Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Risk Management Framework / Information Assurance Analyst Lead image - Rise Careers
Job details

Risk Management Framework / Information Assurance Analyst Lead

Leidos is seeking an RMF/Information Assurance Engineer to support large-scale migration and operations on a large, high-profile DOD contract. The I3TS program provides enterprise-wide IT support to enable DTRA’s Information Management & Technology Directorate (ITD) to consolidate, modernize, and continuously innovate the delivery of IT services and mission capabilities to DTRA’s internal and external mission partners operating in CONUS and OCONUS locations.

Primary Responsibilities

  • Assist the DTRA ISSM(s) by proactively tracking and reporting cybersecurity and RMF activity timelines, ensuring that all NIPR and SIPR RMF Packages are accurately maintained.

  • Populate and regularly update RMF packages within DTRA's instances of the DoD Enterprise Mission Assurance Support Service (eMASS) and the Intelligence Community's Xacta system for IT systems, networks, and other assets requiring package preparation.

  • Lead the creation and maintenance of cybersecurity operations-related Policies and Procedures, Administrative Guides, Plans, and Technical Documentation.

  • Provide cybersecurity technical support and subject matter expertise to DTRA's cybersecurity and risk management leadership, delivering senior-level briefings as necessary.

  • Offer security guidance throughout system lifecycles in collaboration with engineers, administrators, and software developers.

  • Prepare impact and risk assessment reports on residual risks, including identifying false positives and nonapplicable findings, for use by DTRA's cybersecurity and risk management leadership. This includes security compliance reports, STIG reports, compliance status briefings, and security/risk test artifacts.

  • Assist in the selection, configuration, operation, and reporting of vulnerability assessment and container-based security testing tools.

  • Support cybersecurity and risk management workflow actions and change request tickets within DTRA's change management system, including reviewing, approving, or addressing risk management aspects of change requests.

  • Ensure compliance with and support DTRA's supply chain risk management, foreign ownership and controlling interest, and review requirements for commercial, third-party, and open-source software.

  • Lead security and compliance scanning of IT assets, including the delivery of scan reports.

  • Help DTRA ISSM cybersecurity and RMF support teams respond to Cyber Task Orders, IA Directives, task responses, vulnerability discoveries, and ad-hoc vulnerability scanning requirements.

  • Provide technical guidance to engineers, software developers, and system administrators to support vulnerability remediation, STIG compliance, patching, and code security measures required to achieve compliance.

  • Validate the effectiveness of bug fixes, patches, and other remediation activities identified during previous test activities, providing evidential artifacts when needed to support IV&V, RMF, Cyber Task Orders, and other processes.

  • Review and update IS Authorization documentation (Body of Evidence) to support IS Assessment and Authorization (Certification/Accreditation) activities.

Basic Qualifications

  • BS degree with 12+ years’ experience or 16+ years of IA experience without a degree.

  • Current DoD 8570 baseline certification for IAM III

  • Expert in Risk Management Framework (RMF), NIST, ICD, and CNSS standards.

  • Expert with with network technologies (LAN & WAN) and best practices within a classified environment to include crypto and key management

  • STIG compliance, SCC and STIG Viewer experience, and ACAS expertise.

  • Expert with Microsoft Windows, Linux, and system virtualization in a secure network environment.

  • Must be able to work in a constantly changing regulatory environment with short-, mid-, and long-term timelines for remediating any non-compliance

  • Must be able to work well within a team environment and able to adapt quickly to change

  • Good writing and verbal presentation skills

  • Active DoD Top Secret Clearance with eligibility to obtain an SCI

Preferred Qualifications

  • Past or current ISSM/ISSO experience

  • Security+ or CISSP

  • GCIH a plus

  • DoD IS knowledge and experience

  • Background or understanding of System Security Plans (SSP)

  • Security hardening scripting/automation experience

  • Microsoft OS Certification (MCSE Win 7 or other)

  • Linux certification (RHCSA, CompTIA Linux, LCFS/LCFE, etc.)

Original Posting:

March 27, 2025

For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $126,100.00 - $227,950.00

The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.

Leidos Glassdoor Company Review
3.8 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Leidos DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Leidos
Leidos CEO photo
Tom Bell
Approve of CEO

Average salary estimate

$177025 / YEARLY (est.)
min
max
$126100K
$227950K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Risk Management Framework / Information Assurance Analyst Lead, Leidos

Leidos is on the lookout for a dynamic Risk Management Framework / Information Assurance Analyst Lead to join our team in Fort Belvoir, VA. In this crucial role, you will be supporting large-scale migration and operations on a prominent DOD contract. Your mission? To provide top-notch information assurance and cybersecurity support to DTRA’s Information Management & Technology Directorate. You'll be proactively tracking and reporting on cybersecurity activities, ensuring that RMF packages are kept up-to-date and compliant. You’ll be leading the charge in creating and maintaining essential cybersecurity policies and technical documentation, all while being a resource for various teams throughout the system life cycles. Your expertise will shine as you prepare detailed impact assessment reports and security compliance documents. Additionally, you'll assist with vulnerability assessments and support risk management workflows while ensuring compliance with essential guidelines. As you collaborate with engineers and developers, your insights will help guide vulnerability remediation processes and ensure we maintain the highest security standards. If you have a passion for cybersecurity and risk management, along with extensive experience in the field, Leidos is excited to offer you this opportunity where you can truly make your mark!

Frequently Asked Questions (FAQs) for Risk Management Framework / Information Assurance Analyst Lead Role at Leidos
What are the primary responsibilities of the Risk Management Framework / Information Assurance Analyst Lead at Leidos?

As a Risk Management Framework / Information Assurance Analyst Lead at Leidos, you'll be tasked primarily with tracking and reporting cybersecurity activities, maintaining RMF packages, creating and updating cybersecurity documentation, providing cybersecurity guidance across system life cycles, and assisting with compliance and vulnerability assessments.

Join Rise to see the full answer
What qualifications are required for the Risk Management Framework / Information Assurance Analyst Lead position at Leidos?

The position requires a BS degree with at least 12 years of experience or 16 years without a degree, along with a current DoD 8570 baseline certification for IAM III. Expertise in RMF, NIST, and cybersecurity standards is essential, as well as knowledge of network technologies and system security protocols.

Join Rise to see the full answer
Can you explain the importance of RMF in the role of the Risk Management Framework / Information Assurance Analyst Lead at Leidos?

RMF is integral in this role as it provides a structured process for managing risk through the lifecycle of information systems. The Risk Management Framework / Information Assurance Analyst Lead will leverage RMF to ensure that DTRA systems are compliant and secure while effectively managing any cybersecurity risks that may arise.

Join Rise to see the full answer
What experience is preferred for candidates applying for the Risk Management Framework / Information Assurance Analyst Lead at Leidos?

Preferred candidates typically have past experience as ISSM/ISSO, or hold certifications such as Security+ or CISSP. Knowledge of DoD information systems and experience with security automation or hardening scripting are also beneficial.

Join Rise to see the full answer
What is the work environment like for the Risk Management Framework / Information Assurance Analyst Lead at Leidos?

The work environment is dynamic and collaborative at Leidos, where the Risk Management Framework / Information Assurance Analyst Lead will engage with various teams to tackle evolving cybersecurity challenges in a fast-paced regulatory landscape.

Join Rise to see the full answer
Common Interview Questions for Risk Management Framework / Information Assurance Analyst Lead
Can you describe your experience with the Risk Management Framework?

When answering this question, discuss specific situations where you applied RMF principles, detailing how you managed risks and ensured compliance within projects. Use metrics or outcomes to showcase the effectiveness of your approach.

Join Rise to see the full answer
How do you stay updated with current cybersecurity threats and trends?

Highlight your dedication to continuous learning by mentioning relevant courses, webinars, or cybersecurity forums you participate in. Discuss specific instances where this knowledge has informed your work in securing information systems.

Join Rise to see the full answer
What tools and methodologies do you use for vulnerability assessment?

Discuss the various tools you are familiar with, like ACAS or STIG Viewer, and provide examples of how you utilized these tools in real situations to enhance cybersecurity posture.

Join Rise to see the full answer
Describe a time when you had to lead a cybersecurity initiative.

Use the STAR method to outline the situation, your task, the action you took, and the result. This gives a structured way to demonstrate your leadership skills and effectiveness in managing cybersecurity projects.

Join Rise to see the full answer
How would you handle a non-compliant system?

Explain your strategy, including conducting a root cause analysis, developing a remediation plan, and collaborating with relevant teams to bring the system back into compliance efficiently.

Join Rise to see the full answer
What is your approach to developing cybersecurity policies and procedures?

Emphasize collaboration with stakeholders, conducting thorough risk assessments, and incorporating best practices based on current standards and frameworks when crafting policies.

Join Rise to see the full answer
How do you assess the risk and impact of a potential vulnerability?

Discuss your method for evaluating vulnerabilities, including the factors you consider, such as the asset's value, the potential threat landscape, and how you prioritize remediation efforts based on risk exposure.

Join Rise to see the full answer
What experience do you have with compliance reporting?

Share examples of compliance reports you've created, the metrics you tracked, and how these reports informed decision-making within the organization regarding cybersecurity strategies.

Join Rise to see the full answer
Can you explain a cybersecurity issue you resolved successfully?

Describe a specific incident, detailing your analysis, the steps you took to resolve the issue, and the overall impact of your actions on the organization's security posture.

Join Rise to see the full answer
What strategies do you use for effective communication with technical and non-technical teams?

Highlight your ability to tailor communication styles, using clear, jargon-free language for non-technical audiences, while providing detailed technical insights to specialized teams. Providing specific examples can further strengthen your answer.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Leidos Remote United States
Posted 5 days ago
Photo of the Rise User
Leidos Hybrid Huntsville, Alabama, United States
Posted 5 days ago
Photo of the Rise User
Airbnb Remote San Francisco, California, United States
Posted 5 days ago
Mission Driven
Collaboration over Competition
Inclusive & Diverse
Growth & Learning
Maternity Leave
Paternity Leave
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
401K Matching
Paid Time-Off
L3Harris Technologies Hybrid US, Brevard County, FL; Florida, Melbourne, FL
Posted 3 days ago
Photo of the Rise User
Posted 5 days ago
Photo of the Rise User
SpryPoint Remote No location specified
Posted 11 days ago
Photo of the Rise User
Posted 5 hours ago
Mission Driven
Social Impact Driven
Passion for Exploration
Reward & Recognition

Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business. At Leidos, our mission is to make the world safer, healthier, and mor...

428 jobs
MATCH
VIEW MATCH
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
March 30, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!