Traveling Security Control Assessor at Leidos performing RMF assessments, vulnerability testing, and eMASS reporting for DoD systems
Responsibilities
Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD information or connecting to the DoDIN
Evaluate systems and Defensive Cyberspace Operations using cyber threat emulation and performance-based testing
Adhere to policies and processes for each assessment type
Support assessment development and execution to ensure security expertise is properly applied
Coordinate logistics, test plans, and scope with the SCA Team Lead
Perform vulnerability assessments, capture results using STIG Viewer or designated tools, and document findings in eMASS
Analyze security gaps and provide mitigation recommendations
Validate cybersecurity controls, TTPs, STIGs, RMF controls, and compliance with DoD policies and guidelines
Provide risk analysis and assessment results for authorization recommendations
Participate in daily assessment reviews, in-briefs, and out-briefs, sharing findings with the SCA-R
Mentor and guide personnel if senior staff, providing technical expertise and professional development support
Travel domestically or internationally up to ~85% and work from home when not on assignment; initial 4-8 weeks of virtual training
Requirements
Active DoD Top Secret clearance with SCI eligibility required
Current DoD 8570 IAM II or IAT II certification
Ability and willingness to travel for assessments as required, up to 85% of the time
Bachelor's degree (IT-related field preferred) and five (5) years cybersecurity or network security experience for Level II (including three (3) years in a Certification and Accreditation/A&A role)
Bachelor's degree (IT-related field preferred) and eight (8) years cybersecurity or network security experience for Level III (including five (5) years in a Certification and Accreditation/A&A role)
Additional relevant experience may be considered in lieu of degree
Demonstrated experience with STIGs, SRGs, POA&Ms
Experience with tools such as eMASS, STIG Viewer, Nessus, ACAS, SCAP, or HBSS
Strong understanding of the RMF process, NIST SP 800-37, NIST SP 800-53, CNSSI 1253
Experience across Network, Mobility, Windows, UNIX, Cloud Environments and Cloud Native Tools/Services, HBSS/Endpoint Security Solutions, Databases, Applications
Strong written and verbal communication skills
Must be local to Alexandria, VA, Fort Meade, MD, or Chambersburg, PA for training and occasional customer meetings
Product Security Engineer at Junglee Games ensuring security is integrated into each stage of the software development lifecycle. Collaborate across teams and harden the security of products and platforms.
Senior Penetration Testing Analyst collaborating with DoD and other teams on cybersecurity solutions. Conducting penetration tests and assessments to enhance security across various environments.
Senior Cybersecurity Documentation Specialist managing Risk Management Framework initiatives for Leidos. Supporting cybersecurity documentation and compliance activities across departments with a focus on national security.
Security Engineer role at Contour Software focused on IT administration and security operations. Ensuring tools and systems are secure and aligned with best practices across the organization.
First Vice President driving Axos Bank's information security strategy and leading a high - performing team. Architecting solutions and leading technical initiatives within a fast - paced environment.
Mid to Senior Data Engineer joining CrowdStrike's Cloud Identity & Perimeter team. Focus on developing and maintaining complex data pipelines and security analytics at scale.
Cybersecurity Assessor evaluating enterprise systems for vulnerabilities and compliance. Engaging in assessments and reporting within a hybrid work structure based in Brooklyn Heights, NY.
Security Business Analyst engaging in requirements gathering, risk assessments, and stakeholder liaison. Supporting measurable security outcomes with comprehensive documentation in a hybrid work setup.
Senior Software Engineer developing engaging gamified learning experiences for cybersecurity awareness. Driving technical leadership and product ownership in a rapidly growing team.
Cyber Security Engineer providing cybersecurity support for SCADA, OT networks and industrial control systems at Vestas. Collaborating with cross - functional teams to ensure secure operations in offshore wind farms.