Traveling Security Control Assessor at Leidos performing RMF assessments, vulnerability testing, and eMASS reporting for DoD systems
Responsibilities
Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN
Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing
Adhere to policies and processes for each assessment type
Support assessment development and execution to ensure security expertise is properly applied
Coordinate logistics, test plans, and scope with the SCA Team Lead
Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS
Analyze security gaps and provide mitigation recommendations
Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines
Provide risk analysis and assessment results for authorization recommendations
Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R
Mentor and guide personnel if senior staff, providing technical expertise and professional development support
Travel domestically or internationally up to ~85% and work from home when not on assignment; initial 4-8 weeks of virtual training
Requirements
Active DoD Top Secret clearance with SCI eligibility required
Current DoD 8570 IAM II or IAT II certification
Ability and willingness to travel for assessments as required, up to 85% of the time
Bachelor's degree (IT-related field preferred) and five (5) years cybersecurity or network security experience for Level II (including three (3) years in a Certification and Accreditation/A&A role)
Bachelor's degree (IT-related field preferred) and eight (8) years cybersecurity or network security experience for Level III (including five (5) years in a Certification and Accreditation/A&A role)
Additional relevant experience may be considered in lieu of degree
Demonstrated experience with STIGs, SRGs, POA&Ms
Experience with tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS
Strong understanding of the RMF process, NIST SP 800-37, NIST SP 800-53, CNSSI 1253
Experience across Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, HBSS/Endpoint Security Solutions, Databases, Applications
Strong written and verbal communication skills
Must be local to Alexandria, VA, Fort Meade, MD, or Chambersburg, PA for training and occasional customer meetings
Senior Security Engineer focusing on hardening enterprise endpoints for cyber defense. Collaborating with NetSec and DataSec teams to minimize risks and enforce security protocols.
Security Consultant assessing and implementing security measures for organizations. Collaborating with clients to enhance their security posture and protect sensitive data.
Manager overseeing leadership protection and event security for GEICO. Responsible for security planning, threat analysis, and incident management during company events.
Cybersecurity Consultant managing TDR delivery team to enhance client security posture. Collaborating with clients and leading technical contributions in cybersecurity services.
Cyber Security & Compliance Lead protecting data and systems at Displayr. Responsible for risk management, compliance frameworks, and innovative security solutions using AI.
Lead Engineer in Security Engineering at Allstate overseeing security controls and product security teams. Collaborating with global stakeholders to manage security architecture and meet key performance indicators.
AI Security Architect focusing on AI security and governance for Voya Financial's applications and projects. Leading initiatives in artificial intelligence and securing innovative technology solutions.
Senior Analyst for Third - Party Security at a leading law firm. Responsible for program execution and risk assessment regarding vendors and service providers.
Application Architecture Engineer responsible for defining software architecture frameworks and leading implementation teams. Driving innovation in developing robust and scalable applications at Schneider Electric.
Security Officer managing safety and security at Cromwell Hospital and Canary Wharf locations. Responding to security requests and maintaining logs while ensuring compliance with safety regulations.