20 hours ago
Base Salary
$108k - $195k/yr
Responsibilities
- Review and assess cybersecurity, architecture, engineering artifacts, and cybersecurity Body-of-Evidence results.
- Conduct compliance scanning, vulnerability assessments, and risk analysis for cloud-based systems.
- Implement and manage security controls for containerized applications and cloud infrastructure.
- Collaborate with DevSecOps, infrastructure, and software development teams on secure coding and engineering practices.
- Integrate security measures into software development processes, CI/CD pipelines, and engineering tools.
- Develop and maintain shell commands, scripts, and automation for STIG compliance and validation.
- Implement and manage continuous monitoring for cloud-based architectures.
- Support preparation of IATT, ATO, and Change Request cybersecurity packages.
- Track emerging cloud security threats, technologies, and practices.
Requirements
- Active or current Top Secret clearance with SCI eligibility and the ability to obtain a polygraph.
- Bachelor’s degree with 8-12 years of relevant experience or master’s degree with 6-10 years of relevant experience; additional experience may substitute for a degree.
- At least one DoD 8570.01-M IAT and one IAT Level II or higher certification, Linux+ certification, and ability to obtain PUA/elevated access.
- At least 5 years of experience hardening Linux hosts and applying DISA STIGs.
- Experience securing Kubernetes platforms, containers, CI/CD pipelines, and cloud-based systems.
- Experience developing A&A packages for obtaining and maintaining ATOs in secure environments.
- Knowledge of NIST SP 800-37, NIST SP 800-53, and CNSSI 1253.
- Experience with XACTA/eMass, ACAS vulnerability compliance, and STIG automation.
- Experience with Bash and Python scripting, secure software development, code reviews, encryption, transport security, microservices, and service mesh.
- Preferred qualifications include TS/SCI with polygraph, AWS or other commercial cloud experience, Intelligence Community RMF experience, Zero Trust experience, security scanning and monitoring tools, advanced cybersecurity, cloud, Kubernetes, and Linux certifications, AI security, and network engineering experience.
Benefits
- Most work is onsite at the client location in Bethesda, Maryland, with a flexible schedule and occasional remote work depending on client requirements.
- Paid time off and 11 paid holidays.
- 401(k) with a 6% company match and immediate vesting.
- Flexible schedules, discounted stock purchase plans, technical upskilling, education and training support, and paid parental leave.
Tech Stack
Categories
About Leidos
Leidos builds and operates technology and engineering solutions for defense, intelligence, civil, and health agencies, including systems integration, cyber, enterprise IT, sensors, and healthcare IT. It primarily sells through government contracts and long-term programs, plus managed services and mission software. Founded in 1969 and headquartered in Reston, Virginia, Leidos is a Fortune 500 public company on the NYSE; customers include U.S. defense and intelligence agencies and civil bodies such as the FAA.
