Senior Information Security Engineer
Leidos
- Location
- 6314 Remote/Teleworker US
- Work model
- Remote
- Level
- Senior
- H-1B history
- 26 approvals (FY2023)
- Posted
- 14h ago
Skills
About this role
Job Description
The Digital Sector at Leidos currently has an opening for a Senior Information Security Engineer to support the Department of Veterans Affairs’ Office of Information & Technology (OIT). In this contract, Leidos assists with the underlying infrastructure, tools, and operational services used to build, deploy, secure, and run VA health applications. The Senior Information Security Engineer plays a critical role in advancing cybersecurity operations for mission-critical Federal cloud environments by leading RMF activities, ATO/ATC efforts, security assessments, continuous monitoring, vulnerability management, and risk remediation. This position develops and maintains key security documentation, supports audits and authorization activities, and drives the implementation of security governance, incident response, and access control practices in alignment with Federal cybersecurity requirements and NIST standards.
Primary Responsibilities
The selected candidate will: Support all six steps of the NIST RMF lifecycle and develop/maintain required RMF documentation and security diagrams Prepare, submit, and track ATO/ATC packages and reauthorization efforts across HAPS capabilities, services, and hosted applications; ensure no lapse in ATO status Conduct and coordinate recurring vulnerability scans across infrastructure, containers, applications, and code repositories; track findings through POA&M closure within Government-defined timelines Draft and maintain Incident Response Plans and Disaster Recovery Plans, including RACI charts, and host/support annual IRP/DRP tabletop exercises Support all security audits and assessments (e.g., IG, SAVD, CCTF, OIS, ISRM, GRC, and independent assessors such as MITRE or Palo Alto), including documentation, findings review, and closeout meetings Maintain required security documentation (SIA, PIA, PTA, ISCP, SAP, SAR, Configuration Management Plan) and diagrams (ICD, HLD, security assessment boundary diagrams) Conduct periodic user access/account audits, enforce least-privilege and role-based access controls, and rotate service account credentials per VA policy and NIST guidelines Prepare and submit the Monthly RMF, Security, and ATO Status Report, clearly flagging deficiencies, emerging risks, and significant changes on the first page Support Technical Reference Model (TRM) software authorization submissions and Business Partner Extranet (BPE) connection request management as needed. This position requires some light travel.
Basic Qualifications
Candidates should possess: Bachelors degree in Cybersecurity, Computer Science, Information Technology, or a related field. Minimum of 12 years of experience in information security, cybersecurity engineering, or RMF compliance within Federal or DoD environments; candidates without a degree must have at least 18 years of relevant experience. Experience managing ATO/ATC activities Security assessments Continuous monitoring SNOWCAM Nessus scanning Vulnerability remediation Audit coordination Incident response planning Enterprise security governance Experience preparing and maintaining Authority to Operate (ATO)/Authority to Connect (ATC) packages and supporting artifacts (e.g., SSP, SAP, SAR, POA&M, ISCP) Experience conducting or coordinating vulnerability scanning, patch/remediation tracking, and continuous monitoring reporting for cloud-hosted platforms Experience developing and maintaining Incident Response Plans (IRP) and Disaster Recovery Plans (DRP), including facilitating tabletop exercises Working knowledge of applicable federal security and privacy requirements (FISMA, NIST 800-53, HIPAA, Privacy Act, FIPS) The ability to obtain and maintain a Public Trust security clearance. The ability to travel, as needed, to customer sites. Must have a US Citizenship.
Preferred Qualifications
The ideal candidate will bring: Experience supporting VA-specific RMF/ATO systems and processes (e.g., SNOWCAM, ICAMP,