Cyber Security STIG Tester

Leidos

Odenton (MD)

On-site

USD 108,000 - 195,000

Full time

4 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Leidos is seeking a Cyber Security STIG Tester to join our GSMO-II team at Ft. Meade, MD. This role performs technical security assessments using STIG Checklists, SCAP scans, and ACAS/ESS scans to identify vulnerabilities and ensure compliance with DoD IA guidelines.

The candidate will analyze results, coordinate with system owners, and contribute to RMF STIG testing and reporting for security briefings. You will also ensure readiness for RMF authorization, coordinate with administrators, and

Qualifications

  • Bachelor’s degree and 8+ years of experience; additional years of directly applicable experience may be accepted in lieu of a degree.
  • Prior relevant experience working with STIG Compliance, SCAP tools, vulnerability assessments and reporting.
  • Experience using eMASS and/or Xacta.
  • Solid understanding of the Risk Management Framework (RMF) and the System Development Life Cycle (SDLC).

Responsibilities

  • Ensure STIG Checklists are up to date and settings are enforced with minimal operational impact for all systems.
  • Educate systems/network administrators regarding completion/edits as required.
  • Examine results of STIG testing and pass results to system owners and system administrators.
  • Track response times to STIG findings and report on the security briefing.
  • Support POA&M analysis and coordination efforts, as required, including eMASS updates.
  • Perform cybersecurity lab testing/hardening activities supporting deployment of/updates to computer systems and applications.
  • Review data from ACAS/ESS scans and set tickets to add new equipment into scans as necessary.
  • Maintain SOP’s for testing and reporting activities.
  • Support functional testing as necessary for new technology.
  • Support testing events and preparation for testing events.
  • Perform vulnerability/risk analyses of computer systems and applications during all phases of the system development life cycle.
  • Support Authorizing Official (AO) actions by ensuring all testing related security testing artifacts are presented in accordance with RMF as defined in NIST 800-37 revision 2 and related agency specific RMF requirements.
  • Have experience performing various types of vulnerability and assessment scans with multiple tools.

Skills

RMF knowledge
SDLC understanding
Analytical thinking
Problem solving

Education

Bachelor’s degree

Tools

SCAP tools
eMASS
Xacta
ACAS

Job description

Description

Are you ready to make an impact and join a creative, forward-thinking team? Leidos is seeking qualified Cyber Security STIG Tester to join our GSMO-II team at Ft. Meade, MD.

POSITION SUMMARY:

The selected candidate shall perform (or review) technical security assessments using STIG Checklists, SCAP scans, and ACAS/ESS Scans of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) guidelines and regulations and recommend mitigation strategies. In this role, the candidate will ensure that the environments in which DoD information systems reside are secure and compliant, develop approaches to secure the environment, assess threats to the environment, provide inputs on the adequacy of security designs and architectures, perform RMF STIG and compliance testing related activities, and participate in risk assessment mitigation with the system administrators and providing relevant reporting for security briefing.

CLEARANCE REQUIREMENT:
  • Must hold an active Secret security clearance. (US Citizenship required)
PRIMARY RESPONSIBILITIES:
  • Ensure STIG Checklists are up to date and settings are enforced with minimal operational impact for all systems (workstations, servers, network) within the environment.
  • Support systems within GMS to have an up to date and complete STIG Checklist; educate systems/network administrators regarding completion/edits as required.
  • Examine results of STIG testing and pass results to system owners and system administrators.
  • Track response times to STIG findings and report on the security briefing.
  • Support POA&M analysis and coordination efforts, as required, including eMASS updates.
  • Perform cybersecurity lab testing/hardening activities supporting deployment of/updates to computer systems and applications.
  • Review data from ACAS/ESS scans and set tickets to add new equipment into scans as necessary.
  • Maintain SOP’s for testing and reporting activities.
  • Support functional testing as necessary for new technology.
  • Support testing events and preparation for testing events.
  • Perform vulnerability/risk analyses of computer systems and applications during all phases of the system development life cycle.
  • Support Authorizing Official (AO) actions by ensuring all testing related security testing artifacts are presented in accordance with RMF as defined in NIST 800-37 revision 2 and related agency specific RMF requirements.
  • Have experience performing various types of vulnerability and assessment scans with multiple tools.
BASIC QUALIFICATIONS:
  • Bachelor’s degree and 8+ years of experience; additional years of directly applicable experience may be accepted in lieu of a degree.
  • Prior relevant experience working with STIG Compliance, SCAP tools, vulnerability assessments and reporting.
  • Have experience performing various types of vulnerability and assessment scans with multiple tools.
  • Have experience using eMASS and/or Xacta.
  • Solid understanding of the Risk Management Framework (RMF) and the System Development Life Cycle (SDLC).
  • Understanding of hardware and software engineering best practices.
  • Demonstrated analytical and problem-solving skills.
  • Must meet eligibility requirements for work assignment on specified contract.
  • Applicants selected will be subject to a government security investigation and must meet eligibility requirements.
  • Current DoD 8570 IAT II Certification is required. (Sec+.)
PREFERRED QUALIFICATIONS:
  • Ability to identify needed changes to processes and activities and help to implement continuous improvement solutions.
  • ACAS training completed.
  • Ability to work successfully as part of a virtual team.

If you’re looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We’re not hiring followers. We’re recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We’re already at step 30 — and moving faster than anyone else dares.

Pay Range:

Pay Range $107,900.00 - $195,050.00

The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

About Leidos

Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employees, Leidos reported annual revenues of approximately $16.7 billion for the fiscal year ended January 3, 2025. For more information, visit www.Leidos.com.

Pay and Benefits

Pay and benefits are fundamental to any career decision. That’s why we craft compensation packages that reflect the importance of the work we do for our customers. Employment benefits include competitive compensation, Health and Wellness programs, Income Protection, Paid Leave and Retirement. More details are available at www.leidos.com/careers/pay-benefits.

Commitment to Non-Discrimination

All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior ISSE/Penetration Tester TS/SCI Polygraph
Senior ISSE/Penetration Tester TS/SCI Polygraph

Leidos • Annapolis (MD)

On-site
USD 131,000 - 237,000
Paid Time Off
11 holidays
401K with 6% company match
+4
Cyber Infrastructure Support
Cyber Infrastructure Support

Via Logic LLC • California (MD)

On-site
USD 108,000 - 195,000
Cyber Infrastructure Support
Cyber Infrastructure Support

Koitecc Solutions • California (MD)

On-site
USD 108,000 - 195,000
Defensive Cybersecurity Analyst
Defensive Cybersecurity Analyst

Via Logic LLC • Illinois

On-site
USD 70,000 - 126,000
Cyber Security Analyst
Cyber Security Analyst

Leidos • Arlington (VA)

On-site
USD 87,000 - 157,000
On-site in Arlington
Cyber Infrastructure Support
Cyber Infrastructure Support

Leidos Inc • California (MD)

On-site
USD 108,000 - 195,000
Cyber Security Specialist
Cyber Security Specialist

Via Logic LLC • Hampton (VA)

On-site
USD 87,000 - 157,000
Cybersecurity Analyst Intern
Cybersecurity Analyst Intern

Leidos Inc • Odenton (MD)

On-site
USD 48,000 - 87,000
Information System Security Engineer
Information System Security Engineer

Via Logic LLC • Norfolk (VA)

On-site
USD 87,000 - 157,000
Information System Security Engineer
Information System Security Engineer

Leidos • Norfolk (VA)

On-site
USD 87,000 - 157,000