
Information Assurance Engineer
Leidos
full-time
Posted on:
Location Type: Hybrid
Location: Norfolk • California • Hawaii • United States
Visit company websiteExplore more
Salary
💰 $107,900 - $195,050 per year
Tech Stack
About the role
- Perform cybersecurity authorization services, including acting as a main point of contact for cybersecurity authorization related aspects to the assigned information systems
- Ensure systems are maintained per security policies and procedures and maintaining compliance and ongoing reporting to management.
- Serve as a primary information system security engineer (ISSE) for Authorization to Operate (ATO) packages under the Risk Management Framework (RMF)
- Assist in the development and review of ATO submissions and coordinate all updates and corrections to assessment and authorization (A&A) artifacts
- Evaluate software and hardware during pre-acquisition phases to determine its ability to meet minimum security requirements based on NIST SP 800-53 Rev4 security controls.
- Author, review, coordinate and submit cybersecurity authorization required artifacts to eMASS (including change requests) to achieve milestones such as Interim Authority to Test (IATT) and ATO in accordance with the project schedule.
- Support conducting cybersecurity authorization activities to comply with all current Cybersecurity and IA manuals, instructions, and guides within the DoDI 8500.01, DON 5239, and Marine Corps ECSM’s.
- Continuously monitor system resources through automated scanning and implement automated reporting feeds to support cybersecurity authorizations
- Verify patch compliance using the approved technical solution (i.e., Assured Compliance Assessment Solution (ACAS)), Information Assurance Vulnerability Alert (IAVA) compliance dashboards, and Microsoft Defender for Endpoints.
- Coordinate with local administrators to troubleshoot and elevate patching issues in a timely manner in order to meet patch compliance timelines.
Requirements
- Bachelor's degree and 8-12 years of prior relevant experience or Master’s with 6-10 years of prior relevant experience in Cybersecurity, Information Security, IT, EE, Network Engineering, Computer Science, or related field.
- US Citizen and DoD Secret Clearance
- Hold an active security certification that meets DOD 8570 IAT level III or higher
- Must have complete understanding of the RMF steps, especially Steps 4 through Steps 7
- Ability to identify upon review of a system authorization boundary and its components to identify all applicable STIGs
- Ability to decompose a security control/security check and ensure the provided artifact and test result satisfies said control/AP/check
- Understanding of techniques and tactics used to exploit systems (MITRE ATTACK) to determine risk and possible mitigations
- Ability to understand technical mitigations/know resources to identify proper mitigating factors (i.e. https://attack.mitre.org/mitigations/enterprise/ )
- Experience with eMASS to include control inheritance, TR Import, and POAM import functionality.
- Support conducting cybersecurity authorization activities to comply with all current Cybersecurity and IA manuals, instructions, and guides within the DoDI 8500.01, DON 5239, and Marine Corps ECSM’s.
- Verify patch compliance using the approved technical solution (i.e., Assured Compliance Assessment Solution (ACAS)), Information Assurance Vulnerability Alert (IAVA) compliance dashboards, and Microsoft Defender for Endpoints.
- Assist with the implementation of security procedures, and verify information system security requirements, including coordinating the execution, review, and disposition of Security Technical Implementation Guide (STIG) checklists for systems, applications, developed code and other components.
- Independently develop and maintain system security documentation, including drafting, reviewing, editing and recommending guidance for Standard Operating Procedures (SOP), Tactics, Techniques, & Procedures (TTP), Plan of Action and Milestones (POA&M) and Federal Information Security Management Act (FISMA) Score Card.
- Assist with the development and application of business processes to ensure they have the appropriate level of security
- Discuss and document the Ports, Protocols and Services (PPS) to include ensuring the dataflows are accurate, CAL boundaries crossed are compliant, and registrations with the AO are completed per DODI 8551.1
Benefits
- Competitive compensation
- Health and Wellness programs
- Income Protection
- Paid Leave
- Retirement
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
cybersecurity authorization servicesinformation system security engineeringRisk Management Framework (RMF)NIST SP 800-53 Rev4Assured Compliance Assessment Solution (ACAS)eMASSSecurity Technical Implementation Guide (STIG)MITRE ATTACKpatch compliancecybersecurity documentation
Soft Skills
communicationcoordinationtroubleshootingindependent developmentreviewingeditingguidance recommendationbusiness process applicationtimely issue resolutioncompliance monitoring
Certifications
DoD Secret Clearancesecurity certification (DOD 8570 IAT level III or higher)