Senior Cyber Specialist - ISSO

Leidos•Odenton, MD
•$131,300 - $237,350

About The Position

Leidos is seeking a Senior Cyber Specialist to serve as an Information System Security Officer (ISSO) responsible for the day-to-day security posture, authorization, and continuous monitoring of enterprise information systems. The role owns the security control implementation and accreditation artifacts for assigned systems and serves as the principal point of contact for cybersecurity matters affecting them. This position is responsible for ensuring assigned systems are built, documented, assessed, and operated in accordance with applicable federal and DoD cybersecurity requirements. Duties include security control implementation and validation, risk assessment, vulnerability and compliance oversight, incident support, and the development and maintenance of the artifacts required to obtain and sustain an authorization to operate. The successful candidate is a cybersecurity practitioner who works comfortably between the engineering teams who build the system and the authorizing officials who must accept its risk — translating technical reality into defensible control documentation, and translating control requirements into changes engineers can actually implement.

Requirements

  • Bachelor's degree or equivalent experience and 12+ years of prior relevant experience, or Master's degree with 10+ years of experience. Specific experience, education, and training may be considered in lieu of a degree.
  • Current IAT Level II or higher certification, such as Security+ or CISSP.
  • Active DoD Secret clearance.

Responsibilities

  • Serve as ISSO for assigned systems, maintaining the system security posture and acting as the principal cybersecurity point of contact for those systems.
  • Execute Risk Management Framework (RMF) activities across categorization, control selection, implementation, assessment, authorization, and continuous monitoring.
  • Develop, maintain, and defend authorization packages, including the System Security Plan, security control implementation statements, risk assessment reports, contingency and incident response plans, and supporting artifacts.
  • Maintain system records and artifacts in eMASS or the designated authorization repository, keeping control status, assessment results, and documentation current and accurate.
  • Develop and track Plans of Action and Milestones (POA&Ms), including risk justification, mitigation approach, compensating controls, and milestone closure evidence.
  • Support security assessments, audits, inspections, and command cyber readiness activities, including evidence collection and assessor coordination.
  • Evaluate proposed system and architecture changes for security impact, and provide written recommendations on acceptance, mitigation, or denial.
  • Oversee vulnerability management for assigned systems, including scan review, validation, prioritization, remediation tracking, and reporting against required timelines.
  • Oversee DISA STIG and security configuration compliance, including baseline review, deviation justification, and verification of applied hardening.
  • Review and act on cybersecurity directives, bulletins, advisories, and tasking orders applicable to assigned systems, and track compliance to closure.
  • Perform continuous monitoring activities, including control status review, log and audit record oversight, account and privilege review, and security posture reporting.
  • Support incident response and reporting, including initial analysis, documentation, coordination with the security operations team, and after-action tracking of corrective measures.
  • Partner with network, systems, cloud, application, and operations engineering teams to ensure security requirements are designed in rather than retrofitted.
  • Provide practical security guidance on architecture and implementation decisions, including boundary definition, access control, encryption, auditing, and least privilege.
  • Advise program leadership and government stakeholders on cybersecurity risk, control posture, remediation options, and the security implications of schedule and design decisions.
  • Mentor junior cybersecurity staff and provide technical direction on assessment, documentation, and remediation work.
  • Improve cybersecurity processes, templates, evidence standards, and reporting to reduce rework and shorten authorization timelines.
  • Develop and maintain cybersecurity documentation, including: System Security Plans and control implementation statements, System boundary descriptions, data flow diagrams, and hardware/software inventories, Risk assessment reports and security impact analyses, Plans of Action and Milestones with supporting evidence, Contingency, continuity, and incident response plans, Configuration and hardening baselines and deviation justifications, Continuous monitoring and security posture reports, Standard operating procedures for recurring security activities.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service