About this role
We are currently seeking a Vulnerability Analyst to join the Compartmented Enterprise Services Office (CESO) effort. This program is establishing a modern secure web service (SWS) operation as part of a state-of-the-art, highly automated platform capable of supporting a rapidly expanding customer population. Apply today to become part of the Leidos team assisting CESO as it migrates to a high security cloud environment, providing vulnerability management, risk assessment, and compliance services that protect the integrity of the platform throughout its lifecycle.
This position is based in Arlington, VA and is 100% on-site.
Requires a TS/SCI US Government Security Clearance to start.
Primary Responsibilities
- Responsible for meeting both regulatory (Legal and Mandated Requirements) and non-regulatory (Real-World Threat Reduction) compliance demands across the CESO environment.
- Assist in the management and maintenance of the IAVA (Information Assurance Vulnerability Alerts) program for CESO systems.
- Manage and enforce information security policies, and train and educate end-users on proper security practices.
- Conduct security and risk assessments using established frameworks (e.g., NIST, RMF, Common Criteria), mitigating risk via security controls and testing and evaluation to certify and accredit commercial security products used within the CESO platform.
- Develop, update, organize, maintain, and track RMF documentation using information obtained from the customer.
- Ensure privacy of data throughout its lifecycle; perform vulnerability management (scanning, assessment, reporting, and mitigation verification), business continuity, and disaster recovery activities.
- Coordinate with infrastructure, storage, database, and application teams to align vulnerability management activities with CESO's operational and compliance requirements.
- Maintain documentation, operational procedures, and compliance reports supporting CESO's secure cloud migration.
- Responsible for a combination of duties to protect information and maintain security controls across the CESO system, site, or program in order to reduce risk.
Basic Qualifications
- Bachelor's degree and 2+ years of related IT security experience; additional experience, education, or training may be considered in lieu of degree.
- Active TS/SCI security clearance required
- DoDD 8140 compliant certification, at minimum IAT Level II (e.g., Security+ CE), at start.
- Experience with the Defense Information Systems Agency (DISA) security model, controls, and authorization processes for standard computing systems and cloud computing across the Department of Defense
- Experience conducting activities associated with Information Assurance Vulnerability Alerts (IAVA) for example, Cybersecurity and Infrastructure Security Agency (CISA).
- Experience with creating Information Assurance documentation such as Security Control Traceability Metrics (SCTM), Risk Assessment Report (RAR), Security Assessment Report (SAR) and maintaining POA&Ms (Plans of Action and Milestones).
- Experience with ACAS and SEIM tools.
- Experience with application and hardware security settings for vendor and/or DISA best business practices.
- Candidate may be asked to obtain a CI Polygraph in the future.
Preferred Qualifications
- Prior experience with DISA and DISA's support to mission partners.
- TS/SCI with CI Polygraph preferred.
- Experience with ACAS, SPLUNK, ACT (cybersecurity event), IAVA reporting, and eMASS.
- Familiarity with vulnerability management across enterprise applications and infrastructure (e.g., Oracle, SQL Server, Exchange, virtualization platforms, Windows, Red Hat).
- Understanding of disaster recovery and business continuity concepts as they apply to secure cloud migrations.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
##
##
## Original Posting:
September 22, 2026
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
## Pay Range:
Pay Range $69,550.00 - $125,725.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.