Leidos' Corporate Information Security Office, reporting through the Digital sector, has an opening for an Information System Security Officer (ISSO) in our Omaha, NE office.
In this role, you will support the operation, maintenance, and authorization of classified information systems by implementing and monitoring cybersecurity requirements throughout the system lifecycle. This position will perform day-to-day information system security activities, maintain Risk Management Framework documentation and evidence, assess system compliance, support vulnerability-management activities, and coordinate remediation of identified security deficiencies.
You must be able to work independently while collaborating effectively with Information System Security Managers, Information Assurance personnel, system administrators, engineers, program management, and customer security representatives. You should possess hands-on experience applying Department of Defense cybersecurity requirements, interpreting security controls, evaluating technical evidence, and translating compliance requirements into practical actions for technical personnel.
Location: Work will be performed on-site at our Omaha office.
Clearance: You must currently hold an active DoD Top Secret clearance and be eligible to obtain Special Compartmented Investigation (SCI) post hire. Those with current TS SCI will be given first consideration.
Primary Responsibilities
This role may include a combination of duties to protect information, maintain security controls, and reduce risk across assigned information systems, sites, or programs.
- Serve as the Information System Security Officer for assigned classified information systems.
- Support the implementation, operation, maintenance, and continuous monitoring of cybersecurity controls throughout the system lifecycle.
- Apply the Department of Defense Risk Management Framework to assigned systems, including security control implementation, assessment preparation, authorization maintenance, and ongoing monitoring.
- Assist the Information System Security Manager with maintaining system authorization packages and supporting documentation.
- Develop, review, and update system security documentation, including System Security Plans, security control implementation statements, plans of action and milestones, continuous monitoring records, risk assessments, procedures, inventories, diagrams, and supporting evidence.
- Evaluate security controls to determine whether they are properly implemented, operating as intended, and producing the desired security outcome.
- Collect, review, organize, and maintain technical and administrative evidence supporting security control implementation and assessment activities.
- Conduct recurring reviews of assigned systems to verify continued compliance with approved authorization packages, security policies, technical baselines, and customer requirements.
- Support continuous monitoring activities by tracking control assessments, vulnerability scans, configuration reviews, account reviews, audit records, training requirements, hardware and software changes, and other recurring security activities.
- Develop and maintain continuous monitoring schedules, recurring task trackers, evidence repositories, and status reports.
- Identify security deficiencies, evaluate associated risk, document findings, assign or coordinate corrective actions, and track remediation through closure.
- Create, review, and maintain plans of action and milestones for identified weaknesses, including accurate deficiency descriptions, risk statements, milestones, resources, scheduled completion dates, and supporting evidence.
- Perform vulnerability-management activities, including scan coordination, result analysis, false-positive validation, risk evaluation, remediation tracking, mitigation verification, and reporting.
- Use approved vulnerability scanning and compliance-assessment tools to identify missing patches, insecure configurations, unsupported software, and other technical weaknesses.
- Review vulnerability and compliance scan results to determine applicability, severity, affected assets, potential impact, and required remediation actions.
- Coordinate with system administrators and infrastructure personnel to remediate vulnerabilities, configuration findings, patching deficiencies, and other security issues.
- Validate that remediation actions have been successfully completed through rescanning, configuration review, documentation review, or other appropriate verification methods.
- Support the implementation, assessment, and documentation of Security Technical Implementation Guide requirements and other approved security configuration baselines.
- Review Security Technical Implementation Guide checklists, Security Content Automation Protocol results, configuration evidence, and technical documentation for accuracy and completeness.
- Assist technical personnel with interpreting security requirements and identifying compliant implementation approaches.
- Conduct account-management and access-control reviews, including reviews of privileged accounts, inactive accounts, group memberships, permissions, authentication requirements, and user-access authorizations.
- Review audit records, security logs, and monitoring data for suspicious activity, policy violations, unauthorized changes, or other indications of cybersecurity events.
- Support the investigation, documentation, containment, remediation, and reporting of cybersecurity incidents and security violations.
- Ensure cybersecurity incidents, vulnerabilities, and compliance deficiencies are reported and escalated in accordance with approved procedures and customer requirements.
- Participate in configuration management and change-control activities by evaluating proposed hardware, software, firmware, network, and system configuration changes for potential security impact.
- Conduct or support security impact analyses for proposed system changes and document affected controls, risks, testing requirements, and required authorization-package updates.
- Participate in Configuration Control Board meetings and provide cybersecurity recommendations regarding proposed changes.
- Verify that approved changes are implemented, tested, validated, and accurately reflected in system documentation and security evidence.
- Support software approval and installation processes by reviewing software sources, versions, dependencies, vulnerabilities, licensing, technical requirements, and security impacts.
- Monitor systems for unauthorized hardware, software, services, accounts, connections, or configuration changes.
- Support hardware and software inventory validation and ensure security documentation accurately reflects the authorized system configuration.
- Develop, review, and maintain cybersecurity policies, procedures, checklists, implementation guidance, and standard operating procedures.
- Provide cybersecurity education, training, and guidance to system administrators, users, engineers, and program personnel.
- Support initial and recurring privileged-user, administrator, and general-user security training requirements.
- Prepare assigned systems for internal reviews, customer assessments, authorization activities, audits, inspections, and security vulnerability assessments.
- Participate in assessment interviews, technical demonstrations, evidence reviews, and system inspections.
- Coordinate responses to assessment findings and track resulting corrective actions to completion.
- Communicate system-security posture, vulnerabilities, compliance concerns, remediation status, and risk information to the Information System Security Manager, program leadership, technical teams, and customer representatives.
- Provide cybersecurity input for system planning, architecture, engineering, procurement, maintenance, refresh, and disposal activities.
- Assist with the secure introduction, transfer, handling, sanitization, and disposal of hardware, software, media, and data in accordance with approved procedures.
- Review and coach the work of less-experienced cybersecurity personnel, as assigned.
- Identify opportunities to improve cybersecurity processes, documentation quality, evidence management, vulnerability remediation, and continuous monitoring effectiveness.
Basic Qualifications
- Bachelor’s degree coupled with 4–8 years of prior relevant experience. Additional relevant experience may be considered in lieu of degree.
- Must currently possess an active Top Secret clearance with eligibility to obtain Sensitive Compartmented Information (SCI) security clearance.
- Must possess IAT II 8140/8570 certification (CompTIA Security+ certification, equivalent or higher)
- Hands-on experience applying the Department of Defense Risk Management Framework to information systems.
- Experience supporting classified information systems and complying with applicable Department of Defense cybersecurity requirements.
- Experience implementing, assessing, documenting, or monitoring NIST security controls.
- Experience developing, reviewing, or maintaining information system authorization documentation.
- Experience with security control implementation, continuous monitoring, vulnerability management, configuration compliance, or assessment and authorization activities.
- Experience interpreting cybersecurity requirements and translating them into technical or procedural implementation actions.
- Experience reviewing technical evidence to determine whether security requirements have been adequately implemented.
- Working knowledge of vulnerability scanning, vulnerability analysis, remediation tracking, and mitigation verification.
- Working knowledge of Security Technical Implementation Guides and secure configuration baselines.
- Experience collaborating with system administrators, engineers, information technology personnel, program management, and customer security representatives.
- Ability to independently manage assigned security activities, recurring compliance requirements, documentation, findings, and remediation actions.
- Ability to analyze complex cybersecurity issues and develop practical, risk-informed solutions.
- Ability to communicate technical cybersecurity requirements clearly to both technical and nontechnical stakeholders.
- Strong technical writing, documentation, organizational, analytical, and problem-solving skills.
- Ability to manage multiple systems, projects, findings, and recurring security activities with minimal supervision.
Relevant Experience Considered
- Information assurance
- Cybersecurity operations
- Department of Defense Risk Management Framework
- Assessment and authorization
- Security control implementation and assessment
- System Security Plan development and maintenance
- Body of Evidence development and maintenance
- Continuous monitoring
- Plan of Action and Milestones management
- Vulnerability scanning and analysis
- Vulnerability remediation and mitigation verification
- Security Technical Implementation Guide implementation
- Security Content Automation Protocol compliance assessment
- Configuration management and change control
- Security impact analysis
- Cybersecurity policy and procedure development
- Account and access-control reviews
- Privileged-user monitoring
- Security logging and audit-record review
- Cybersecurity incident response
- Security audits, assessments, and inspections
- Supporting classified information systems
- Supporting disconnected, isolated, or air-gapped environments
- Active Directory and enterprise identity management
Preferred Qualifications
- CISSP certification.
- CompTIA SecurityX certification.
- CompTIA Cybersecurity Analyst certification.
- Additional cybersecurity certifications aligned with the applicable Department of Defense cyber workforce role.
- Extensive hands-on experience implementing Department of Defense policies, security controls, and technical cybersecurity requirements.
- Experience developing, reviewing, or maintaining Risk Management Framework authorization packages for classified information systems.
- Experience using eMASS or a comparable governance, risk, and compliance platform.
- Experience performing continuous monitoring and maintaining recurring control-assessment schedules and evidence.
- Experience conducting vulnerability scans, analyzing scan results, assigning remediation actions, and verifying corrective measures.
- Experience using vulnerability-management and compliance tools such as Tenable Security Center, Assured Compliance Assessment Solution, Security Content Automation Protocol Compliance Checker, or comparable technologies.
- Experience implementing, validating, and documenting Security Technical Implementation Guide requirements.
- Experience using STIG Viewer or comparable security configuration documentation tools.
- Experience with centralized logging, security monitoring, endpoint security, or vulnerability-management tools such as Splunk, Trellix, Tenable, or comparable products.
- Experience developing and maintaining plans of action and milestones.
- Experience conducting security impact analyses for hardware, software, firmware, network, and configuration changes.
- Experience supporting Configuration Control Boards and formal change-management processes.
- Experience preparing for or participating in Department of Defense, Defense Counterintelligence and Security Agency, customer, or other government cybersecurity assessments and inspections.
- Familiarity with National Institute of Standards and Technology publications, Department of Defense cybersecurity policies, Security Technical Implementation Guides, and classified information system requirements.
- Working knowledge of Windows and Linux operating systems, Active Directory, virtualization technologies, networking, enterprise applications, and infrastructure security.
- Experience supporting classified systems in disconnected, isolated, or air-gapped environments.
- Experience coaching, mentoring, or reviewing the work of junior cybersecurity personnel.
If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.
Original Posting:
October 5, 2026For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:
Pay Range $87,100.00 - $157,450.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
More Information
Application Details
- Organization Details00100 LEIDOS, INC.


Recommended Comments
There are no comments to display.
Join the conversation
You are posting as a guest. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.