Traveling Security Control Assessor at Leidos performing RMF assessments, vulnerability testing, and eMASS reporting for DoD systems
Responsibilities
Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN
Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing
Adhere to policies and processes for each assessment type
Support assessment development and execution to ensure security expertise is properly applied
Coordinate logistics, test plans, and scope with the SCA Team Lead
Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS
Analyze security gaps and provide mitigation recommendations
Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines
Provide risk analysis and assessment results for authorization recommendations
Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R
Mentor and guide personnel if senior staff, providing technical expertise and professional development support
Travel domestically or internationally up to ~85% and work from home when not on assignment; initial 4-8 weeks of virtual training
Requirements
Active DoD Top Secret clearance with SCI eligibility required
Current DoD 8570 IAM II or IAT II certification
Ability and willingness to travel for assessments as required, up to 85% of the time
Bachelor's degree (IT-related field preferred) and five (5) years cybersecurity or network security experience for Level II (including three (3) years in a Certification and Accreditation/A&A role)
Bachelor's degree (IT-related field preferred) and eight (8) years cybersecurity or network security experience for Level III (including five (5) years in a Certification and Accreditation/A&A role)
Additional relevant experience may be considered in lieu of degree
Demonstrated experience with STIGs, SRGs, POA&Ms
Experience with tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS
Strong understanding of the RMF process, NIST SP 800-37, NIST SP 800-53, CNSSI 1253
Experience across Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, HBSS/Endpoint Security Solutions, Databases, Applications
Strong written and verbal communication skills
Must be local to Alexandria, VA, Fort Meade, MD, or Chambersburg, PA for training and occasional customer meetings
IT Security Expert creating and managing SIEM solutions to strengthen Europe's defence capabilities. Collaborating in a small elite team to solve significant security challenges rapidly.
Senior Manager in Regulatory Compliance ensuring effective risk management within the Information Security Group. Overseeing regulatory compliance and governance while leading automation efforts.
Information Security Engineer overseeing security tasks, ensuring implementation of security controls. Collaborating with legal and technical teams in a professional office environment.
Security Administrator managing security across cloud and on - premises environments at Homecare Homebase. Collaborating with teams for patient care systems security and compliance.
Principal Security Engineer shaping security strategy for enterprise IT systems and software products at RedCloud. Leading a team to ensure robust security practices for business growth.
Security Lead at Qargo overseeing security strategy and implementation for a cloud - native transport platform. Collaborating with engineering to ensure compliance and resiliency across Europe.
Project Manager for cybersecurity at Consort Group, leading security solution implementations and client engagement. Collaborating within teams to execute comprehensive cybersecurity projects while ensuring client satisfaction.
Infrastructure Security Consultant deploying and implementing network security solutions at Consort Group. Responsible for analyzing and producing comparative syntheses of security solutions with a hybrid work arrangement.
Cyber Security Engineer responsible for application security and vulnerability management for Consort Group. Supporting secure development practices and collaborating with development teams to identify and mitigate security risks.
Cybersecurity Intern supporting Keenova's security program through hands - on experiences and mentorship. Engaging in various cybersecurity functions and contributing to meaningful projects.