Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Compliance Security Lead image - Rise Careers
Job details

Compliance Security Lead - job 1 of 3

DescriptionLeidos has an immediate need for a Compliance Security Lead, contingent upon contract award.The Compliance Security Lead will lead the implementation and improvement of administrative and technical controls of the Information Security Management System for the program. The selected candidate will create and deploy the corporate governance framework for cybersecurity risk, including identifying risks and awareness, and provide briefings to senior leaders to advise them of critical issues that may affect business or security posture. Help conduct security and privacy assessments. Assess and create and execute remediation plan for the same.Role will be hybrid. Must be local to the DC Metro area for onsite meetings in Reston, Rockville, Silver Spring or DC.Be US Citizen or US Person (Green Card Holder) with the ability to obtain a level 5 Public Trust Clearance.Primary Responsibilities• Lead projects, define priorities, and articulate tradeoffs as you advocate for continually improving the state of our information security and IT compliance functions• Lead, support, and mentor security and compliance teams in secure development practices• Act as a security and compliance subject matter expert and resource within the broader organization• Develop and lead strategies for the governance, risk and compliance functions across the company that support transformation of the security function• Ensure exposure to cybersecurity risks are identified and managed at an acceptable level• Maintain a security risk registry with clearly defined owners and timelines for each risk• Lead, coordinate, track and report all cybersecurity-related external assessments and internal audits including action plans and responses• Lead and deliver security training and awareness programs• Drive continuous improvement across all aspects of managing product security vulnerability reports and inquiries, communicating product security information to customers amongst other customer-related issues• Build solid working relationships with business stakeholders to maintain and improve product and application security processes• Interacting with project management team members and vendors on application projects• Implement and remediating security weaknesses, audit user system activity, perform security exercises, coordinate and perform all Authority to Operate (ATO) activities and related documentation requirements.Basic Qualifications• BS degree in Computer Science or related technical field and 7 years of prior relevant experience• Leadership experience in cybersecurity• Ability to obtain a Public Trust Clearance• Good understanding of popular application security standards including OWASP TOP 10 and SANS TOP 25• Strong understating of Single Sign-on (SSO) and Multi-factored authentication (MFA)• Knowledge/experience in data protection tools and techniques• Knowledge/experience in identity access management tools and common networking protocols• Act as a security and compliance subject matter expert and resource within the broader organization• Excellent written and verbal communication skills with the ability to adapt messaging to executive, technical, and non-technical audiences• Knowledge of NIST security controls and Risk Management Framework, Zero Trust Models and awareness and training programsPreferred Qualifications• Certifications such as: CISSP, CISM or CISA is desired• Static Code Analysis, DAST Penetration Testing, Intrusion Detection/Prevention, etc.• Previous experience in software development and/or cloud infrastructure operations.• Cloud Security and/or Networking Professional certification.hhsfdaOriginal Posting Date:2024-10-30While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.Pay Range:Pay Range $104,650.00 - $189,175.00The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Leidos Glassdoor Company Review
3.8 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Leidos DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Leidos
Leidos CEO photo
Tom Bell
Approve of CEO

Average salary estimate

$146912.5 / YEARLY (est.)
min
max
$104650K
$189175K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Compliance Security Lead, Leidos

Are you ready to take your career to the next level as a Compliance Security Lead at Leidos in Herndon, VA? This is an exciting opportunity to lead the implementation and improvement of our Information Security Management System. You will play a crucial role in shaping our corporate governance framework for cybersecurity risk, identifying vulnerabilities, and briefing senior leaders on essential security matters. Your work will involve conducting security and privacy assessments while creating and executing remediation plans that keep our operations smooth and secure. With a hybrid role, you'll enjoy the flexibility of working from home, while also being able to participate in vital onsite meetings across the DC Metro area. As a key player, you'll mentor and support our dedicated security and compliance teams, ensuring adherence to best practices in secure development. Your expertise will guide us in managing cybersecurity risks effectively, ultimately maintaining robust security throughout the organization. If you have a BS in Computer Science or a related field, 7 years of relevant experience, and a passion for leadership in cybersecurity, we encourage you to apply. As part of Leidos, you'll contribute to our mission of delivering trusted and innovative solutions that help our clients succeed in a rapidly evolving digital landscape.

Frequently Asked Questions (FAQs) for Compliance Security Lead Role at Leidos
What are the main responsibilities of a Compliance Security Lead at Leidos?

As a Compliance Security Lead at Leidos, your primary responsibilities will include leading the implementation of the Information Security Management System, conducting security and privacy assessments, and managing cybersecurity risks. You'll transition organizational governance frameworks, define priorities for projects, and advocate for continuous improvements in information security. Additionally, leading training programs and maintaining cybersecurity audit readiness are crucial tasks in this role.

Join Rise to see the full answer
What qualifications are needed for the Compliance Security Lead role at Leidos?

To qualify for the Compliance Security Lead position at Leidos, candidates must possess a BS degree in Computer Science or a related technical area along with at least 7 years of experience in cybersecurity. Strong leadership skills, knowledge of security standards like OWASP TOP 10, and experience with risk management frameworks such as NIST are essential. Familiarity with data protection tools and identity access management techniques will also be beneficial.

Join Rise to see the full answer
Does the Compliance Security Lead at Leidos require security clearance?

Yes, obtaining a Public Trust Clearance is a prerequisite for the Compliance Security Lead position at Leidos. The candidate must be a US Citizen or a US Person (Green Card Holder) to be eligible for this clearance, given the sensitive nature of the work involved.

Join Rise to see the full answer
What certifications are preferred for the Compliance Security Lead at Leidos?

Preferred qualifications for the Compliance Security Lead role at Leidos include certifications such as CISSP, CISM, or CISA. Having expertise in Static Code Analysis, DAST Penetration Testing, and Cloud Security certifications can strengthen your application, showcasing your commitment to the cybersecurity field and enhancing your effectiveness in this role.

Join Rise to see the full answer
What is the work environment like for a Compliance Security Lead at Leidos?

The Compliance Security Lead position at Leidos is hybrid, allowing for a blend of remote work and onsite meetings in the DC Metro area. This flexible work environment fosters collaboration with team members while ensuring accessibility to senior stakeholders, enabling efficient communication and decision-making related to the organization’s security posture.

Join Rise to see the full answer
Common Interview Questions for Compliance Security Lead
Can you describe your experience in leading cybersecurity teams?

When answering this question, share specific examples of your leadership roles in previous positions, detailing how you guided and mentored your teams in cybersecurity best practices, managed projects, and improved compliance standards.

Join Rise to see the full answer
How do you approach creating a cybersecurity risk management strategy?

Discuss your perspective on identifying potential risks, assessing their impact, and implementing controls to mitigate them. Highlight any frameworks or methodologies you have used to formulate successful security strategies.

Join Rise to see the full answer
What security frameworks are you familiar with, and how have you applied them?

Mention relevant frameworks like NIST or the Risk Management Framework, and provide examples of how you've utilized them to develop security policies, conduct assessments, or ensure compliance in your previous roles.

Join Rise to see the full answer
How do you maintain effective communication with non-technical stakeholders?

Share your strategies for adapting technical information for non-technical audiences by using simple language, visual aids, or analogies. Describe a specific instance where this skill helped convey critical security information.

Join Rise to see the full answer
What techniques do you use to perform security assessments?

Elaborate on the assessment techniques you employ, such as vulnerability scanning or penetration testing. Providing real-life examples will illustrate your hands-on experience in evaluating the security landscape.

Join Rise to see the full answer
Can you give an example of a security incident you managed and the outcomes?

Describe a specific incident, outlining your response actions, the collaboration with your team, and how the incident was resolved. Discuss lessons learned and adjustments made to prevent recurrence.

Join Rise to see the full answer
What role does continuous improvement play in cybersecurity?

Discuss the importance of continuous improvement in adapting to evolving threats. Share methods you’ve implemented to review and enhance security measures and processes based on lessons learned or best practices.

Join Rise to see the full answer
What experience do you have with security training and awareness programs?

Talk about how you’ve designed or led training initiatives aimed at educating employees about security best practices. Highlight any measurable impacts these programs had in improving the organization's security posture.

Join Rise to see the full answer
How do you handle regulatory compliance in cybersecurity?

Explain your process for maintaining compliance with industry regulations and standards, giving examples of relevant compliance projects you've managed and how you ensured adherence through audits or documentation.

Join Rise to see the full answer
What strategies do you use to stay updated on cybersecurity trends?

Share how you keep abreast of the latest developments in cybersecurity through industry publications, networking, conferences, or certifications. Mention how staying informed has influenced your work and decision-making.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 7 days ago
Photo of the Rise User
Posted 9 hours ago
Photo of the Rise User
Tipico Remote Vjal Portomaso, St. Julian's, Malta
Posted 7 days ago
Photo of the Rise User
Posted 3 days ago
Photo of the Rise User
Foot Anstey LLP Remote Bristol, Exeter, Plymouth or Southampton
Posted 6 hours ago
Jobot Hybrid Freehold Township, NJ
Posted 10 days ago

Everything we do is built on a commitment to do the right thing for our customers, our people, and our community. Our Mission, Vision, and Values guide the way we do business. At Leidos, our mission is to make the world safer, healthier, and mor...

391 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
December 20, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!