Information Assurance Security Analyst
LeidosAbout the role
Are you ready for a rewarding career challenge?
Unleash your potential at Leidos, where we deliver innovative solutions through the efforts of our diverse and talented people who are dedicated to our customer’s success. We empower our teams, contribute to our communities, and operate sustainably. Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business.
If this sounds like an environment where you can thrive, keep reading!
The Information Assurance Security Analyst is a member of the Leidos – Antarctic Support Contract (ASC) Information Security (InfoSec) team responsible for applying cybersecurity principles and best practices to proactively protect and maintain the confidentiality, integrity, and availability, of USAP data, information systems, and enterprise network. Personnel in this position must have an elevated level of trust, with access to sensitive and private information, which must be handled with integrity and respect in accordance with USAP policies and procedures.
The Security Analyst will be responsible for coordination, oversight, execution and enhancement of consistent security practices for all information systems within the USAP. The Security Analyst will ensure effective information security controls are documented and delivered to safeguard USAP business operations, prevent unauthorized system access, and to protect sensitive information.
The individual filling this position will contribute to delivering analysis and assessment of compliance with security and privacy laws, regulations, guidance, and direction, including the Federal Information Security Management Act (FISMA); National Institute of Standards and Technology (NIST) guidance; Federal Information Processing Standards (FIPS); applicable Office of Management and Budget (OMB) memoranda; National Science Foundation (NSF); and United States Antarctic Program (USAP) policies and instructions.
Due to contract requirements, US Citizenship is required.
Must obtain a Public Trust security clearance prior to start date. This process could take up to 4 months.
The anticipated salary range for this role is $115,000 - $120,000 annually.
Your greatest work is ahead!
Are you ready to join a team dedicated to a mission? Begin your journey of a flourishing and meaningful career, share your resume with us today!
The Challenge:
Maintains applicable security controls in the annual System Security Plan in accordance with NIST SP 800-53 rev 5, Security and Privacy Controls for Federal Information Systems and Organizations, and NIST SP 800-37, Risk Management Framework.
Provides configuration control over Security Assessment and Authorization (SA&A) packages.
Responds to audit requests and creation of deliverables.
Coordinates with Security Engineers and IT Operations teams to update and maintain the Plan of Actions and Milestones (POA&M), Acceptance of Risk (AOR) and other required security documentation.
Conducts and documents security assessments to determine the effectives and compliance of planned and implemented security controls.
Facilitates and documents contingency planning exercises.
Performs systems security evaluations, audits, and server logging reviews to verify secure operations.
Updates and maintains annual information security awareness and training program.
Develops information security reports for stakeholders, customers and management based on Information Security operational metrics, security assessments and security reviews.
Conducts continuous security reviews, recommends mitigations and corrective actions.
What Sets You Apart:
Bachelor's degree in Cybersecurity and 4+ years relevant experience. Additional years of experience and relevant certifications will be considered in lieu of degree.
Knowledgeable in the application of FISMA requirements such as NIST SP 800-53 rev 5 and NIST SP 800-37 to US Government programs.
Familiar with Governance, Risk, and Compliance (GRC) Tools.
Understanding and application of IT Infrastructure Library (ITIL).
Experience working within a project management framework.
Familiar with patch and vulnerability management processes and tools (e.g. Tenable Nessus).
Excellent written and verbal communication skills.
You May Also Have:
Security+, CISA/CISM, or related certifications desired.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s