Overview
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visitperaton.comto learn how we’re keeping people around the world safe and secure.
Responsibilities
Peraton is seeking a Senior ISSO to support our customer onsite in Washington D.C.Key responsibilities include:Lead or co-lead ATO/reauthorization efforts for complex boundary systemsMentor junior ISSOs and shape security operations playbooksPerform risk analysis and author formal recommendations to leadershipDrive security engineering outcomes by partnering with internal teams on scalable compliance patternsBrief senior internal and customer stakeholders on security posture, systemic risk trends, remediation burn-down, and authorization readinessAct as the Senior ISSO supporting the system security lifecycle across development, operations, and modernizationExecute and maintain RMF activities (e.g., control implementation oversight, evidence collection, assessment support, POA&M management, continuous monitoring)Maintain security authorization artifacts (e.g., SSP, control narratives, diagrams, inheritance/leverage controls, CM plan, incident handling plan, contingency artifacts, user/admin procedures)Operate continuous monitoring: vulnerability management, config compliance, patching coordination, scan result triage, risk acceptance, and remediation verificationReview and approve security-relevant changes through configuration/change control and validate security configurations after major upgradesSupport incident response and reporting: participate in investigations, coordinate containment actions, preserve evidence, and contribute to post-incident lessons learnedEnsure least privilege/access governance: account management oversight, privileged access workflows, periodic access reviews, and audit compliance requirementsTranslate security requirements into implementation guidance that engineering teams can operationalize (clear, testable, and automatable where possible)
Qualifications
Required QualificationsRequires active Top Secret clearance with SCI eligibilityMin 12 years with BS/BA, Min 10 years with MS/MA; may consider 4 additional years experience in lieu of BS degree.8+ years of experience in information security/compliance supporting DOD/IC or government systems, including ownership of major RMF deliverables and ATO events for complex systemsDemonstrated leadership experience coordinating across security, engineering, and customer stakeholdersAbility to provide mentorship and direction to team membersProven ability to write risk decisions and packages that stand up to assessor/AO scrutinyDeep understanding of continuous monitoring at scale (recurring evidence, metrics, audit readiness, remediation governance)Hands-on experience executing RMF tasks and maintaining authorization artifacts (SSP, POA&Ms, continuous monitoring evidence)Strong working knowledge of NIST SP 800-53 controls and how they map to technical implementations and proceduresExperience with vulnerability and configuration compliance workflowsAbility to communicate risk clearly to both technical engineers and non-technical leadershipOne or moreactive/currentcertifications such as: CISSP, CISM, SecurityX, Security+, and etc.Preferred QualificationsExperience with SAP assessments and authorizationsExperience securing or assessing different platforms (applications, databases, operating systems, hardware, and etc )Experience with SCRUM methodologiesExperience with Splunk and/or other auditing compliance tools.Experience with ACAS, Nessus, and/or other vulnerability scannersExperience with data protection requirements relevant to sensitive environments