Security Operations Lead
LeidosAbout the role
At Leidos, innovation is at the heart of everything we do. Powered by a team as diverse as it is talented, we're driven by a shared passion for delivering bold solutions that fuel our customers' success. We empower our teams, contribute to our communities, and operate sustainably. Every action we take is grounded in integrity and a steadfast commitment to doing what’s right—for our customers, our teams, and the world around us. Our Mission, Vision, and Values aren't just words—they're the compass guiding our journey toward a brighter future.
The Leidos Digital Modernization Sector is seeking a highly experienced Security Operations Lead to work on a key program supporting the U.S. Department of State as the Manager over a team responsible for implementation of all Security controls in coordination with the ISSO and other teams for the systems under our purview and maintain an active Authorization to Operate (ATO) to include, primarily, the Consular Consolidated Database (CCD) and databases, applications as well as the SOA stack and any applications this team develops . This role serves as the primary interface for the Security Operations function and frequently interfaces with the other functional teams and the Program Management Office working in coordination with the government, overseeing all aspects of scope status.
The Security Operations Lead will be responsible for the overall execution and success of the primary team responsible for management of ATO including continuous ATO, ATO package management, audit support and controlling implementations and all other security requirements on program, as well as providing leadership, strategic direction, and day-to-day oversight for all team personnel. This includes ensuring technical excellence, operational efficiency, and ensuring Service Level Agreement metrics are exceeded.
The ideal candidate will be proactive, responsive, and collaborative, with the ability to build and lead high-performing teams, maintain strong customer relationships, and identify opportunities for continuous improvement.
Key Responsibilities:
Serve as the lead for security operations across CCD, database applications, the SOA stack, and other systems under the team’s purview.
Serve as the primary point of contact to the Government and program leadership for security operations status, risks, findings, remediation progress, and deliverables.
Lead, manage, and direct contractor personnel assigned to the security operations function.
Implement, monitor, and maintain required security controls in coordination with the ISSO and other CST teams.
Maintain active Authority to Operate (ATO) status for supported systems and lead preparation, update, and support of authorization packages and annual security assessment activities.
Manage information assurance and security compliance for production and non-production environments, ensuring alignment with development, engineering, and architectural standards.
Ensure data security, data quality, and access controls are enforced across supported systems and environments.
Review application and database scripts, database configurations, and related technical artifacts for security violations and compliance gaps.
Review and approve roles, privileges, and access requests in accordance with least-privilege principles.
Lead POA&M management, remediation planning, and creation of remediation scripts for IV&V testing and deployment.
Resolve database-level security issues and support response to cyber incidents, urgent security findings, and operational security events.
Ensure supported systems can withstand recurring vulnerability scans every 72 hours and support annual DHS security architecture reviews, risk assessments, and mitigation activities.
Proactively identify and eliminate vulnerabilities to maintain no high or moderate security findings.
Develop, maintain, and update all required security documentation, including SSPs, ISCPs, PIAs, ISAs, and related artifacts.
Document security controls using Department of State processes and templates, support control validation testing, and cooperate fully with audits, reviews, evaluations, and assessments.
Ensure compliance with NIST SP 800-53, Department of State technical security foundations, approved configuration guides, and release baselines; develop security/configuration guides where no Department guidance exists.
Coordinate with the ISSO on planned software changes to support A&A requirements before production deployment and maintain current security boundaries in the SSP.
Support contingency planning, disaster recovery, COOP planning, and annual recovery/se
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s