Leidos' Corporate Information Security Office, reporting through the Digital sector, has an opening for an Information System Security Officer (ISSO) in our Omaha, NE office.
In this role, you will support the operation, maintenance, and authorization of classified information systems by implementing and monitoring cybersecurity requirements throughout the system lifecycle. This position will perform day-to-day information system security activities, maintain Risk Management Framework documentation and evidence, assess system compliance, support vulnerability-management activities, and coordinate remediation of identified security deficiencies.
You must be able to work independently while collaborating effectively with Information System Security Managers, Information Assurance personnel, system administrators, engineers, program management, and customer security representatives. You should possess hands‑on experience applying Department of Defense cybersecurity requirements, interpreting security controls, evaluating technical evidence, and translating compliance requirements into practical actions for technical personnel.
Location: Work will be performed on-site at our Omaha office.
Clearanc e: You must currently hold an active DoD Top Secret clearance and be eligible to obtain Special Compartmented Investigation (SCI) post hire. Those with current TS SCI will be given first consideration.
Primary Responsibilities
- This role may include a combination of duties to protect information, maintain security controls, and reduce risk across assigned information systems, sites, or programs.
- Serve as the Information System Security Officer for assigned classified information systems.
- Support the implementation, operation, maintenance, and continuous monitoring of cybersecurity controls throughout the system lifecycle.
- Apply the Department of Defense Risk Management Framework to assigned systems, including security control implementation, assessment preparation, authorization maintenance, and ongoing monitoring.
- Assist the Information System Security Manager with maintaining system authorization packages and supporting documentation.
- Develop, review, and update system security documentation, including System Security Plans, security control implementation statements, plans of action and milestones, continuous monitoring records, risk assessments, procedures, inventories, diagrams, and supporting evidence.
- Evaluate security controls to determine whether they are properly implemented, operating as intended, and producing the desired security outcome.
- Collect, review, organize, and maintain technical and administrative evidence supporting security control implementation and assessment activities.
- Conduct recurring reviews of assigned systems to verify continued compliance with approved authorization packages, security policies, technical baselines, and customer requirements.
- Support continuous monitoring activities by tracking control assessments, vulnerability scans, configuration reviews, account reviews, audit records, training requirements, hardware and software changes, and other recurring security activities.
- Develop and maintain continuous monitoring schedules, recurring task trackers, evidence repositories, and status reports.
- Identify security deficiencies, evaluate associated risk, document findings, assign or coordinate corrective actions, and track remediation through closure.
- Create, review, and maintain plans of action and milestones for identified weaknesses, including accurate deficiency descriptions, risk statements, milestones, resources, scheduled completion dates, and supporting evidence.
- Perform vulnerability-management activities, including scan coordination, result analysis, false-positive validation, risk evaluation, remediation tracking, mitigation verification, and reporting.
- Use approved vulnerability scanning and compliance-assessment tools to identify missing patches, insecure configurations, unsupported software, and other technical weaknesses.
- Review vulnerability and compliance scan results to determine applicability, severity, affected assets, potential impact, and required remediation actions.
- Coordinate with system administrators and infrastructure personnel to remediate vulnerabilities, configuration findings, patching deficiencies, and other security issues.
- Validate that remediation actions have been successfully completed through rescanning, configuration review, documentation review, or other appropriate verification methods.
- Support the implementation, assessment, and documentation of Security Technical Implementation Guide requirements and other approved security configuration baselines.
- Review Security Technical Implementation Guide checklists, Security Content Automation Protocol results, configuration evidence, and technical documentation for accuracy and completeness.
- Assist technical personnel with interpreting security requirements and identifying compliant impleme