yoinka

Cyber Security STIG Tester

Leidos

Odenton, MDSeniorH-1B sponsor companyClearance required
Sign in to applyVerified 4h ago
Location
Odenton, MD
Work model
On-Site
Level
Senior
H-1B history
26 approvals (FY2023)
Posted
Sep 10, 2026

Skills

Cybersecurity

About this role

Are you ready to make an impact and join a creative, forward-thinking team?   Leidos is seeking qualified Cyber Security STIG Tester to join our GSMO-II team at Ft. Meade, MD.

POSITION

SUMMARY: The selected candidate shall perform (or review) technical security assessments using STIG Checklists, SCAP scans, and ACAS/ESS Scans of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) guidelines and regulations and recommend mitigation strategies. In this role, the candidate will ensure that the environments in which DoD information systems reside are secure and compliant, develop approaches to secure the environment, assess threats to the environment, provide inputs on the adequacy of security designs and architectures, perform RMF STIG and compliance testing related activities, and participate in risk assessment mitigation with the system administrators and providing relevant reporting for security briefing.   CLEARANCE REQUIREMENT:  •Must hold an active Secret security clearance. (US Citizenship required)   PRIMARY RESPONSIBILITIES: •Ensure STIG Checklists are up to date and settings are enforced with minimal operational impact for all systems (workstations, servers, network) within the environment.  •Support systems within GMS to have an up to date and complete STIG Checklist; educate systems/network administrators regarding completion/edits as required.  •Examine results of STIG testing and pass results to system owners and system administrators. •Track response times to STIG findings and report on the security briefing. •Support POA&M analysis and coordination efforts, as required, including eMASS updates. •Perform cybersecurity lab testing/hardening activities supporting deployment of/updates to computer systems and applications.  •Review data from ACAS/ESS scans and set tickets to add new equipment into scans as necessary. •Maintain SOP’s for testing and reporting activities.  •Support functional testing as necessary for new technology.  •Support testing events and preparation for testing events. •Perform vulnerability/risk analyses of computer systems and applications during all phases of the system development life cycle. •Support Authorizing Official (AO) actions by ensuring  all testing related security testing artifacts are presented in accordance with RMF as defined in NIST 800-37 revision 2 and related agency specific RMF requirements. •Have experience performing various types of vulnerability and assessment scans with multiple tools.   BASIC QUALIFICATIONS: •Bachelor’s degree and 8+ years of experience; additional years of directly applicable experience may be accepted in lieu of a degree. •Prior relevant experience working with STIG Compliance, SCAP tools, vulnerability assessments and reporting. •Have experience performing various types of vulnerability and assessment scans with multiple tools. •Have experience using eMASS and/or Xacta. •Solid understanding of the Risk Management Framework (RMF) and the System Development Life Cycle (SDLC). •Understanding of hardware and software engineering best practices. •Demonstrated analytical and problem-solving skills. •Must meet eligibility requirements for work assignment on specified contract. •Applicants selected will be subject to a government security investigation and must meet eligibility requirements. •Current DoD 8570 IAT II Certification is required. (Sec+.)   PREFERRED QUALIFICATIONS: •Ability to identify needed changes to processes and activities and help to implement continuous improvement solutions. •ACAS training completed. •Ability to work successfully as part of a virtual team.     If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and

Listing verified 4h ago. Applications go through the company's official careers site.

← Back to Yoinka

Cyber Security STIG Tester at Leidos, Odenton, MD | Yoinka