Lead Security Engineer
Job Description
Benefits and rewards
Leidos offers a competitive compensation package for the Lead Security Engineer role, onsite in Annapolis Junction, Maryland. The annual salary ranges from USD 154,050 to 278,475. The benefits program includes paid time off, 11 paid holidays, and a 401K with a 6% company match and immediate vesting. It also features flexible schedules, discounted stock purchase plans, opportunities for technical upskilling, education and training support, and parental paid leave.
- Paid Time Off
- 11 paid Holidays
- 401K with a 6% company match and immediate vesting
- Flexible Schedules
- Discounted Stock Purchase Plans
- Technical Upskilling
- Education and Training Support
- Parental Paid Leave
Location: Annapolis Junction, MD onsite. In this role you will lead all security engineering efforts for a large, complex network, mentor ISSOs and ISSEs, and help ensure ATOs and STE/STN compliance.
Responsibilities
- Own the overall security architecture by defining, implementing, and verifying security requirements across systems.
- Act as a security subject matter expert, providing guidance and oversight for the end-to-end security architecture.
- Engage with multiple system owners across networks to interpret, negotiate, and refine system and security requirements.
- Define and drive security strategy including risk assessment and management, security control assessment, continuous monitoring, service design, and broader cybersecurity program support.
- Identify and analyze security issues across complex, highly integrated systems and environments, and develop clear remediation recommendations.
- Design, develop, and execute static and dynamic application security testing, as well as penetration testing activities.
- Partner with development teams to improve understanding of vulnerabilities, attack vectors, and effective remediation techniques.
- Lead and mentor a team of program security engineers in day-to-day security engineering activities.
- Collaborate with the program security team to ensure STE/STN and continuous monitoring requirements are met for Test, Integration, and Development environments.
- Clearly articulate program security requirements, risks, and compliance challenges to multiple customer points of contact.
- Coordinate with internal cross-functional teams to plan, prioritize, and execute remediation and other security-related activities.
Requirements
- Master’s degree in Information Technology, Information Assurance, or a related field, and at least 15 years of relevant experience. Additional experience may substitute for a degree.
- At least 10 years of experience leading large, diverse Security Engineering teams, including ISSO and ISSE teams.
- Current active CISSP certification.
- Certified Scrum Master certification.
- At least 5 years of experience applying Agile methodologies in security engineering projects, including Scrum or SAFe frameworks.
- Extensive hands-on experience with modern security tools; hardware and software security implementations; communication protocols; encryption technologies; and web services.
- Expert-level understanding of security vulnerabilities and remediation techniques, including risk assessment, risk management, and security strategy/design.
- Extensive experience formulating, implementing, and assessing IT security policy.
- Solid understanding of ATOs, SSPs, and STE/STN requirements.
- Direct experience collaborating with software developers, software testers, and integration, deployment, and sustainment teams.
- Strong communication and interpersonal skills, with the ability to clearly convey program requirements and system compliance challenges to multiple customer stakeholders.
- Demonstrated ability to coordinate across multiple internal teams for planning and remediation activities.
- Solutions oriented team player with a high level of self-initiative.
- Clearance: TS/SCI with Polygraph required.
Similar Jobs
J
J