Overview
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visitperaton.comto learn how we’re keeping people around the world safe and secure.
Responsibilities
Peraton is seeking a Information Assurance and Security Engineer. The position will be responsible for the following but not limited too:This position is remoteProvide technical and programmatic information assurance services to internal and external customers in support of network and information security systems across the DEERS application portfolio.Design, develop, and implement security requirements within the organization's business processes, including DevSecOps pipelines, cloud migration activities (OCI), and Agile development sprints.Prepare and maintain security documentation using accepted DoD and NIST guidelines, includingSystem Security Plans (SSPs),Security Assessment Reports (SARs),Plans of Action and Milestones (POA&Ms),STIG checklists, and implementation plans withineMASS.PrepareSecurity Test and Evaluation (ST&E) plansand support execution of formal security assessments in coordination with the DMDC Cybersecurity Division (CSD) and Enterprise ISSOs.ProvideCertification and Accreditation (C&A) / Assessment and Authorization (A&A) support, including development of security and contingency plans, in alignment withDoDI 8510.01andNIST SP 800-37RMF principles.Conduct complexrisk and vulnerability assessments; develop and maintain risk mitigation strategies addressing identified weaknesses across the DEERS application environment.Analyze organizational policies and procedures against Federal laws and regulations - includingFISMA,NIST SP 800-53 Rev 5,DoDI 8500.01, andOMB M-14-03- and provide recommendations for closing identified compliance gaps.Recommend and implement system enhancements to improve security deficiencies; supportIAVA (Information Assurance Vulnerability Alert)monitoring and monthly resolution activities.Develop, test, and integrate computer and network security tools, includingFortify,Sonatype, andBURPscanning solutions; integrate security scanning into the DevSecOps pipeline for every production release.Secure system configurations and install security tools; scan systems to determine compliance againstSTIGandNIST SP 800-53 Rev 5baselines; report results and evaluate products and system administration configurations.Conductsecurity program auditsand develop solutions to address identified risks; support 1-3 external audits annually (e.g., DHA MERHCF, DoD CIO ICOFR, FIAR).Provide IA support for the development and implementation of security architectures to meet new and evolving security requirements, including support for OCI cloud migration atDISA IL-4/IL-5authorization levels.Provide assistance incomputer incident investigations; report cyber incidentswithin 1 hourof discovery perDFARS 252.204-7012and DMDC IR Team protocols, with follow-up reporting every 24 hours until closure.Perform vulnerability assessments including development of risk mitigation strategies; submitPOA&Ms within 3 business daysof Category 1 or 2 vulnerability identification and update within 10 business days of vulnerability events.SupportInformation Security Continuous Monitoring (ISCM)activities perNIST SP 800-137/137A,DoDI 8530.01, andDoDI 8531.01, and report weekly vulnerability scan status during Integrated Progress Reviews (IPRs).Maintain and support the program'sATOs and A&I packagesthrough the full RMF lifecycle - Prepare, Categorize, Select, Implement, Assess, Authorize, and Monitor.ImplementJFHQ-DODINandUSCYBERCOMCyberspace Tasking Orders (CTOs) as directed.Ensure all cybersecurity workforce personnel are identified, screened, trained, and certified in accordance withDoD 8140.03andCMMC (DFARS 252.204-7021)requirements.Conduct and support mandatory security training including OPSEC, CUI Handling, Insider Threat, Privacy Act/PII, IT Security Awareness, Counterintelligence, Antiterrorism Level I, and Records Management.
Qualifications
Minimum of 8 years with BS/BA; Minimum of 6 years with MS/MA; Minimum of 3 years with PhD, 12 years with HS diplomaAbility to obtain and maintain DOD Public TrustHands-on experience with theDoD Risk Management Framework (RMF)and associated tooling, specificallyeMASS (Enterprise Mission Assurance Support Service).In-depth knowledge ofNIST SP 800-53 Rev 5,NIST SP 800-37,NIST SP 800-171 Rev 2,NIST SP 800-137,FISMA,DoDI 8510.01, andDoDI 8500.01.Experience conductingvulnerability assessments, developingPOA&Ms, and managing the full A&A lifecycle including ATO package development.Experience with application security scanning tools includingFortify,Sonatype, andBURP; familiarity withOWASPsecure coding practices.Working knowledge ofSTIGcompliance verification, checklist preparation, and remediation.Demonstrated experience supportingDevSecOpssecurity practices within Agile development environments.DoD 8140.03 / DoD 8570.01-M compliant certification IAT/IAM Level II(e.g., CISSP, CASP+, CEH, Security+, or equivalent certification).Preferred QualificationsActive Public Trustclearance.CISSP (Certified Information Systems Security Professional)or equivalent advanced certification.Experience withcloud securityatFedRAMP Moderate,DISA IL-4, orDISA IL-5authorization levels; familiarity withOracle Cloud Infrastructure (OCI)security configuration.Familiarity withCMMC (Cybersecurity Maturity Model Certification)framework and compliance.Experience supporting externalDoD financial/operational audits(FIAR, ICOFR, FISCAM).Working knowledge ofServiceNow,JIRA, andSharePointin an ITSM/project context.Knowledge ofDFARS 252.204-7012cyber incident reporting requirements.Experience implementingcyberspace tasking orders (CTOs)from JFHQ-DODIN or USCYBERCOM.Prior experience in the S-ISSO role within a large-scale DoD program environment