
Information Assurance Engineer – USAF Cloud One
Leidos
full-time
Posted on:
Location Type: Hybrid
Location: Huntsville • Alabama • Massachusetts • United States
Visit company websiteExplore more
Salary
💰 $87,100 - $157,450 per year
Tech Stack
About the role
- Provide Risk Management Framework (RMF) engineering and cybersecurity support for the USAF Cloud One (C1) enterprise cloud environment.
- Support ISSO/ISSM functions, ATO sustainment, continuous monitoring, vulnerability management, and cybersecurity compliance activities.
- Work closely with Government ISSOs, ISSMs, Authorizing Officials (AOs), Cybersecurity Service Providers (CSSPs), and Cloud One engineering teams.
- Develop, update, and maintain RMF authorization artifacts.
- Provide RMF-required documentation in support of Assessment & Authorization (A&A) activities.
- Maintain System Security Plans (SSPs), Security Control Traceability Matrices (SCTMs), POA&Ms, and supporting documentation.
- Support migration of security control baselines from NIST SP 800-53 Rev 4 to Rev 5.
- Support Continuous Authorization to Operate (cATO) within a DevSecOps or cloud-based environment.
- Support ATO maintenance and sustainment activities for C1 and DPaaS environments.
Requirements
- Bachelor’s degree with 4–8 years of relevant experience, or Master’s degree with 2–6 years of relevant experience.
- Additional years of experience may be considered in lieu of a degree.
- Active Secret clearance at a minimum required to start.
- US citizenship required
- CompTIA Security+ (IAT Level II) or equivalent required
- Experience with USAF Cloud One or Platform 1
- Experience with Zero Trust Architecture
- Cloud certifications in AWS, Azure, Google, or Oracle clouds
- Automation experience
- Certifications: CISSP (IAT Level III) or equivalent
Benefits
- Health and Wellness programs
- Income Protection
- Paid Leave
- Retirement
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
Risk Management Framework (RMF)cybersecurityvulnerability managementcontinuous monitoringAssessment & Authorization (A&A)System Security Plans (SSPs)Security Control Traceability Matrices (SCTMs)DevSecOpsZero Trust Architectureautomation
Certifications
CompTIA Security+CISSP