Leidos hiring for Cyber Security Watch Officer Lead jobs in Odenton, MD, US
Description
The Leidos Digital Modernization Sector has a current job opportunity for a Cyber Security Watch Officer (CSWO) - Lead on our GSM-O II DISA Command Comprehensive Support Services (DCCSS) program supporting the 24x7 operations at the DISA Joint Operations Center (DJOC) on Ft. Meade, MD.
The ideal candidate will serve as the Cyber Security Watch Officer (CSWO) - Lead of a small cyber focused team supporting the Command and Control (C2) of DISA operations across the enterprise via a 24x7 mission support model. The Lead must support, provide leadership, and have the interpersonal communication skills necessary to inspire and lead a complex and high-paced environment. The lead will interface with program and customer leadership across multiple fields to include, but not limited to, Current Ops, Future Ops, Defensive Cyber Ops, and Fields Operations Commands.
This position will participate in the day to day functions of the team and support shift coverage where needed. The Lead will primarily work during core business hours to better enable communication and collaboration with program and customer leaders. We currently define these hours as Mon-Fri, 0800 – 1600, and this role could require afternoon, overnight, weekends, and/or holidays coverage to visit employees or help provide shift coverage to ensure minimal manning is achieved across the shifts.
The position is also an active participant in the Contingency Support and the Emergency Readiness Group (ERG) and employees are considered emergency personnel who will perform duty functions at customer off-site facilities within the DC Metro Area.
PRIMARY RESPONSIBILITIES:
Serve as a people leader for personnel supporting the CSWO watch desk by conducting:
- Annual performance assessments to include periodic check ins,
- Approving or validating time charging for both Leidos and vendor personnel,
- Providing coaching and mentoring to personnel.
Serve as the Senior CSWO and customer point of contact for the following:
- Develop and execute continual service improvement technical strategies to modify and enhance operational processes and impact strategic goals.
- Create, update, and maintain SOPs, TTPs and documentation for training or reference material for the CSWOs.
- Communicate and coordinate work with the DJOC and the DCO Report DCO on incident management responses to network intrusions, malware, and other cyber events.
- Support the DJOC Battle Captain with all Cyber Defense and Network Assurance issues to include making recommendations regarding Indicators of Compromise (IOC), malicious cyber activity, and the overall security posture of our networks.
- Provide technical oversight of information security services and customer support initiatives, by Updating DoD shared SA and knowledge management (KM) tools, including CMDNet, websites, blogs, and wikis, chat, collaboration tools, and portals.
- Consume and analyze operational reporting from cyber organizations; prepare and deliver daily situational awareness and operational update briefings, through the by coordinating with other cyber elements to obtain information for slide, briefings, presentations, or other SA products.
- Maintain awareness of all pertinent directives, orders, alerts, and messages to include the preparation and delivery of daily situational awareness and operational update briefings to DISA Senior Leadership.
- Oversee all network defense operations and be familiar with the operations process flow and execution. Coordinate and collaborate with internal DISA elements and mission partners to share the understanding and impact of day-to-day malicious cyber activity.
- Identify problems, determine accuracy and relevance of a broad range of technical information. Use sound judgment to generate, evaluate, and execute alternative courses of action. Produce timely, effective, decision-quality technical recommendations to support senior leadership.
- Coordinate and ensure DoD incident handling reporting procedures are adhered to in accordance with (IAW) DoD, CJCS, USCC, and DISA guidance, regulations, and directives. Review Commander Joint Chiefs of Staff Manual (CJCSM) 6510: Cyber Incident Handling Program.
- Serve as Senior Defensive Cybersecurity SME during 24x7 operations. Requires the ability to think independently and make decisions/recommendations which will have an immediate effect on the security of our networks.
BASIC QUALIFICATIONS:
- BA/BS or equivalent experience and 5+ years or prior relevant experience or Masters with 3+ years of prior relevant experience. Additional experience may be accepted in lieu of degree.
- Must have an active Top Secret/SCI security clearance.
- Must have a DoD-8570 IAT Level 2 baseline certification (Security+ CE or equivalent) to start and must obtain CSSP-A certification within 180 days of start date.
- Experience in a 24x7 environment. This includes mentoring, training, and reviewing the work performed by more junior personnel.
- Experience creating and maintaining shift scheduling and leave request in a 24x7 environment.
- Leadership experience with small to medium sized team in a 24x7 work environment.
- Strong Oral, Written and Briefing communication skills.
- Strong interpersonal, organizational and problems solving skills..
- Flexible, dependable, and be able to multi-task with priorities.
- Demonstrated understanding of the life cycle of network threats, attacks, attack vectors and methods of exploitation with an understanding of intelligence driven defense and/or Cyber Kill Chain methodology.
- Develops solutions to issues that are unclear and require deep technical knowledge.
- Experience recognizing situational awareness indicators and executing judgment of potential impact on mission operations.
- CND / CSSP / MSSP experience (Protect, Detect, Respond and Sustain) within a Computer Incident Response organization. Requires a deep understanding and the ability to apply cyber security related principles, theories, and concepts.
PREFERRED QUALIFICATIONS:
- Prior Military IT or IC Experience
- Hands on Experience working with DoD Networks including NIPR and SIPR
- Motivated, initiative driven person with strong written and verbal communication skills, replying to official communications via email or phone, with the ability to report or speak to complex technical reports on analytical findings.
- Demonstrated understanding of the life cycle of cybersecurity threats, attacks, attack vectors and understanding of intrusion set tactics, techniques, and procedures (TTPs)
Original Posting Date:2024-09-03
While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.
Pay Range:Pay Range $101,400.00 - $183,300.00
The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.