Information System Security Officer and POAM Manager

Posted:
11/12/2024, 4:00:00 PM

Location(s):
Virginia, United States

Experience Level(s):
Mid Level ⋅ Senior

Field(s):
IT & Security


The Leidos Digital Modernization Sector has a career opportunity for an Information System Security Officer and POAM Manager in support of the Air Force National Capital Region IT Services program.

The AFNCR IT Services program provides support services for information systems for Headquarters Air Force (HAF), Air Force District of Washington (AFDW), Office of the Secretary of Defense (OSD), Joint Chiefs of Staff, and other Air Force activities within the AFNCR, missions to include the Pentagon, Joint Base Andrews (JBA), Joint Base Anacostia-Bolling (JBAB), and other locations, leased spaces, and alternate sites. The major support areas required are IT Operations and Maintenance; Plans, Projects, and Engineering (PP&E); and National Military Command Center (NMCC). The senior leaders and national defense missions that are supported require that the AFNCR operations never fail, resulting in a fast-paced, challenging, but also rewarding environment. 

If this sounds like the kind of environment where you can thrive, keep reading!

The Leidos Digital Modernization Sector provides a diverse portfolio of systems, solutions, and services covering land, sea, air, space, and cyberspace for customers worldwide. Solutions for Defense include enterprise and mission IT, large-scale intelligence systems, command and control, geospatial and data analytics, cybersecurity, logistics, training, and intelligence analysis and operations support. Our team is solving the world’s toughest security challenges for customers with “can’t fail” missions. 

To explore and learn more, click here!

Are you ready to make an impact? Begin your journey of a flourishing and meaningful career, share your resume with us today!


Primary Responsibilities:

  • Must be able to work in a constantly changing regulatory environment with short, mid, and long term timelines for remediating any non-compliance.

  • Must be able to work well within a team environment and able to adapt quickly to change.

  • Identify key stakeholders in A&A efforts and ensure system documentation reflects current system security configurations to include hardware and software components, data flow, interconnections, and ports, protocols, and services, etc.

  • Maintain cybersecurity procedures and processes as assigned.

  • Able to analyze, interpret, and apply Federal cybersecurity guidance to customer needs.

  • Communicate the security posture of systems through designated reporting mechanism.

  • Assist in preparation and review documentation to include System Security Plans (SSPs), Risk Assessment Reports (RAR), and other Assessment & Authorization (A&A) artifacts

  • Assist in the research and address information security issues as required, and develop and maintain the Plan of Action and Milestones (POA&M) and support remediation activities

  • Develop and advise development of Assessment and Authorization (A&A) artifacts and security documentation to include, but not limited to System Security Plans (SSP), Plan of Action and Milestone (POAM), Contingency Plan, Incident Response Plan, Configuration Management Plan.

  • Assist with pre-assessment preparation.

  • Perform Risk Management Framework (RMF) activities to achieve Authority to Operate (ATO).

  • Perform continuous monitoring of security controls to ensure that they are implemented correctly, operating as intended, and producing the desired outcome with respect to meeting the cybersecurity requirements for assigned IT systems.

  • Advise system owners on all matters, technical and otherwise, involving the security of assigned IT systems.

  • Strong verbal and written skills required providing management status reports and document system changes.

  • Analyze problems and provide focused solutions to effectively communicate information to various audiences verbally and through written communications.

  • Conduct reviews of closed Plan of Actions and Milestones (POA&M) for completeness and compliance.

  • Develops and maintains POA&Ms and supports remediation activities.

  • Experience with continuous monitoring and Plans of Actions and Milestones (POA&Ms).

Basic Qualifications:

  • Bachelors degree and 4+ years of relevant experience, additional years of applicable experience will be accepted in lieu of a degree.

  • Active TS/SCI Security Clearance.

  • Current DoD 8570 baseline certification for IAT II (one of the following: GSEC, Security+, SCNP and SSCP certifications).

  • 3+ years of Cyber Security experience.

  • 2 Years of IT experience (Networking/System Administration). 

  • Working knowledge of security system controls, policies, technical security safeguards, and operational security measures.

  • Familiarity with DoD STIG process.

  • Excellent verbal and written communication skills.

  • Executing the security assessment and authorization (or ATO) process with independent assessors.

  • Executing Continuous Monitoring and maintaining the security posture of IT systems day to day.

  • To include familiarity with eMASS and XACTA.

Original Posting Date:

2024-11-13

While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $81,250.00 - $146,875.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.