using RMF and related methodologies. You will assess security controls, document findings, and support authorization decisions.

The role requires a Bachelor’s or Master’s degree with substantial IT/security experience, US citizenship, and strong writing and analytical skills. You will work with cross‑functional teams to ensure compliant, secure deployments across the system lifecycle.

Qualifications

  • Bachelor’s degree with 4–8 years in IT/Security or Master’s with 2+ years.
  • US Citizenship required.
  • 1–3 years ISSO experience with federal information systems.
  • Strong writing, communication and analytical skills.
  • Knowledge of NIST SP 800-37 and RMF.
  • Willing to commute to Ashburn, VA up to 5 days/week.

Responsibilities

  • Conduct formal assessments and determine whether the system is authorized to operate.
  • Evaluate the system’s security posture and controls for effectiveness.
  • Document results and provide recommendations for security improvements.
  • Assist in creating System Security Plan, Security Assessment Report, and ATO.
  • Coordinate security across lifecycle and various IT areas.

Skills

ISSO experience
NIST RMF
Security policies
Communication skills
Information Assurance
Ability to commute

Education

Bachelor’s degree
Master’s Degree

Job description

Description
Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a US Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security services to CBP information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, cloud, security devices, servers and workstations. The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed security violations.

Description
Department of Homeland Security (DHS), Customs and Border Protection (CBP) Security Operations Center (SOC) is a US Government program responsible to prevent, identify, contain and eradicate cyber threats to CBP networks through monitoring, intrusion detection and protective security services to CBP information systems including local area networks/wide area networks (LAN/WAN), commercial Internet connection, public facing websites, wireless, mobile/cellular, cloud, security devices, servers and workstations. The CBP SOC is responsible for the overall security of CBP Enterprise-wide information systems, and collects, investigates, and reports any suspected and confirmed security violations.

Primary Responsibilities
The selected candidate will apply experience as an Assessment and Authorization Analyst by evaluating CBP Information Systems being introduced to the environment to determine if they meet the required security standards and are authorized to operate within the CBP network, using the NIST Risk Management Framework (RMF) or similar methodologies

The candidate will be responsible for evaluating key points in the System Lifecycle, such as before its deployment or during major updates. Responsibilities may include creating security documentation (e.g., System Security Plan, Security Assessment Report) and obtaining the final authorization to operate (ATO).The candidate should be able to provide assistance in collecting information and answering questions in regard to many broad IT areas including, but not limited to: security management controls, access controls, provisioning and deprovisioning, transfers, separation of duties, configuration management, contingency planning, application security, business process controls, interface controls, and data management system controls.

The Candidate Will Be Responsible For

  • Conducting formal assessments and deciding whether the system is authorized to operate
  • Conducting a formal assessment of the system’s security posture
  • Evaluating whether security controls meet established standards and are functioning effectively
  • Documenting results and making recommendations for improving security
  • Recommending whether the system should be authorized to operate based on assessment outcomes
  • Ensuring that the system has the necessary security controls to minimize risks
Basic Qualifications
  • A minimum of a Bachelor’s degree coupled with 4-8 years’ experience in the Information Technology, Computer Science, IT, Information/Cyber Security field from an accredited college or university arena or Master’s Degree with 2 years of relevant experience.
OR

  • A minimum of a Bachelor’s degree coupled with 8 years’ experience in the Information Technology, Computer Science, IT, Information/Cyber Security field from an accredited college or university arena or Master’s Degree with 6 years of relevant experience.
  • Superior writing, communication and critical analysis skills
  • Deep understanding of Information Assurance, Information Technology and Information Management concepts, processes and procedures
  • Experience with supporting the delivery of large and complex projects on time and within budget in government organizations
  • Minimum of 1-3 years of experience as an ISSO supporting major federal information systems/applications
  • Superior writing, communication and critical analysis skills
  • Deep understanding of Information Assurance, Information Technology and Information Management concepts, processes and procedures
  • Working knowledge of the following policies: NIST SP 800-37, Rev 2, Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy, DHS 4300A Policy and Handbook, CBP Information Systems Security Policies and Procedures Handbook (HB 1400-05D).
  • Must be a US Citizen.
  • Must be able to commute to Ashburn VA up to 5 days per week if required.
Preferred Qualifications
  • Prior experience with CBP
  • DoD 8570 IAT III
  • CompTIA Certified Advanced Security Practitioner (CASP+)
  • ISC2 Certified in Governance, Risk and Compliance Certification (CGRC)
  • ISC2 Certified Information Systems Security Professional (CISSP)
  • ISACA Certified Information Systems Auditor (CISA).


If you\'re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We\'re not hiring followers. We\'re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We\'re already at step 30 — and moving faster than anyone else dares.

Original Posting

May 4, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range

Pay Range $87,100.00 - $157,450.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos
Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay And Benefits
Pay and benefits are fundamental to any career decision. That\'s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

Securing Your Data
Beware of fake employment opportunities using Leidos’ name. Leidos will never ask you to provide payment-related information during any part of the employment application process (i.e., ask you for money), nor will Leidos ever advance money as part of the hiring process (i.e., send you a check or money order before doing any work). Further, Leidos will only communicate with you through emails that are generated by the Leidos.com automated system – never from free commercial services (e.g., Gmail, Yahoo, Hotmail) or via WhatsApp, Telegram, etc. If you received an email purporting to be from Leidos that asks for payment-related information or any other personal information (e.g., about you or your previous employer), and you are concerned about its legitimacy, please make us aware immediately by emailing us at LeidosCareersFraud@leidos.com.

If you\'re the victim of a scam, contact your local law enforcement and report the incident to the U.S. Federal Trade Commission.

Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Assessment & Authorization Analyst
Assessment & Authorization Analyst

Koitecc Solutions • Ashburn (VA)

On-site
USD 87,000 - 157,000
Health and Wellness programs
Paid Leave
Retirement
Application Security Engineer
Application Security Engineer

Leidos Inc • Ashburn (VA)

On-site
USD 107,000 - 196,000
Assessment & Authorization Analyst
Assessment & Authorization Analyst

Leidos Inc • Ashburn (VA)

On-site
USD 69,550 - 125,725
Health and Wellness programs
Income Protection
Paid Leave
+1
Sr. ISSE with TS/SCI Polygraph
Sr. ISSE with TS/SCI Polygraph

Leidos • Corridor North (MD)

On-site
USD 131,000 - 238,000
Paid Time Off
401K with 6% match
Flexible Schedules
+2
Full Stack Developer
Full Stack Developer

Leidos • United States

On-site
USD 131,000 - 238,000
Health and Wellness programs
Paid Leave
Retirement benefits
Assessment & Authorization Analyst
Assessment & Authorization Analyst

Leidos • Ashburn (GA)

On-site
USD 87,000 - 157,000
Assessment & Authorization Analyst
Assessment & Authorization Analyst

Leidos • United States

On-site
USD 69,550 - 125,725
Information System Security Officer (ISSO)
Information System Security Officer (ISSO)

Leidos • Oklahoma City (OK)

On-site
USD 87,000 - 157,000
Cyber Infrastructure Support Lead
Cyber Infrastructure Support Lead

Leidos Inc • Concord (MA)

On-site
USD 108,000 - 195,000
System Administrator TS/SCI Poly
System Administrator TS/SCI Poly

Via Logic LLC • Corridor North (MD)

On-site