Cyber GRC Team Lead

3324 DISA Fort George G. Meade MD, United States

Apply now Apply later

Ranked first in Government IT and systems integration, Leidos brings decades of experience leading large-scale mission-critical network IT programs. We’re looking for innovators and forward-thinkers to help us do great things.

Leidos is seeking qualified Cyber GRC Team Lead candidates to join our Defense Enclave Services team who will support an extensive digital modernization program critical to DISA and Fourth Estate Agencies.

We offer competitive compensation, retirement and paid leave packages, health and wellness programs, career development trainings and certifications, income protection, employee stock purchase plans, and family benefits.

Job Description:

Leidos has an exciting opportunity for a Cyber Governance, Risk, and Compliance (GRC) Team Lead.   In this role, a successful candidate will be knowledgeable over several security solutions, providing security infrastructure operations and RMF support across the program. This support includes, but is not limited to system authorization processes, endpoint security solutions, vulnerability scanning, and both configuration and vulnerability risk compliance and reporting. The successful candidate for this position is a highly motivated individual, with a strong IT security and RMF background who excels in managing security technology and personnel, analyzing and communicating the results, and interacts well with both internal teams and clients.

CLEARANCE REQUIREMENTS:  Must possess an active SECRET clearance prior to start with Leidos.  (US Citizenship required)

Primary Responsibilities:

  • Lead a team of RMF Compliance personnel

  • Interface with information assurance customer personnel and support cybersecurity efforts across the program.

  • Support Authorizing Official (AO) actions by providing supporting documents and artifacts for various security tools in accordance with RMF as defined in NIST 800-37 revision 2 and related agency specific RMF requirements.

  • Provide updates or create new Security Plans and Procedures supporting NIST SP 800-53 Security controls

  • Provide input to and guide implementation and/or verification and validation of an organizational access control policy and plan reflecting various cybersecurity solutions in compliance with risk-levels defined in the National Institute of Standards and Technology (NIST) 800-53, rev 4, Access Control family of controls to include auditing annually, at a minimum.

  • Brief upper management and customer on status of security related projects

  • Oversee/manage security deliverables to the customer, per contract requirements

  • Assist as required with project/task order level support for Cyber, PKI, and A&A related inspections.

  • Review and recommend updates to existing security tools, policies, and/or procedures.

  • Mentor team members and help create individual development plans.,

Basic Qualifications:

  • Bachelor’s degree and 8-12 years of experience; additional years of directly applicable experience may be accepted in lieu of a degree.

  • Certified Information Systems Security Professional (CISSP).

  • 10+ years’ experience with a variety of DoD security tools functioning to support a strong cybersecurity posture and deliver cybersecurity related services, including developing and maintaining all related documentation and artifacts.

  • 5+ years leading a team of professionals.

  • Analytical ability, problem-solving skills, and ability to break down complex problems into actionable steps

  • Excellent knowledge and experience covering a wide range of security related discovery and management tools, included, but not limited to, ESS, Vulnerability Management, eMASS, and other cybersecurity tools and resultant applications.

  • Experience selecting effective methods, techniques, and evaluation criteria to achieve desired outcomes.

  • Understanding of federal cybersecurity guidance such as FISMA NIST SP 800-37 - Guide for Applying the Risk Management Framework to Federal Information Systems: a Security Life Cycle Approach and NIST 800-137 - Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations.

Preferred Qualifications:

  • Familiarity with ACAS, Trellix and MDE

  • Familiarity with DoD A&A and eMASS

  • Familiarity with COAMS

  • Familiarity with SNAP and GIAP

  • DoD CTOs and Incident Response.

  • Additional certifications demonstrating cybersecurity/technical mastery.

DISADES

External Referral Eligible

Original Posting Date:

2025-01-31

While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $126,100.00 - $227,950.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Apply now Apply later
Job stats:  0  0  0

Tags: ACAS Audits CISSP Clearance Compliance DISA DoD eMASS Endpoint security FISMA Governance Incident response Monitoring NIST NIST 800-53 PKI Risk management RMF Vulnerability management

Perks/benefits: Career development Competitive pay Equity / stock options Health care Wellness

Regions: Asia/Pacific North America
Country: United States

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.