Skip to main content
Tallo logoTallo logo

Find Jobs

Find Jobs Near You – Available Work in Your Location

Skip to job details

Back to Results

Apply for this opportunity

To apply for this job, you'll continue to an external website or email application.

ClearanceJobs.com | Leidos, Inc. | CollegeRecruiter | Programmatic - Appcast

Cyber Security STIG Tester

Career Insights for Vulnerability Analyst / Penetration Tester

See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.

Scorecard

Based on Maryland data

Review key factors to help you decide if this role fits your goals. How is this calculated?

Were these scores useful?

What they do

A Vulnerability Analyst or Penetration Tester probes for and exploits security vulnerabilities in web-based applications, networks and systems. Penetration Tests are designed to achieve a specific, attacker-simulated goal and should be requested by customers who are already at their desired security posture. A typical goal could be to access the contents of the prized customer database on the internal network, or to modify a record in an HR system. Vulnerability Assessments are designed to yield a prioritized list of vulnerabilities and are generally for clients who already understand they are not where they want to be in terms of security. The customer already knows they have issues and simply need help identifying and prioritizing them.

$121,766 / year median in Maryland

+3% projected growth

Explore Career

Job Description

Cyber Security STIG Tester

R-00191998DescriptionAre you ready to make an impact and join a creative, forward-thinking team?



Leidos is seeking qualified Cyber Security STIG Tester to join our GSMO-II team at Ft. Meade, MD.

POSITION SUMMARY:

The selected candidate shall perform (or review) technical security assessments using STIG Checklists, SCAP scans, and

ACAS/ESS

Scans of computing environments to identify points of vulnerability, non-compliance with established Information Assurance (IA) guidelines and regulations and recommend mitigation strategies. In this role, the candidate will ensure that the environments in which DoD information systems reside are secure and compliant, develop approaches to secure the environment, assess threats to the environment, provide inputs on the adequacy of security designs and architectures, perform RMF STIG and compliance testing related activities, and participate in risk assessment mitigation with the system administrators and providing relevant reporting for security briefing.

CLEARANCE REQUIREMENT
  • Must hold an active Secret security clearance.

(US Citizenship required)

PRIMARY RESPONSIBILITIES
  • Ensure STIG Checklists are up to date and settings are enforced with minimal operational impact for all systems (workstations, servers, network) within the environment.
  • Support systems within GMS to have an up to date and complete STIG Checklist; educate systems/network administrators regarding completion/edits as required.
  • Examine results of STIG testing and pass results to system owners and system administrators.
  • Track response times to STIG findings and report on the security briefing.
  • Support POA&M analysis and coordination efforts, as required, including eMASS updates.
  • Perform cybersecurity lab testing/hardening activities supporting deployment of/updates to computer systems and applications.
  • Review data from
ACAS/ESS

scans and set tickets to add new equipment into scans as necessary.

  • Maintain SOP's for testing and reporting activities.
  • Support functional testing as necessary for new technology.
  • Support testing events and preparation for testing events.
  • Perform vulnerability/risk analyses of computer systems and applications during all phases of the system development life cycle.
  • Support Authorizing Official (AO) actions by ensuring all testing related security testing artifacts are presented in accordance with RMF as defined in
NIST 800-37

revision 2 and related agency specific RMF requirements.

  • Have experience performing various types of vulnerability and assessment scans with multiple tools.
BASIC QUALIFICATIONS
  • Bachelor's degree and 8+ years of experience; additional years of directly applicable experience may be accepted in lieu of a degree.
  • Prior relevant experience working with STIG Compliance, SCAP tools, vulnerability assessments and reporting.
  • Have experience performing various types of vulnerability and assessment scans with multiple tools.
  • Have experience using eMASS and/or Xacta.
  • Solid understanding of the Risk Management Framework (RMF) and the System Development Life Cycle (SDLC).
  • Understanding of hardware and software engineering best practices.
  • Demonstrated analytical and problem-solving skills.
  • Must meet eligibility requirements for work assignment on specified contract.
  • Applicants selected will be subject to a government security investigation and must meet eligibility requirements.
  • Current DoD 8570 IAT II Certification is required.

(Sec+.)

PREFERRED QUALIFICATIONS
  • Ability to identify needed changes to processes and activities and help to implement continuous improvement solutions.
  • ACAS training completed.
  • Ability to work successfully as part of a virtual team.

If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares.

Original Posting:

September 10, 2026 For U.S.

Positions:

While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above.

Pay Range:

Pay Range $107,900.00 - $195,050.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law. About Leidos Leidos is an industry and technology leader serving government and commercial customers with smarter, more efficient digital and mission innovations. Headquartered in Reston, Virginia, with 47,000 global employe...Visit the Employer site for more details

Benefits

  • Dental Insurance