Junior Security Engineer
Bethesda, MD - USA
Job Summary
General program information and/or position overview.
Leidos is seeking a Junior Security Engineer to support day-to-day security activities across enterprise and isolated environments. This position will provide hands-on support for security operations vulnerability management RMF/ATO activities and continuous monitoring.
The individual will work closely with senior security personnel system administrators engineers and other technical teams to implement security requirements identify and remediate security issues and maintain the overall security posture of the environment.
This position provides an opportunity to develop across multiple areas of cybersecurity including vulnerability management security engineering RMF/ATO system hardening and continuous monitoring. The individual will be given opportunities to take on increased technical responsibility as their knowledge and experience grow.
This is a 100% on-site position. All work must be performed at the customer site.
Primary Responsibilities
Perform day-to-day security activities under the direction of senior security personnel and escalate risks technical issues and blockers as appropriate.
Support vulnerability management activities from identification through closure including analysis remediation validation and documentation.
Perform vulnerability scanning and analyze findings using ACAS Tenable/Nessus or equivalent technologies.
Work with Windows Linux network desktop support and other engineering teams to assist with vulnerability remediation and security-related technical issues.
Implement and validate DISA STIGs and approved security configuration baselines across infrastructure systems.
Perform recurring security activities including audit log reviews account reviews vulnerability reviews security control validation and continuous monitoring.
Support RMF/ATO activities including security documentation control evidence Body of Evidence (BoE) POA&Ms and compliance with NIST SP 800-53 ICD 503 and applicable security directives.
Assist with reviewing system and configuration changes for potential security impact and document findings for review by senior security personnel and the ISSM.
Support security activities for isolated or restricted environments including vulnerability scanning logging patching hardening and security monitoring.
Review security logs and events using Splunk or equivalent SIEM/log-management technologies and escalate identified issues as appropriate.
Assist with maintaining security procedures documentation compliance evidence and vulnerability remediation records.
Track assigned security findings remediation activities and action items through completion and provide status updates as required.
Participate in security reviews engineering meetings and Technical Exchange Meetings (TEMs) as required.
Research security vulnerabilities technical requirements and remediation approaches and provide findings and recommendations to senior security personnel.
Develop technical knowledge across the environment and take on increased responsibility for security activities as experience and proficiency grow.
Basic Qualifications
Experience with application performance and latency problems related to security requirements from front middle and back end
Working experience with Windows Server 2016/2019 Active Directory IIS DNS DHCP Exchange DFS
Experience implementing security controls on common network services such as file email and active directory across multiple geographically dispersed sites.
Experience with networking technologies and security assessment to include but not limited to STIGs.
Experience implementing and supporting enterprise system security and malware monitoring and prevention tools such as Splunk McAfee HBSS and ACAS
Solid network and systems troubleshooting experience with TCP/IP Internet security and encryption (data at rest data in transit)
Ability to produce clear and concise documents and diagrams capturing networking and operational procedures and LAN/WAN topology using MS Visio MS Project MS Excel and MS Word.
Candidate must at a minimum meet DoD 8570.11- IAT Level II certification requirements (currently Security CE CCNA-Security GSEC or SSCP along with an appropriate computing environment (CE) certification)
Education/Experience Requirements
Bachelors degree with at least 2 years of relevant experience. Additional years of experience may be considered in lieu of degree.
Clearance
Active TS/SCI clearance with Polygraph required OR active TS/SCI and willingness to get a Poly.
US Citizenship is required due to the nature of the government contracts we support.
Preferred Qualifications
CISSP or CASP Certification
If youre looking for comfort keep scrolling. At Leidos we outthink outbuild and outpace the status quo because the mission demands it. Were not hiring followers. Were recruiting the ones who disrupt provoke and refuse to fail. Step 10 is ancient history. Were already at step 30 and moving faster than anyone else dares.
For U.S. Positions: While subject to change based on business needs Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job education experience knowledge skills and abilities as well as internal equity alignment with market data applicable bargaining agreement (if any) or other law.
Required Experience:
Junior IC
About Company
Leidos is an innovation company rapidly addressing the world's most vexing challenges in national security and health. Our 47,000 employees collaborate to create smarter technology solutions for customers in these critical markets.