Cybersecurity ISSE
Job Description
Leidos is seeking a Cybersecurity Information System Security Engineer (ISSE) to design, integrate, and validate cybersecurity solutions across mission systems and lab/test environments. This on-site role is located in Beavercreek, OH near Wright Patterson AFB and supports RMF authorization and program compliance. The position offers a salary range of USD 87,100 - 157,450 per year.
Responsibilities
- Engineer cybersecurity solutions for mission systems, software applications, networks, lab environments, and integrated hardware/software platforms throughout the system lifecycle.
- Convert cybersecurity requirements, NIST SP 800-53 controls, RMF objectives, customer requirements, and mission needs into actionable designs, configurations, and verification methods.
- Develop, review, and maintain cybersecurity architecture artifacts, including security design descriptions, network boundary diagrams, data flow diagrams, control implementation details, interface descriptions, and system hardening approaches.
- Support cybersecurity design decisions for tactical networking and communications environments, addressing boundary protection, segmentation, authentication, encryption considerations, logging visibility, and tradeoffs in constrained settings.
- Collaborate with software, hardware, network, and systems engineering teams to implement secure configurations, authentication and authorization mechanisms, logging, encryption, boundary protections, vulnerability mitigations, and secure interfaces.
- Assist with secure system integration in Software Integration Laboratory and test environments, covering Linux system hardening, scripting/automation, vulnerability remediation, tool integration, and security configuration management.
- Conduct technical security assessments of systems, components, and configurations to identify design gaps, weaknesses, vulnerabilities, and cyber risk; propose and implement remediation plans.
- Lead or support vulnerability management activities, interpret scan results from Tenable Nessus, SCAP, STIG, ACAS, or similar tools; validate findings; develop fixes; coordinate remediation with engineers; verify closure.
- Design and implement mitigations for vulnerabilities uncovered during system scans, security audits, integration events, ground tests, and flight-test preparations.
- Support the implementation and validation of security controls, documenting how controls are satisfied, identifying residual risk, and providing objective evidence for RMF authorization packages.
- Participate in design reviews, engineering review boards, configuration control boards, cyber risk reviews, and test readiness events to ensure cybersecurity considerations are addressed prior to deployment.
- Develop or contribute to cybersecurity test procedures, security verification methods, risk assessments, and technical inputs for RMF artifacts, POA&Ms, system security plans, and authorization documentation.
- Evaluate cybersecurity events, anomalies, and system deficiencies to determine technical impact, root cause, mission risk, and corrective actions.
- Collaborate with ISSMs, ISSOs, system owners, and customer stakeholders to align technical cybersecurity implementations with program compliance, authorization, and operational objectives.
- Support continuous improvement of cybersecurity engineering practices, including automation, secure configuration baselines, vulnerability remediation playbooks, and repeatable lab/test environment security processes.
Requirements
- Bachelor’s degree in computer science, IT, cybersecurity or a related field with 4+ years of experience in the Cybersecurity ISSE discipline; an additional 4 years of experience may substitute for a degree.
- U.S. Citizenship is required.
- Active DoD Top Secret clearance with the ability to obtain and maintain TS/SCI.
- Security+ (8570) certification.
- Experience working in a Software Integration Laboratory environment.
- Strong working knowledge of Linux systems, including the ability to write Bash scripts and modify Linux security configurations.
- Solid understanding of information security policies, principles, and practices in IT service delivery.
- Proficiency with implementing security controls in line with NIST SP 800-53A.
- Experience with policies and procedures ensuring information system confidentiality, integrity, and accessibility.
- Experience conducting risk and vulnerability assessments to identify vulnerabilities and protection needs.
- Experience documenting system deficiencies and proposing remediation strategies.
- Familiar with automated vulnerability scanning tools such as Tenable Nessus, SCAP, or similar.
- Experience participating in security evaluations, audits, and reviews.
- A demonstrated ability to learn new technologies, tools, and engineering practices supporting ISSE duties, including secure design, control implementation, remediation, hardening, and test/validation activities.
- Strong written and verbal communication skills, with the ability to engage in one-on-one discussions or small-group settings.
- Able to work in a dynamic environment and manage multiple tasks concurrently.
Technologies
- Linux
- bash
- Tenable Nessus
- SCAP
- STIG
- ACAS
- Splunk
- Elastic
- Security Onion
- Zeek
- Suricata
- rsyslog
- syslog-ng
- auditd
- JIRA
- Confluence
- Bitbucket
Benefits
- Competitive compensation
- Health and Wellness programs
- Income Protection
- Paid Leave
- Retirement