About this role
Leidos' Corporate Information Security Office, reporting through the Digital Sector, is seeking an Information System Security Engineer to support various information systems and act as the Subject Matter Expect to Junior System Administrators. The successful candidate will be responsible for maintaining, securing, and supporting complex classified information systems, as well as ensuring compliance with security protocols and regulations.
Location: This position is full time, onsite at our Campus Point, San Diego office.
Clearance: You must currently hold an active DoD Top Secret clearance to be considered and must be eligible to obtain Special Access Program and Special Compartmented Access (SCI) post hire.
Primary Responsibilities
This role includes a combination of duties to protect information, and maintain security controls, for an entire system, site, or program to reduce risk.
- Serve as the Information System Security Engineer (ISSE) for Special Access Program information systems, providing security engineering support throughout the full system lifecycle from research and development through deployment, accreditation, operations, maintenance, and decommissioning.
- Design, develop, integrate, and maintain secure classified information systems and architectures in accordance with the Joint Special Access Program Implementation Guide (JSIG), Risk Management Framework (RMF), applicable DoW policies, and program-specific security requirements.
- Develop and maintain system security architecture, including network segmentation, boundary protections, authentication, privileged access, encryption, auditing, logging, secure communications, virtualization, storage, and data protection solutions.
- Implement and validate DISA Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), vendor security guidance, and program specific hardening requirements across Windows, Linux, network, virtualization, storage, and supporting infrastructure.
- Coordinate with ISSMs, ISSOs, System Administrators, and Program Management to resolve technical and compliance issues.
- Develop secure configuration baselines, build procedures, automation, scripts, and configuration management processes to improve repeatability and compliance across classified systems.
- Support troubleshooting and resolution of complex security and infrastructure issues involving a variety of information systems.
- Support the preparation for and execution of government security assessments, authorization reviews, inspections, and audits, including collection and presentation of objective evidence demonstrating control implementation.
- Provide technical cybersecurity guidance and mentoring to system administrators, ISSOs, and other program personnel.
Basic Qualifications
- Must be a U.S. Citizen.
- Bachelor's Degree with 8-12 years of experience, Master’s degree with 6-10 years of experience, or equivalent relevant experience and/or industry-standard certifications may be considered in lieu of degree.
- Must hold a current Active Top Secret security clearance to be considered along with sustained ability to be cleared to Special Access Programs and ability to obtain Top Secret/SCI security clearance.
- Must have a DoD 8140/8570 IAT level II or higher certification such as CompTIA Security+.
- Professional-level knowledge and hands-on experience administering, engineering, or securing Windows and Linux operating systems, including enterprise server and workstation environments.
- Expert-level knowledge of virtualization technologies, enterprise storage platforms, and backup/recovery solutions, including the security considerations associated with each.
- Working knowledge of enterprise networking concepts and technologies, including TCP/IP, routing, switching, VLANs, firewalls, network segmentation, DNS, authentication, and secure network architecture.
- 3+ years of demonstrated experience supporting Special Access Program (SAP) environments and applying applicable cybersecurity requirements, including the RMF and JSIG.
- Experience interpreting cybersecurity requirements and translating security controls into technical configurations, engineering requirements, and system implementations.
- Experience implementing, assessing, and maintaining technical security controls across operating systems, networks, virtualization platforms, storage, and supporting infrastructure.
- Hands-on experience implementing and maintaining DISA STIGs, SRGs, Nessus, and secure configuration baselines.
- Knowledge of enterprise security technologies and concepts, including Active Directory, Group Policy, endpoint security, centralized logging, auditing, privileged access, encryption, and access control.
- Experience supporting the system development and security lifecycle, including design, integration, testing, deployment, authorization, continuous monitoring, maintenance, and decommissioning.
- Ability to troubleshoot complex technical and cybersecurity issues spanning operating systems, networking, or other information system components.
- Strong technical documentation and communication skills with the ability to clearly communicate security risks, technical requirements, remediation strategies, and engineering recommendations to both technical and nontechnical stakeholders.
- Experience with the Risk Management Framework (RMF) and maintaining compliance artifacts such as SCAP scans, STIGs, and Nessus Vulnerability reports.
- Experience developing or maintaining technical procedures, system build documentation, configuration baselines, work instructions, scripts, or automation used to support secure and repeatable system deployments.
- Experience designing or securing air-gapped environments including offline patching, software repositories, vulnerability management, and configuration management.
Preferred Qualifications
- ISC(2) Certification Information System Security Professional (CISSP) or Information System Security Engineering Professional (CISSP-ISSEP) certification.
- RedHat Certified System Administrator (RHCSA) certification.
- Demonstrated ability to independently interpret JSIG/RMF controls and translate them into practical technical architectures, configurations, implementation guidance, and validation procedures.
- Experience developing and maintaining SIEM/log-management platforms such as Splunk, and endpoint security technologies to include DLP.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
##
##
## Original Posting:
October 8, 2026
For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
## Pay Range:
Pay Range $107,900.00 - $195,050.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.