Leidos has an exciting opening for you, our next TS/SCI Cyber Security Engineer working across several Task Orders under the DOMEX Technology Platform (DTP) contract supporting NMEC. Have impact as part of a mission focused, solutions oriented, and adaptive team that values innovation, collaboration, and professional development. As a Cyber Security Engineer, your job will be to design, develop, and implement secure systems in on-premises infrastructure. You will leverage on your experience with security technologies and industry best practices to ensure that security is integrated into system design, development, testing, and deployment and that all security requirements are compliant with the DoD Risk Management Framework. This exciting and challenging work will help you expand your capabilities in security and will provide you with the skills and experience you need to achieve additional levels of the DoD 8570 IAT and IASAE Certifications. While most work is conducted on-site at our client location in Bethesda, MD, we offer a flexible schedule and, occasionally, some tasks may be performed remotely. Percentage of remote work will vary based on client requirements/deliverables. In this role, you will collaborate closely with ISSOs, ISSSMs, software engineers, software developers, system engineers and Government counterparts to perform the full spectrum of systems and cyber security engineering tasks to ensure our systems meet a variety of regulatory compliance frameworks. Key Tasks include the following: Support the secure architecture, design, and implementation of DoD systems in accordance with DoDI 8510.01, NIST SP 800-53, and other DoD security guidance. Lead the integration of RMF activities into the system development lifecycle (SDLC), including selecting, implementing, and validating security controls. Develop and maintain key security documentation such as System Security Plans (SSPs), Security Assessment Reports (SARs), Risk Assessments, and Plan of Action and Milestones (POA&Ms). Collaborate with ISSOs, ISSMs, developers, and system owners to ensure systems are developed and maintained with approved security configurations. Apply Security Technical Implementation Guides (STIGs) to systems and validate compliance using tools such as SCAP, STIG Viewer, and ACAS. Maintain application, network, and database scanning infrastructure (application/product updates, database maintenance, benchmark/audit files, application/server builds, rule pack/content updates, scanner, or agent deployment etc.) Analyze vulnerability scans and ensure timely mitigation or acceptance of risks based on DoD policies. Provide technical input to support and maintain system authorization. Participate in system reviews, architecture assessments, and engineering design reviews to embed cybersecurity from the outset. Develop and implement automation or security tools to improve the compliance and monitoring of systems. Support security incident response and forensics analysis in coordination with ISSMs and Security points of contact.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
5,001-10,000 employees