-
Senior Information System Security Officer (ISSO)
- Leidos (Tucson, AZ)
-
Description
Leidos National Security Sector combines technology-enabled services and mission software capabilities in the areas of cyber, logistics, security operations, and decision analytics to support our defense and intel customers’ mission to defend against evolving threats around the world. Our team’s focus is to ensure our customers have the right tools, technologies, and tactics to keep pace with an ever-evolving security landscape and succeed in their pursuit to protect people and critical assets.
The Intelligence Production Solutions Division (IPSD), part of the Decision Advantage Solutions Business Area, is currently seeking an Information System Security Officer (ISSO) for the Chinook Program. The ISSO will be responsible for managing the authorizations and risks related to the processing, storage, and transmission of information for one or more programs within the Analysis Sustainment portfolio. The ISSO is responsible for meeting regulatory and non-regulatory compliance (security best practices) demands, providing leadership over security assessment activities, working across system ownership and management organizations to test security controls, policies, and procedures, providing program management support, team leadership, and participating in and coordinating the support as needed for security assessment and activities The ISSO also manages and enforces government and corporate information security policies, provides training, and educates end users and program staff about proper security practices.
The ISSO conducts security and risk assessments as required using a range of security accreditation frameworks (e.g., NIST, RMF, Common Criteria, DoD, the Intelligence Community Directives (ICDs)),and works to mitigate risks by applying security controls effectively to achieve an acceptable degree of operational risk. As part of this process, the ISSO performs testing and security assessments to sustain required accreditations. The ISSO promotes the use of secure hardware and software within the systems affected by government and corporate approval standards. The ISSO works to ensure all required security policies and practices are effectively applied to systems and ensures security controls implementing these policies are applied and achieve the proper levels of confidentiality, integrity, availability, and privacy protection throughout the system life cycle.
The ISSO also assists with the execution, analysis, and remediation activities for the vulnerability management program (scanning, assessment, reporting, and mitigation verification) that spans different accreditation entities, three distinct classification domain enclaves (U), (S), and (TS), using the Nessus and Tenable-ACAS vulnerability scanning tools.
•Position may be performed in the following locations below. Please note Gaithersburg, MD is the program’s primary work location.
+ Gaithersburg, MD
+ Alexandria, VA
+ Chantilly, VA
+ Aurora, CO
+ St. Louis, MO
+ Tucson, AZ
Clearance Level Required:
Top Secret with the ability to obtain SCI, as well as a Polygraph.
Primary Responsibilities:
+ Develop risk mitigation strategies that contribute to the effectiveness, efficiencies, and performance outcomes for strategic projects, program goals, and business processes.
+ Respond to the needs for updates and maintenance of security documentation, especially System Security Plans, Plans of Actions and Milestones (POA&Ms); Security Impact Assessment for proposed system changes, and Concept of Operations that identify and explain how each system satisfies its assigned security control baselines.
+ Maintain system security plans and related configuration records in customer Service+ (ServiceNow), XACTA-360 platform, and Leidos-CIO security tools.
+ Drive security changes through steering groups and control (review) boards to meet Risk Management milestones.
+ Work independently as well as collaboratively to drive security process improvements, especially to address gaps in meeting customer or Leidos security requirements and meet due diligence responsibilities.
+ Provide guidance and engage the program lab team to implement secure software and hardware processes, apply government security standards, and commercial best security practices.
+ Resolve highly complex security problems by applying technical knowledge, conceptualizing, reasoning, and interpretation of requirements.
+ Communicate with Leidos and customer leadership (internally or client) regarding matters of significant importance to the organization/project.
+ Apply in-depth understanding of information security technical principles, theories, concepts, and their application across a range of programs.
+ Develop and maintain security documentation per customer/IC/DoD-DISA/NIST/Industry standards and policies.
+ Initiate and coordinate all Assessment and Authorization (A&A) and renewal activities working with the customer Designated Authorization Officials (DAO or DAOR).
+ Address any Information Assurance or Cybersecurity notices, orders, tasking, or directives as required following the NGA operations vulnerability and patch management processes.
+ Measure effectiveness of defense-in-depth architecture and Zero Trust policy implementations against known vulnerabilities.
+ Perform security audits and assessments, including creating, tracking, and assisting in remediation of Plan of Action and Milestones (POA&Ms).
+ Coordinate with System Administrators and others to remediate all vulnerabilities and report results. Track open vulnerabilities, obtain and document approvals while managing POA&M status.
+ Update Security CONOPS and Information Technology Disaster Recovery (ITDR) plans for each Security Plan.
+ Manage security profiles and implementation for systems and services scheduled for Assessment and Authorization (A&A).
+ Collaborate with the Systems Engineers and Administrators, Senior ISSO, ISSMs, Lab Team, and Leidos Corporate Security as required to develop and maintain security plans and associated documentation.
+ Maintain records and documentation on program IT systems, upgrades, patches, and connectivity configurations.
+ Evaluate security solutions and implementation strategies for program IT systems and services and maintain operational security posture of development, integration, and deployed capabilities.
+ Provide training and approve user access and IAA (identification, authorization, and authentication) mechanisms for information systems.
Basic Qualifications:
+ **US citizenship is required per contract.**
+ BS degree and 8 to 12 years of prior relevant experience to operate within the scope of responsibilities.
+ Familiarity with customer mission operations, and security.
+ Demonstrated understanding and application of the ICD-503 and NIST risk management framework.
+ Experience with the following systems/platforms/tools:
+ XACTA
+ XACTA 360 (preferred)
+ HBSS
+ ACAS
+ Nessus
+ SPLUNK
Preferred Qualifications:
+ 3+ years of experience operating, analyzing, and resolving vulnerability scan results using tools such as Nessus, Tenable Security Center, or a comparable commercial or GOTs product.
+ Active Certified Information Systems Security Professional (CISSP) certification or ISACA Certified Information Security Manager (CISM) certification.
+ Intelligence Community experience preferred.
\#Chinook
Come break things (in a good way). Then build them smarter.
We're the tech company everyone calls when things get weird. We don’t wear capes (they’re a safety hazard), but we do solve high-stakes problems with code, caffeine, and a healthy disregard for “how it’s always been done.”
Original Posting:
October 9, 2025
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $104,650.00 - $189,175.00
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
REQNUMBER: R-00168495-OTHLOC-PL-2D2761
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. Leidos will consider qualified applicants with criminal histories for employment in accordance with relevant Laws. Leidos is an equal opportunity employer/disability/vet.
-
Recent Jobs
-
Senior Information System Security Officer (ISSO)
- Leidos (Tucson, AZ)
-
Lead Technical Program Manager - Data Strategy & Reporting
- JPMorgan Chase (Jersey City, NJ)
-
Senior Manager, FP&A
- Coinbase (Jackson, MS)
-
Project Manager - Enterprise Contact Center
- Stanford Health Care (Newark, CA)