Traveling Security Control Assessor at Leidos performing RMF assessments, vulnerability testing, and eMASS reporting for DoD systems
Responsibilities
Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN
Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing
Adhere to policies and processes for each assessment type
Support assessment development and execution to ensure security expertise is properly applied
Coordinate logistics, test plans, and scope with the SCA Team Lead
Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS
Analyze security gaps and provide mitigation recommendations
Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines
Provide risk analysis and assessment results for authorization recommendations
Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R
Mentor and guide personnel if senior staff, providing technical expertise and professional development support
Travel domestically or internationally up to ~85% and work from home when not on assignment; initial 4-8 weeks of virtual training
Requirements
Active DoD Top Secret clearance with SCI eligibility required
Current DoD 8570 IAM II or IAT II certification
Ability and willingness to travel for assessments as required, up to 85% of the time
Bachelor's degree (IT-related field preferred) and five (5) years cybersecurity or network security experience for Level II (including three (3) years in a Certification and Accreditation/A&A role)
Bachelor's degree (IT-related field preferred) and eight (8) years cybersecurity or network security experience for Level III (including five (5) years in a Certification and Accreditation/A&A role)
Additional relevant experience may be considered in lieu of degree
Demonstrated experience with STIGs, SRGs, POA&Ms
Experience with tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS
Strong understanding of the RMF process, NIST SP 800-37, NIST SP 800-53, CNSSI 1253
Experience across Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, HBSS/Endpoint Security Solutions, Databases, Applications
Strong written and verbal communication skills
Must be local to Alexandria, VA, Fort Meade, MD, or Chambersburg, PA for training and occasional customer meetings
Consultant technique pour Microsoft 365 Security à Ingram Micro, impliqué dans le support avant - vente et le déploiement des solutions cloud Microsoft.
Specialist in Information Security at IESO ensuring security for Ontario's electricity system. Responsibilities include monitoring access logs, delivering security programs, and investigating breaches.
Partner Sales Specialist focusing on enabling partners to sell Microsoft Security solutions. Collaborating with teams to activate partners for effective sales across their customer base.
Cybersecurity Engineer enhancing enterprise security posture at GDIT. Designing secure identity controls and managing authentication solutions for Microsoft environments.
Activity Security Representative providing multi - disciplined security support for a customer’s facility at GDIT. Role involves ensuring security protocols and maintaining documentation for classified materials.
Information Security Officer developing risk management systems and collaborating with stakeholders for a tech company. Working on information assets and engineering teams in a hybrid working environment.
Security Lead managing GSA cloud applications security architecture. Collaborating with teams to ensure compliance with federal security standards and best practices.
Security Officer providing safety and security services in East Valley locations for Banner Health. Involves emergency response, patrols, alarm monitoring, and writing reports.
Security Engineer contributing to security initiatives for incident management platform at Rootly. Collaborating cross - functionally to ensure reliable and scalable security solutions.
Lead Senior Information System Security Manager (ISSM) for Boeing's cybersecurity programs. Focus on implementing compliance for DFARS/NIST and managing a large portfolio for CUI.