Risk Management Framework / Information Assurance Engineer

Fort Belvoir, Virginia

Leidos
Apply for this Job
Description

Leidos is excited to invite applications for the position of RMF/Information Assurance Engineer. You will play a crucial role in supporting a large-scale migration and operations for a prominent DOD contract, helping DTRA's Information Management & Technology Directorate (ITD) to modernize and improve the delivery of IT services for its mission partners both domestically and internationally.

Primary Responsibilities
  • Continuously monitor and analyze information system, network, and security events, responding effectively to incidents.
  • Maintain the NIPR and SIPR RMF packages for all relevant enclaves within the contract's scope.
  • Document compliance actions in the automated compliance tracking system approved for use.
  • Ensure that systems are operated, maintained, and disposed of according to established internal security policies outlined in the System Security Plan (SSP), Standard Operating Procedures (SOP), and customer directives.
  • Maintain records for workstations, servers, software, routers, firewalls, network switches, crypto, and other hardware throughout the information system's lifecycle.
  • Evaluate proposed changes to the information system, advising senior leadership on security implications.
  • Participate in internal and external security audits and inspections, conducting risk assessments and Continuous Monitoring.
  • Implement proper protective measures in response to identified incidents or vulnerabilities.
  • Collaborate with the Facility Security Officer (FSO) to manage a comprehensive Information Security / Information Systems Security Program.
  • Develop, implement, and enforce robust Information Security Policies and Procedures.
  • Review and update IS Authorization documentation to support Assessment and Authorization (Certification/Accreditation) activities.
Basic Qualifications
  • Bachelor's degree with 8+ years of experience, or 12+ years of IA experience without a degree.
  • Current DoD 8570 baseline certification for IAM III.
  • Solid understanding of Risk Management Framework (RMF), NIST, ICD, and CNSS standards.
  • Familiarity with LAN and WAN network technologies and best practices in classified environments, including crypto and key management.
  • Experience with STIG compliance, STIG Viewer, and ACAS.
  • Proficient in Microsoft Windows, Linux, and system virtualization within secure network environments.
  • Ability to navigate a constantly evolving regulatory environment with clear timelines for addressing non-compliance.
  • Effective team player who can adapt to change quickly.
  • Strong writing and verbal communication skills.
  • Active DoD Top Secret Clearance with eligibility for SCI.
Preferred Qualifications
  • Experience in an ISSM/ISSO role.
  • Security+ or CISSP certification preferred.
  • GCIH certification is a plus.
  • Knowledge and experience in DoD Information Systems.
  • Background in developing System Security Plans (SSP).
  • Experience in security hardening, scripting, or automation.
  • Microsoft OS Certification (MCSE Win 7 or equivalent).
  • Linux certification (e.g., RHCSA, CompTIA Linux, LCFS/LCFE).
Original Posting:

March 27, 2025

For U.S. Positions: Leidos anticipates this job requisition will remain open for at least 3 days from the original posting date.

Pay Range:

Pay Range $104,650.00 - $189,175.00

The Leidos pay range for this job level is a guideline and not a guarantee of salary. Factors considered include job responsibilities, education, experience, skills, internal equity, and market data alignment.

Date Posted: 05 April 2025
Apply for this Job