Cyber GRC Team Lead
3324 DISA Fort George G. Meade MD, United States
Full Time Senior-level / Expert Clearance required USD 126K - 227K
Ranked first in Government IT and systems integration, Leidos brings decades of experience leading large-scale mission-critical network IT programs. We’re looking for innovators and forward-thinkers to help us do great things.
Leidos is seeking qualified Cyber GRC Team Lead candidates to join our Defense Enclave Services team who will support an extensive digital modernization program critical to DISA and Fourth Estate Agencies.
We offer competitive compensation, retirement and paid leave packages, health and wellness programs, career development trainings and certifications, income protection, employee stock purchase plans, and family benefits.
Job Description:
Leidos has an exciting opportunity for a Cyber Governance, Risk, and Compliance (GRC) Team Lead. In this role, a successful candidate will be knowledgeable over several security solutions, providing security infrastructure operations and RMF support across the program. This support includes, but is not limited to system authorization processes, endpoint security solutions, vulnerability scanning, and both configuration and vulnerability risk compliance and reporting. The successful candidate for this position is a highly motivated individual, with a strong IT security and RMF background who excels in managing security technology and personnel, analyzing and communicating the results, and interacts well with both internal teams and clients.
CLEARANCE REQUIREMENTS: Must possess an active SECRET clearance prior to start with Leidos. (US Citizenship required)
Primary Responsibilities:
Lead a team of RMF Compliance personnel
Interface with information assurance customer personnel and support cybersecurity efforts across the program.
Support Authorizing Official (AO) actions by providing supporting documents and artifacts for various security tools in accordance with RMF as defined in NIST 800-37 revision 2 and related agency specific RMF requirements.
Provide updates or create new Security Plans and Procedures supporting NIST SP 800-53 Security controls
Provide input to and guide implementation and/or verification and validation of an organizational access control policy and plan reflecting various cybersecurity solutions in compliance with risk-levels defined in the National Institute of Standards and Technology (NIST) 800-53, rev 4, Access Control family of controls to include auditing annually, at a minimum.
Brief upper management and customer on status of security related projects
Oversee/manage security deliverables to the customer, per contract requirements
Assist as required with project/task order level support for Cyber, PKI, and A&A related inspections.
Review and recommend updates to existing security tools, policies, and/or procedures.
Mentor team members and help create individual development plans.,
Basic Qualifications:
Bachelor’s degree and 8-12 years of experience; additional years of directly applicable experience may be accepted in lieu of a degree.
Certified Information Systems Security Professional (CISSP).
10+ years’ experience with a variety of DoD security tools functioning to support a strong cybersecurity posture and deliver cybersecurity related services, including developing and maintaining all related documentation and artifacts.
5+ years leading a team of professionals.
Analytical ability, problem-solving skills, and ability to break down complex problems into actionable steps
Excellent knowledge and experience covering a wide range of security related discovery and management tools, included, but not limited to, ESS, Vulnerability Management, eMASS, and other cybersecurity tools and resultant applications.
Experience selecting effective methods, techniques, and evaluation criteria to achieve desired outcomes.
Understanding of federal cybersecurity guidance such as FISMA NIST SP 800-37 - Guide for Applying the Risk Management Framework to Federal Information Systems: a Security Life Cycle Approach and NIST 800-137 - Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations.
Preferred Qualifications:
Familiarity with ACAS, Trellix and MDE
Familiarity with DoD A&A and eMASS
Familiarity with COAMS
Familiarity with SNAP and GIAP
DoD CTOs and Incident Response.
Additional certifications demonstrating cybersecurity/technical mastery.
DISADES
External Referral Eligible
Original Posting Date:
2025-01-31While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $126,100.00 - $227,950.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Tags: ACAS Audits CISSP Clearance Compliance DISA DoD eMASS Endpoint security FISMA Governance Incident response Monitoring NIST NIST 800-53 PKI Risk management RMF Vulnerability management
Perks/benefits: Career development Competitive pay Equity / stock options Health care Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.