Senior CyberArk / PAM SME
DescriptionRanked first in Government IT and systems integration, Leidos brings decades of experience leading large-scale mission-critical network IT programs. We’re looking for innovators and forward-thinkers to help us do great things.Leidos is seeking qualified candidates to join our Defense Enclave Services team, who will support an extensive digital modernization program critical to DISA and Fourth Estate Agencies.We offer competitive compensation, retirement and paid leave packages, health and wellness programs, career development trainings and certifications, income protection, employee stock purchase plans, and family benefits.Job Description:In this role, a successful candidate will be able to provide security architecture support and interface across the program as needed. This support includes, but is not limited to, cybersecurity solutions, business development support, helping to create and deliver presentations at both internal and client engagement meetings, and providing technical strategy for solutions, guidance, policy, and implementations. The successful candidate for this position is a highly motivated individual, with a strong IT security background who excels integrating, operating, and deploying security technology and solutions and interacts well with both internal teams and clients.Primary Responsibilities :
Develop secure privileged access management solutions and architectures for clients.
Evaluate designs and infrastructure against information assurance/security standards and procedures.
Support Authorizing Official (AO) actions by developing and delivering PAM (Privileged Access Management) solutions that include supporting documents and artifacts in accordance with RMF as defined in NIST 800-37 revision 2 and related agency specific RMF requirements
Provide input into an Audit and Accountability Plan containing methods, procedures, and planned reviews for the continuing accreditation and authorization against AU (Audit and Accountability) family controls per NIST SP 800-53 guidance
Provide input to and guide implementation and/or verification and validation of an organizational access control policy and plan reflecting PAM and integrated cybersecurity solutions in compliance with risk-levels defined in the National Institute of Standards and Technology (NIST) 800-53, rev 4, Access Control family of controls to include auditing annually, at a minimum
Develop integrated solutions, processes, and procedures for evaluating, monitoring, remediating, and/or documenting information system security vulnerabilities IAW DoD Instruction (DoDI) 8510.01 (RMF for DoD IT)
Support integration and implementation of Asset Management, Identity, Access Control Systems/Solutions, Compliance Monitoring and Remediation, Multi-Factor Authentication (MFA) and/or single sign-on (SSO) solutions in addition to other cybersecurity and/or cyber operations tools and solutions IAW DoDI 8520.02, DoDI 8520.03, and other applicable policies and regulations
Review and recommend updates to existing PAM architectures, designs, and/or solutions
Basic Qualifications:
Bachelor’s degree and 12-15 years of related experience. Relevant experience may be substituted for education.
Certified Information Systems Security Professional (CISSP)
8+ years hands-on experience designing or implementing PAM solutions, including all related documentation and artifacts
Analytical ability, problem-solving skills, and ability to break down complex problems into actionable steps
Extensive experience in design and development of enterprise PAM architectures. Experience must include a wide range of work in creating diagrams and documentation with all components that comprise IT systems including network topology.
Experience selecting effective methods, techniques, and evaluation criteria to achieve desired outcomes.
Understanding of federal cybersecurity guidance such as FISMA NIST SP 800-37 - Guide for Applying the Risk Management Framework to Federal Information Systems: a Security Life Cycle Approach and NIST 800-137 - Information Security Continuous Monitoring (ISCM) for Federal Information Systems and Organizations.
Previous experience developing architectures, strategies, strategic plans, roadmaps, and technical standards for the federal IT enterprise environment.
Preferred Qualifications:
CyberArk Sentry certified
CyberArk Guardian certified
Other PAM solution certification(s)
Additional certifications demonstrating cybersecurity/technical mastery
DISADESExternal Referral EligibleOriginal Posting Date:2024-10-02While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.Pay Range:Pay Range $122,200.00 - $220,900.00The Leidos pay range for this job level is a general guideline onlyand not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.#RemoteREQNUMBER: R-00145165All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. Leidos will consider qualified applicants with criminal histories for employment in accordance with relevant Laws. Leidos is an equal opportunity employer/disability/vet.