Overview
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visitperaton.comto learn how we’re keeping people around the world safe and secure.
Responsibilities
Peraton seeks aCyber Operations Research Analyst (CORA) Reviewerto conduct information assurance of DoWIN cybersecurity reviews for DCDC.Travel is expected, as work is conducted on site at Continental United States (CONUS), Outside Continental United States (OCONUS), and DOD mission partner locations. .Location: Fort Meade, MD or Chambersburg, PA.Tasks include:Support inspections,evaluations, audits, assessments, DCO-IDM missions, and/or self-assessments of the DoWIN -- follow the DoWIN Inspections and Assessments Schedule.Support on-the-job training and certify new Reviewers via the reviewer certification process.Perform assessments of systems and networks within a Network Environment (NE) / enclave and identifiy deviations from acceptable configurations, enclave policy, or local policy.Follow policies and procedures for specificreview type, ensuring thattechnical expertise is properly represented.Conduct vulnerability reviews, review Security Requirements Guides (SRGs), STIGs, DOD Policy, Cyber Tasking Orders (CTO) and Operational Orders to determine the security posture and compliance of the site/NE/enclaveAssist in developing the Executive Summary/Briefings/Reports foreach trip/assessmet.Conduct internal and/or external vulnerability scansAssemble scanning “packages” prior to conducting scansPerform technical Security Readiness Reviews (SRRs)Use the appropriate technology STIG/SRG and, where applicable, the appropriate automated script or tool for that technology.Provide assessments of the security posture of the organization (traditional): Personnel security, INFOSEC, Physical security, Industrial security, Counterintelligence, and overall security management.Develop and maintain cybersecurity vulnerability review, inspection, and audit Standard Operation Procedures (SOPs), Tactics, Techniques and Procedures (TTPs), checklists, and guidesIdentify the root cause and gap analysisProvide resolution support during theCybersecurity reviewProvide recommendations for fixes and mitigation strategies and validatepost inspection vulnerability mitigation actions as requested.Identify where systems/networks deviate from acceptable configurations, enclave policy, or local policy.
Qualifications
Required:Minimum of 12 years experience with BS/BA, 10 years with MS/MA, 7 years with Ph.D. Will consider HS with 16 years of experience, or Associates and 14 years of experience.Senior Reviewers must have at least 2 years of direct experienceThis position aligns to the KSA's identified to the Vulnerability Assessment Analyst under the DOD Cyber Workforce Framework (DCWF):Must have experience in collecting, analyzing, and assessing data in order to provide formal feedback. Specifically, able to analyze organization's cyber defense policies and configurations and evaluate compliance with regulations and organizational directives (i.e., analysis of mitigations).Should have experience with maintaining a deployable cyber defense audit toolkit (e.g., specialized cyber defense software and hardware) to support cyber defense audit missions.Skilled in reviewing logs to identify evidence of past intrusions.Able to identify systemic security issues based on the analysis of vulnerability and configuration dataAble to identify/assess proper architecture for different operating environmentsUnderstanding of cybersecurity strategy in cloud computing service and deployment modelsMust have knowledge of applicable DoW cyber defense policies, regulations, and compliance documentsNeeds to have an understanding of different types of reviews/assessmentsAs a CORA Reviewer, must cross-certify in multiple related technology areas to allow flexibility for assessment needs from various organizations (e.g., network reviewer may also support network vulnerability scan, virtual infrastructure, cloud, and other related areas)Travel is expected to worldwide locations. Travel will be conducted in accordance with the Task Order guidelines.CurrentIATLevel II certification.CurrentIAMLevel II certification.TS/SCI security clearance or the ability to obtain SCIU.S Citizenship requiredPreferred:Active TS/SCI clearanceCurrent IAT Level III CSSP-Auditor certificationCurrent IAM Level III certification