Traveling Security Control Assessor at Leidos performing RMF assessments, vulnerability testing, and eMASS reporting for DoD systems
Responsibilities
Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN
Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing
Adhere to policies and processes for each assessment type
Support assessment development and execution to ensure security expertise is properly applied
Coordinate logistics, test plans, and scope with the SCA Team Lead
Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS
Analyze security gaps and provide mitigation recommendations
Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines
Provide risk analysis and assessment results for authorization recommendations
Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R
Mentor and guide personnel if senior staff, providing technical expertise and professional development support
Travel domestically or internationally up to ~85% and work from home when not on assignment; initial 4-8 weeks of virtual training
Requirements
Active DoD Top Secret clearance with SCI eligibility required
Current DoD 8570 IAM II or IAT II certification
Ability and willingness to travel for assessments as required, up to 85% of the time
Bachelor's degree (IT-related field preferred) and five (5) years cybersecurity or network security experience for Level II (including three (3) years in a Certification and Accreditation/A&A role)
Bachelor's degree (IT-related field preferred) and eight (8) years cybersecurity or network security experience for Level III (including five (5) years in a Certification and Accreditation/A&A role)
Additional relevant experience may be considered in lieu of degree
Demonstrated experience with STIGs, SRGs, POA&Ms
Experience with tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS
Strong understanding of the RMF process, NIST SP 800-37, NIST SP 800-53, CNSSI 1253
Experience across Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, HBSS/Endpoint Security Solutions, Databases, Applications
Strong written and verbal communication skills
Must be local to Alexandria, VA, Fort Meade, MD, or Chambersburg, PA for training and occasional customer meetings
Teaching and research role in Cybersecurity and AI at De Vinci School. Engaging in course design and research projects in a collaborative academic environment.
Apprentice Fire and Security Engineer installing, commissioning, and maintaining electronic protection systems for Johnson Controls. Collaborating in a team - based environment and gaining hands - on experience in fire and security technology.
Construction Site Superintendent overseeing construction projects for Johnson Controls, ensuring timely completion and adherence to project scope, budget, and schedule. Collaborating with teams and managing site activities in the United States.
Senior Security Architect providing security consulting and risk assessment at The Missing Link. Leading initiatives in security architecture and technology risk support within a hybrid work environment.
Data Protection Security Engineer at Fiserv designing, implementing, and maintaining cybersecurity solutions. Collaborating with teams to safeguard client information and ensure regulatory compliance.
Senior Manager IAM Metric Insights managing metrics and performance in Identity and Access Management. Delivering insights and reporting to enhance security posture for RBC's Global Security team.
HSE Technician I in TechnipFMC's HSE team promoting and supporting an HSE culture. Assisting with investigations, conducting audits, and maintaining safety documentation.
Information Security Officer creating security policies and managing security teams to protect Paytient. Collaborating with internal and external teams to ensure compliance and security posture.
Supplier Manager focused on Microsoft Security products at Arrow. Develops strategies to enhance sales and market share while collaborating with Microsoft and sales teams.
IT Infrastructure and Security Administrator at B&O Bau, managing IT security and infrastructure. Collaborating on innovative projects across multiple German locations.