About this role
Leidos is seeking a Security Authorization Lead to join the Air Traffic Business Area within the Homeland Sector, supporting the development of the Leidos Common Automation Platform (L-CAP). L-CAP is a mission-critical, future-ready automation platform built on a hybrid cloud data mesh architecture, enabling next-generation air traffic management capabilities. We are building with an AI-first engineering mindset, embracing emerging AI capabilities and modern development practices to accelerate delivery, improve software quality, and continuously evolve how we design and build mission-critical systems. This role operates within a SAFe/Agile framework as part of an Agile Release Train (ART) delivering iterative value across the program. This position supports government programs and requires the ability to obtain and maintain a favorable Public Trust investigation.
This is a hybrid position requiring 3 days onsite and 2 days working from home, i f you are located within a commutable distance (Less than 1 hour's drive one-way during normal traffic) from Gaithersburg, MD; Eagan, MN; or Egg Harbor Township, NJ. However, if you do not reside within a commutable distance, you may be considered for a 100% remote role.
In this role, you will own the security authorization lifecycle for L-CAP. You will lead the formal processes required to authorize L-CAP workloads to connect to and operate within government cloud environments, serve as the program’s primary technical interface to FAA security and Authorizing Official organizations, and own the artifact package and control-inheritance position that underpin every authorization decision. This is a delivery-facing compliance leadership role — you will translate authorization requirements into engineering work rather than documenting them after the fact.
What You’ll Do:
- Lead the government network connection and RMF/ATO authorization process for L-CAP workloads on government-provided cloud infrastructure, including security assessments, architecture reviews, control evidence, and assessor coordination.
- Own and maintain the security authorization package , including architecture briefings, data flow/security boundary diagrams, ports/protocols/services matrices, SBOMs, vulnerability/CVE dispositions, and POA&Ms.
- Define and defend security control inheritance across cloud provider, government platform, and Leidos application layers, maintaining the Customer Responsibility Matrix.
- Serve as the primary interface with government security reviewers, ISSOs, assessors, and Authorizing Official staff .
- Manage the POA&M and continuous monitoring lifecycle , including findings, risk characterization, remediation milestones, closure evidence, and security status reporting.
- Maintain the authorization boundary as architecture evolves, assess security impacts of proposed changes, and translate requirements into actionable engineering backlog items.
- Coordinate cross-ART compliance across four Agile Release Trains to ensure consistent control implementation and evidence quality.
- Support FedRAMP and agency-specific authorization requirements across cloud environments.
- Coordinate personnel security and facility access eligibility with program security and Talent Acquisition.
- Champion an AI-first engineering culture through AI-assisted development, automation, and emerging practices that improve productivity, code quality, testing, and delivery.
Core Technical Qualifications:
- Bachelor’s degree in Cybersecurity, Computer Science, IT, or related field with 6+ years of relevant cybersecurity, compliance, or security authorization experience , or a Master’s degree with 4+ years. (additional experience, education and training may be considered in lieu of degree)
- Demonstrated experience leading a federal information system through RMF to ATO or equivalent authorization , including NIST 800-53 Rev. 5 control implementation and assessment.
- Experience developing and defending authorization packages , including SSPs, POA&Ms, Security Assessment Reports, and authorization boundary diagrams.
- Experience with FedRAMP cloud control inheritance, Customer Responsibility Matrices, vulnerability management, CVE disposition, and remediation tracking .
- Experience working directly with government security reviewers, ISSOs, and/or Authorizing Official staff .
- Ability to translate security requirements into actionable engineering backlog items and coordinate compliance across multiple Agile engineering teams.
- Strong technical writing skills with experience producing government-facing security documentation .
- Ability to obtain and maintain a Public Trust and successfully complete required government background investigations.
- U.S. citizenship required , including eligibility for FAA facility and information system access (continuous U.S. residency for at least 3 of the previous 5 years ).
##
Preferred / Desired Qualifications:
- CISSP, CGRC (formerly CAP), CISM , or equivalent certification (strongly preferred)
- FAA or aviation-sector security authorization experience , including familiarity with FAA ATO processes and security governance organizations
- Experience with continuous ATO (cATO) or ongoing authorization models
- Experience defining authorization boundaries for Kubernetes and containerized workloads
- Familiarity with FedRAMP High and GovCloud inheritance models
- Security authorization experience for safety-critical or real-time operational systems
- Experience with compliance automation and evidence tooling , including OSCAL, eMASS, Xacta , or equivalent
- Knowledge of software supply chain security , including SBOM, artifact signing, and provenance
- Experience with SAFe or large-scale Agile compliance integration
Why Leidos?
You’ll work on systems where performance, precision, and reliability matter — every second. This is not experimental AI for prototypes. This is disciplined, responsible AI applied to mission-critical software that supports national infrastructure.
If you’re excited by solving complex problems in regulated, real-world environments — and using AI as a force multiplier rather than a shortcut — we’d like to talk.
ATMC
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
##
##
## Original Posting:
September 21, 2026
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
## Pay Range:
Pay Range $107,900.00 - $195,050.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.