Leidos is seeking an Information System Security Engineer (ISSE) to collaborate with the Information System Security Manager (ISSM) serving as a subject matter expert in advanced technical principles, theories, and concepts in Security Engineering, including operations, engineering, technical and program management support services, and RMF/ATO compliance to support cyber-related operations. Duties will include: Under the direction and guidance of the ISSM, capture and refine information security requirements and ensure their integration into information technology components and information systems through purposeful security design and configuration. Perform vulnerability assessments to determine weaknesses and exploit methods in systems/networks utilizing approved COTS and GOTS tools, in conjunction with security testing methodologies and frameworks to assess threats against information and system/networks and recommend appropriate countermeasures for continued mission assurance. Perform cybersecurity analysis, identification, and remediation of complex cybersecurity compliance requirements on IT systems and applications to include: Microsoft Windows and RHEL family of servers, workstations operating systems. RDBMS such as SQL and PostgreSQL, XML, and JSON-based semi-structured technologies. Web-Server and web application technologies (e.g., MS IIS, Apache/Tomcat, SharePoint). Virtualization technologies such as VMware and VDI infrastructures. Network infrastructure components such as switches, firewalls, vSANs, and thin client hardware. Provide remediation recommendations and mitigating strategies for vulnerabilities discovered and maintain in-depth knowledge of STIG/SRGs, technologies such as Tenable Nessus, SCAP compliance tools like EvaluateSTIG and other automated tools that assist with the assessment of security controls and the presentation of security assessment results. In coordination with change management processes, remediate, apply, and/or mitigate vulnerabilities to systems and system components through the application of security updates, patches, fixes, and/or secure configurations. Support the creation, development, and documentation of cybersecurity processes and procedures supporting Authorization to Operate (ATO) packages and, as needed, to mature the program’s cybersecurity posture. Experience with eMASS to manage ATO package Prepare and maintain security documentation, including System Security Plans (SSPs), Security Assessment Reports, and Plans of Action and Milestones (POA&Ms). Install, configure and manage Trellix products. Create, tune, and enforce security policies through the ePO console to meet company security standards and compliance requirements. Troubleshoot Splunk issues between server and forwarder, create custom dashboards and implement best practices. Administer, configure, and maintain the Tenable Security Center. Review ACAS results and remediate appropriately.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
11-50 employees