Senior Cyber Specialist - ISSO

LeidosOdenton, MarylandOn-siteFull-timeSenior, 5–8 yearsListed 6 hours ago

Apply now

About this role

Leidos is seeking a Senior Cyber Specialist to serve as an Information System Security Officer (ISSO) responsible for the day-to-day security posture, authorization, and continuous monitoring of enterprise information systems. The role owns the security control implementation and accreditation artifacts for assigned systems and serves as the principal point of contact for cybersecurity matters affecting them.

This position is responsible for ensuring assigned systems are built, documented, assessed, and operated in accordance with applicable federal and DoD cybersecurity requirements. Duties include security control implementation and validation, risk assessment, vulnerability and compliance oversight, incident support, and the development and maintenance of the artifacts required to obtain and sustain an authorization to operate.

The successful candidate is a cybersecurity practitioner who works comfortably between the engineering teams who build the system and the authorizing officials who must accept its risk — translating technical reality into defensible control documentation, and translating control requirements into changes engineers can actually implement.

Scope and Impact

Impact: Influences development of solutions that impact strategic project and program goals and business results. Recommends and develops security solutions, practices, and standards. Decisions and risk recommendations have significant impact on the authorization and operation of assigned systems.

Complexity: Resolves highly complex problems through significant application of technical and regulatory knowledge, conceptualization, reasoning, and interpretation. Evaluates technical risk where requirements are ambiguous and compensating controls must be justified.

Communication: Communicates with executive and client leadership on matters of significant importance to the security posture of assigned systems. Presents risk assessments, control implementation positions, and remediation plans to engineering leadership, security authorities, and authorizing officials.

Knowledge: In-depth understanding of cybersecurity principles, risk management frameworks, and security control implementation across a range of systems. Serves as a subject matter expert within the information assurance domain.

Primary Responsibilities

Authorization and Risk Management Framework

- Serve as ISSO for assigned systems, maintaining the system security posture and acting as the principal cybersecurity point of contact for those systems.

- Execute Risk Management Framework (RMF) activities across categorization, control selection, implementation, assessment, authorization, and continuous monitoring.

- Develop, maintain, and defend authorization packages, including the System Security Plan, security control implementation statements, risk assessment reports, contingency and incident response plans, and supporting artifacts.

- Maintain system records and artifacts in eMASS or the designated authorization repository, keeping control status, assessment results, and documentation current and accurate.

- Develop and track Plans of Action and Milestones (POA&Ms), including risk justification, mitigation approach, compensating controls, and milestone closure evidence.

- Support security assessments, audits, inspections, and command cyber readiness activities, including evidence collection and assessor coordination.

- Evaluate proposed system and architecture changes for security impact, and provide written recommendations on acceptance, mitigation, or denial.

Vulnerability, Compliance, and Continuous Monitoring

- Oversee vulnerability management for assigned systems, including scan review, validation, prioritization, remediation tracking, and reporting against required timelines.

- Oversee DISA STIG and security configuration compliance, including baseline review, deviation justification, and verification of applied hardening.

- Review and act on cybersecurity directives, bulletins, advisories, and tasking orders applicable to assigned systems, and track compliance to closure.

- Perform continuous monitoring activities, including control status review, log and audit record oversight, account and privilege review, and security posture reporting.

- Support incident response and reporting, including initial analysis, documentation, coordination with the security operations team, and after-action tracking of corrective measures.

Engineering Partnership and Advisory

- Partner with network, systems, cloud, application, and operations engineering teams to ensure security requirements are designed in rather than retrofitted.

- Provide practical security guidance on architecture and implementation decisions, including boundary definition, access control, encryption, auditing, and least privilege.

- Advise program leadership and government stakeholders on cybersecurity risk, control posture, remediation options, and the security implications of schedule and design decisions.

- Mentor junior cybersecurity staff and provide technical direction on assessment, documentation, and remediation work.

- Improve cybersecurity processes, templates, evidence standards, and reporting to reduce rework and shorten authorization timelines.

Documentation

Develop and maintain cybersecurity documentation, including:

- System Security Plans and control implementation statements

- System boundary descriptions, data flow diagrams, and hardware/software inventories

- Risk assessment reports and security impact analyses

- Plans of Action and Milestones with supporting evidence

- Contingency, continuity, and incident response plans

- Configuration and hardening baselines and deviation justifications

- Continuous monitoring and security posture reports

- Standard operating procedures for recurring security activities

Required Qualifications:

- Bachelor's degree or equivalent experience and 12+ years of prior relevant experience, or Master's degree with 10+ years of experience. Specific experience, education, and training may be considered in lieu of a degree.
- Current IAT Level II or higher certification, such as Security+ or CISSP.

- Active DoD Secret clearance.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

##

##

## Original Posting:
October 9, 2026

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

## Pay Range:
Pay Range $131,300.00 - $237,350.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.