Cyber CISO, Consolidated Nuclear Security
LeidosAbout the role
Leidos is seeking a Cyber Chief Information Security Officer (CISO) in Oak Ridge TN, to support a Leidos joint venture, Consolidated Nuclear Security, LLC (CNS). Remote work options are not available.
About CNS: Leidos is a member company of the joint venture Consolidated Nuclear Security, LLC (CNS). CNS manages and operates the Y-12 National Security Complex in Tennessee under a single contract from the U.S. Department of Energy/NNSA. Y-12 helps ensure a safe and effective U.S. nuclear weapons deterrent by retrieving and storing nuclear materials, fueling the nation’s naval reactors, and performing complementary work for other government and private-sector entities. Y-12 is our nation’s Uranium Center of Excellence.
Must currently possess or be able to obtain/maintain a DOE Q clearance.
The Information Solutions and Services (IS&S) organization is dedicated to providing information services and technology that enable staff to be productively engaged in the NNSA nuclear security mission. The Chief Information Security Officer (CISO) will report to the Chief Information Officer (CIO) and is responsible for managing a broad range of complex cyber operations, risk management, and digital transformation enablement activities. This leadership role requires deep and current practical experience in cybersecurity and risk management. The CISO will implement the vision and strategic direction set by the Consolidated Nuclear Security (CNS), LLC Executive Leadership Team (ELT) and provide a full inventory of all authorization boundaries, risk identification, and mitigation strategies to the CIO and Authorizing Official. This position encompasses responsibility for Information Technology (IT), Operational Technologies (OT), Digital Transformation (DT), and Cybersecurity at the Y-12 National Security Complex (NSC) Site in Oak Ridge, TN.
Primary Duties and Responsibilities:
- Serve as the primary cybersecurity lead for CNS.
- Mature the NIST-based Risk Management Framework (RMF) action plan and integrate it into all information system authorization boundaries and Authorization to Operate (ATO) packages.
- Maintain a full inventory of all information system authorization boundaries and ATO packages with a proactive schedule to ensure all systems remain authorized and operational.
- Maintain liaison with other CISOs in the NNSA Nuclear Security Enterprise (NSE) and attend all virtual and physical meetings to ensure effective collaboration.
- Ensure the Deputy CISO, Authorization Manager, ISSOs, and ISSM positions are filled and maintain liaison and collaboration with the contractor Authorization Official Designated Representative (AODR) and AO.
- Ensure risk-balanced security measures are integrated into all site nuclear security systems, facilities, infrastructures, IT projects, OT projects, and activities.
- Maintain an understanding of current and emerging cyber threats and make recommendations for mitigation to the CIO and Authorizing Official.
- Lead the development, ongoing improvement, and maintenance of the Y-12 cybersecurity architecture.
- Collaborate with IS&S, DT&M, operations, and engineering managers to develop, implement, and operate an integrated Network Operations Center/Security Operations Center (NOC/SOC).
- Perform outreach to internal mission, business, and engineering leaders to facilitate innovative solutions, including support for digital engineering, digital transformation, and artificial intelligence, that balance cybersecurity risk and mission enablement.
- Maintain timely and effective communication with stakeholders to resolve cybersecurity issues, including the development and maintenance of employee cybersecurity training.
- Plan, prioritize, and coordinate assignments of cybersecurity staff to projects.
- Propose and provide input into IS&S architecture efforts to enhance detection, analysis, containment, and response.
- Manage compliance activities to support the contractor assurance program (e.g., patching and mitigation actions to resolve vulnerability scans).
- Establish cyber metrics to gauge program effectiveness and perform internal audits and assessments.
- Develop policies and procedures to ensure appropriate cyber controls and monitoring are in place to ensure the confidentiality, integrity, and availability of CNS and NNSA information.
- Maintain security log infrastructure to monitor, analyze, and respond to log anomalies. Conduct packet capture analysis and ensure the logging infrastructure is monitored for risks to CNS and NNSA information.
- Manage intrusion detection/prevention systems, maintain continuous monitoring systems, and provide timely network traffic analysis.
- Support the CIO and other cybersecurity per
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s