Description
Leidos has a new and exciting opportunity for a Sr. Information System Security Engineer in our Intel Sector's Cyber & Analytics Business Area (CABA). Our team is at the forefront of Security Engineering, Computer Network Operations (CNO), Mission Software, Analytical Methods and Modeling, Signals Intelligence (SIGINT), and Cryptographic Key Management. At Leidos, we offer competitive benefits, including paid time off, holidays, 401K with a company match, flexible schedules, discounted stock purchase plans, technical upskilling, education and training support, parental paid leave, and more. Join us and make a difference in national security!
*You must have an active TS/SCI Polygraph up front. Unfortunately, no exceptions.*
Leidos has an exciting opportunity for a Sr. Information System Security Engineer to join a high-performing agile team using the Scaled Agile Framework (SAFe) methodology to support a fast-paced, complex program. Program execution follows DevOps best practices and employs robust development, test, and production environments. Our security engineers support enhancements to system security architecture and cyber security capabilities; manage multiple system security plans for development, test, and production systems following the Risk Management Framework (RMF); manage cross domain capabilities; and support Security Verification Testing (SVT) of relevant Type 1 devices.
You will provide support for adding new capabilities to a complex system with exacting interface, performance and security requirements. You will work with a team of Security Engineers to improve our operational, test, integration, and development systems and solve challenging issues on a large, significant program. Experience with vulnerability testing, risk management, and security architecture is required.
Responsibilities
- Validate and verify system security requirements and establish system security designs for large-scale systems and interfacing systems in distributed network environments.
- Identify and implement appropriate information security architectures and functionality to ensure uniform application of security policy and enterprise solutions.
- Recommend and develop technical solutions, products, and standards based on current and desired system security architecture.
- Assess and mitigate system security threats and risks throughout the program life cycle.
- Lead or contribute to the security planning, assessment, risk analysis, risk management, certification, and awareness activities for various systems and networking operations.
- Collaborate with other internal technical experts on a day-to-day basis.
- Communicate with program managers and points of contact from customer organizations regarding significant security issues.
- Participate in Program Increment Planning and related agile team activities.
- Work closely with System Engineering, Test Engineering, and Integration teams to ensure hardware and software architecture meets security requirements.
- Analyze and assess system implementation against multiple security compliance policies, recommend and implement enhancements.
- Evaluate security solutions to ensure they meet customer-specified requirements for processing information.
- Assess the impact of new development on the operational security posture of the system.
- Review and test critical software.
- Propose, assess, coordinate, implement, and enforce information system security policies, standards, and methodologies.
- Audit and assess system security configuration settings using common methodologies and tools.
- Manage and enforce security strategies and policies affecting geographically distributed systems.
- Provide configuration management for security-relevant information system software.
- Serve as a subject-matter expert in security architecture and advise program managers, customer technical experts, and internal program teams.
- Formulate security compliance requirements for new system features.
- Identify and remediate security issues throughout the system.
- Support risk assessment, risk management, security control assessment, continuous monitoring, service design, and other IA program support functions.
- Work with development teams to improve understanding of vulnerabilities, attack vectors, and remediation approaches.
- Plan and conduct security verification testing of relevant type 1 devices.
Basic Qualifications
- Bachelor's degree in Computer Science, Information Assurance, Information Security System Engineering, or a related discipline and at least 12 years of relevant experience. Additional experience may be substituted for a degree.
- Solid understanding of security practices and policies and hands‑on vulnerability testing experience using customer tools.
- Experience applying the Risk Management Framework.
- Experience formulating and assessing IT security policy.
- Knowledge of and experience with common security tools, such as Nessus, NMAP, and Wireshark, hardware/software security implementation, communication protocol, encryption techniques/tools, and web services.
- Experience with secure configurations of commonly used desktop and server operating systems.
- Ability to work on multiple systems and components simultaneously in various configurations.
- Strong verbal and written communication skills.
- Commitment to adopting and adhering to best practices.
- Ability to plan and prioritize tasks and communicate clearly regarding technical options and trade‑offs.
- Capability to perform high-quality work both independently and with a team in a fast-moving environment.
Preferred Qualifications
- Five (5) years of experience with Defense in Depth principals/technology and applying risk assessment methodology to system development.
- DoD 8570 compliance with IASAE Level 2 or 3.
- Information Systems Security Engineering Professional (ISSEP) Certification.
- Computer Information Systems Security Professional (CISSP) Certification.
- Experience developing and implementing integrated security services management processes, such as assessment and auditing network penetration testing, antivirus planning assistance, risk analysis, and incident response.
- Experience providing information assurance support for application development that includes system security certifications and project evaluations for firewalls.
- Experience with penetration testing tools.
- Experience with scripting languages.
Pay Range
$131,300.00 – $237,350.00
Pay and Benefits
Employment benefits include competitive compensation, health and wellness programs, income protection, paid leave, and retirement. For more details, visit www.leidos.com/careers/pay-benefits.
Commitment to Non-Discrimination
All qualified applicants will receive consideration for employment without regard to sex, race, ethnicity, age, national origin, citizenship, religion, physical or mental disability, medical condition, genetic information, pregnancy, family structure, marital status, ancestry, domestic partner status, sexual orientation, gender identity or expression, veteran or military status, or any other basis prohibited by law. Leidos will also consider for employment qualified applicants with criminal histories consistent with relevant laws.