Cyber Security STIG Tester

Leidos LLC

Fort Meade (MD)

On-site

USD 108,000 - 195,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Leidos is seeking a Cyber Security STIG Tester to join our GSMO-II team at Ft. Meade, MD.

The role focuses on performing and reviewing security assessments using STIG checklists, SCAP scans, and ACAS/ESS scans to identify vulnerabilities and non-compliance with IA guidelines. The candidate will contribute to RMF STIG and compliance testing, coordinate risk mitigation with system admins, and provide reporting for security briefings.

Qualifications

  • Bachelor’s degree and 8+ years of related experience.
  • Experience with STIG compliance and SCAP tools.
  • Experience with vulnerability and assessment scans.
  • Familiarity with eMASS and/or Xacta.
  • Strong RMF and SDLC understanding.
  • Security clearance: Secret.

Responsibilities

  • Ensure STIG Checklists are up to date and settings are enforced with minimal operational impact for all systems.
  • Support systems with up-to-date STIG Checklist and educate admins on completion/edits.
  • Examine results of STIG testing and pass results to owners/admins.
  • Track response times to STIG findings and report on security briefing.
  • Support POA&M analysis and coordination including eMASS updates.
  • Perform cybersecurity lab testing/hardening for deployments and updates.
  • Review data from ACAS/ESS scans and adjust scans for new equipment.
  • Maintain SOPs for testing and reporting activities.
  • Support testing events and preparations for tests.
  • Perform vulnerability/risk analyses during all SDLC phases.
  • Assist AO actions with RMF-compliant artifacts.

Skills

Analytical thinking
Problem-solving
Communication skills
Team collaboration

Education

Bachelor's degree in related field

Tools

SCAP tools
eMASS
Xacta
ACAS/ESS
STIG Checklists
RMF tooling

Job description

Are you ready to make an impact and join a creative, forward-thinking team? Leidos is seeking qualified Cyber Security STIG Tester to join our GSMO-II team at Ft. Meade, MD.

POSITION SUMMARY:

The selected candidate shall perform (or review) technical security assessments using STIG Checklists, SCAP scans, and ACAS/ESS Scans of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) guidelines and regulations and recommend mitigation strategies. In this role, the candidate will ensure that the environments in which DoD information systems reside are secure and compliant, develop approaches to secure the environment, assess threats to the environment, provide inputs on the adequacy of security designs and architectures, perform RMF STIG and compliance testing related activities, and participate in risk assessment mitigation with the system administrators and providing relevant reporting for security briefing.

CLEARANCE REQUIREMENT:
  • Must hold an active Secret security clearance. (US Citizenship required)
PRIMARY RESPONSIBILITIES:
  • Ensure STIG Checklists are up to date and settings are enforced with minimal operational impact for all systems (workstations, servers, network) within the environment.
  • Support systems within GMS to have an up to date and complete STIG Checklist; educate systems/network administrators regarding completion/edits as required.
  • Examine results of STIG testing and pass results to system owners and system administrators.
  • Track response times to STIG findings and report on the security briefing.
  • Support POA&M analysis and coordination efforts, as required, including eMASS updates.
  • Perform cybersecurity lab testing/hardening activities supporting deployment of/updates to computer systems and applications.
  • Review data from ACAS/ESS scans and set tickets to add new equipment into scans as necessary.
  • Maintain SOP’s for testing and reporting activities.
  • Support functional testing as necessary for new technology.
  • Support testing events and preparation for testing events.
  • Perform vulnerability/risk analyses of computer systems and applications during all phases of the system development life cycle.
  • Support Authorizing Official (AO) actions by ensuring all testing related security testing artifacts are presented in accordance with RMF as defined in NIST 800-37 revision 2 and related agency specific RMF requirements.
  • Have experience performing various types of vulnerability and assessment scans with multiple tools.
BASIC QUALIFICATIONS:
  • Bachelor’s degree and 8+ years of experience; additional years of directly applicable experience may be accepted in lieu of a degree.
  • Prior relevant experience working with STIG Compliance, SCAP tools, vulnerability assessments and reporting.
  • Have experience performing various types of vulnerability and assessment scans with multiple tools.
  • Have experience using eMASS and/or Xacta.
  • Solid understanding of the Risk Management Framework (RMF) and the System Development Life Cycle (SDLC).
  • Understanding of hardware and software engineering best practices.
  • Demonstrated analytical and problem-solving skills.
  • Must meet eligibility requirements for work assignment on specified contract.
  • Applicants selected will be subject to a government security investigation and must meet eligibility requirements.
  • Current DoD 8570 IAT II Certification is required. (Sec+.)
PREFERRED QUALIFICATIONS:
  • Ability to identify needed changes to processes and activities and help to implement continuous improvement solutions.
  • ACAS training completed.
  • Ability to work successfully as part of a virtual team.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Original Posting: September 10, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above. Pay Range: Pay Range $107,900.00 - $195,050.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Leidos Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $17.2 billion for the fiscal year ended January 2, 2026. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That's why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available here.

Securing Your Data

Leidos will never ask you to provide payment-related information at any part of the employment application process. And Leidos will communicate with you only through emails that are sent from a Leidos.com email address. If you receive an email purporting to be from Leidos that asks for payment-related information or any other personal information, please report the email to spam.leidos@leidos.com.

Commitment and Diversity

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security STIG Tester
Cyber Security STIG Tester

Leidos Inc • Odenton (MD)

On-site
USD 108,000 - 195,000
Cyber Security STIG Tester
Cyber Security STIG Tester

Via Logic LLC • Odenton (MD)

On-site
USD 108,000 - 195,000
Cyber Security STIG Tester
Cyber Security STIG Tester

Koitecc Solutions • Odenton (MD)

On-site
USD 108,000 - 195,000
SCA-R Validator
SCA-R Validator

Leidos LLC • Alexandria (VA)

On-site
USD 87,000 - 157,000
Per diem while travel
Cyber Security STIG Tester
Cyber Security STIG Tester

Leidos • Odenton (MD)

On-site
USD 108,000 - 195,000
SCA-R Validator
SCA-R Validator

Leidos • Odenton (MD)

On-site
USD 87,000 - 157,000
Per diem for travel
SCA-R Validator
SCA-R Validator

Leidos • Alexandria (VA)

On-site
USD 87,000 - 157,000
Per diem while traveling
On-site work
SCA-R Validator
SCA-R Validator

Leidos • Chambersburg

On-site
USD 87,000 - 157,000
Per diem while travel
Cyber Engineer
Cyber Engineer

Leidos LLC • Bath Township (OH)

On-site
USD 87,000 - 157,000
Competitive compensation
Health and Wellness programs
Income protection
+2
Cyber Engineer
Cyber Engineer

Leidos LLC • Dayton (OH)

On-site
USD 87,000 - 157,000