Information System Security Manager
LeidosAbout the role
The Digital Modernization Sector at Leidos currently pursuing a new opportunity that has openings for an Information System Security Manager (ISSM) to work in
Tampa, FL. This is an exciting opportunity to use your experience helping the U.S. Special Operations Command (USSOCOM) Enterprise Development, Application, and Training (EDAT) mission. In this mission
we are focused on providing innovative, data-driven solutions and enterprise architecture enhancements to enable seamless operations across USSOCOM's global network. The program emphasizes rapid
development and deployment of technologies to enhance the mobility and readiness of Special Operations Forces (SOF) in both combat and non-combat scenarios. Key tasks include program management,
application development, training support, and technology integration to maintain USSOCOM's operational edge. The EDAT program underscores agility and adaptability, ensuring SOF professionals have access to
the information and tools they need to meet evolving mission requirements.
Primary Responsibilities:
Develop and implement comprehensive information system security strategies to protect against cyber threats and ensure the confidentiality, integrity, and availability of sensitive information, aligning with organizational goals and objectives.
Oversee the development and maintenance of Authorization to Operate (ATO) packages, ensuring compliance with relevant security controls and requirements, and guide the ATO process from risk assessment to continuous monitoring.
Provide oversight and guidance for vulnerability assessments, ensuring that identified weaknesses are properly addressed through effective remediation strategies and risk mitigation plans.
Develop and maintain incident response plans and procedures, ensuring timely and effective incident handling, and providing technical leadership and support to respond to and resolve security incidents.
Ensure compliance with industry standards and government regulations, including NIST 800-53 and DISA STIG, by developing and implementing compliance plans, providing guidance on audit preparation, and overseeing remediation efforts.
Lead the integration of security into the software development lifecycle, providing guidance on secure coding practices, secure development methodologies, and ensuring that security requirements are incorporated into system design and development.
Oversee the development and maintenance of security documentation, including security plans, risk assessments, and incident response plans, ensuring that all documentation is accurate, up-to-date, and compliant with relevant regulations and standards.
Provide technical leadership and guidance to ensure the security of systems and applications, staying current with industry trends and emerging technologies to continuously improve the organization's security posture.
Develop and implement comprehensive vulnerability management processes, including scanning, assessment, reporting, and mitigation verification, to identify and remediate vulnerabilities in a timely and effective manner.
Develop and implement data protection policies and procedures to ensure the privacy of data throughout its life-cycle, from creation to disposal, and provide guidance on safeguarding sensitive information.
Basic Qualifications:
Bachelor’s degree in Computer Science, Cybersecurity, or a related field, with 4+ years of prior relevant experience, or a Master's degree with 2-6 years of prior relevant experience.
Must possess a Top-Secret clearance.
Relevant technical certifications, such as Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC), or equivalent.
Deep understanding of information system security principles, theories, and concepts.
Broad knowledge of related specialty areas, including compliance reporting, data encryption, and risk management.
Strong skills in security controls, security management, and risk analysis.
Experience with information system security tools and technologies, such as firewalls and encryption technologies.
Familiarity with industry standards, laws, corporate policies, and regulatory requirements, including NIST 800-53 and DISA STIG.
Ability to apply knowledge of security controls and risk management to protect digital information.
Strong analytical and problem-solving skills to identify and mitigate potential risks.
Proven experience managing the Authorization to Operate (ATO) process, with a minimum of one successfully completed ATO under th
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s