Peraton is a next-generation national security company that drives missions of consequence spanning the globe. They are seeking a seasoned Information Assurance and Security Engineer to serve as an Information System Security Officer (ISSO) for a cloud-hosted, Azure-based system, providing security expertise and support for Agile software development teams.
Responsibilities:
- Provide technical and programmatic information assurance support to internal and external customers for network and information security systems
- Design, develop, and implement security requirements across enterprise and program-level business processes
- Prepare documentation and security artifacts based on customer input and industry standard guidelines (e.g., NIST RMF, DHS 4300A). Lead certification and accreditation activities for the program
- Develop and maintain security test and evaluation plans and contingency plans
- Conduct risk and vulnerability assessments and prepare formal reports and recommendations
- Analyze existing policies and procedures for compliance with Federal laws, regulations, and standards; recommend remediation strategies to close security gaps
- Recommend system enhancements to address identified deficiencies and improve the overall security posture
- Design, test, and integrate computer and network security tools; secure system configurations and ensure compliant deployments
- Perform system scans, interpret results, and support system administrators in resolving findings
- Conduct internal security program audits and develop mitigation strategies to address identified risks
- Provide technical guidance for secure architecture design supporting evolving mission needs
- Support security incident investigations, root-cause analysis, and response
- Perform vulnerability assessments and develop, document, and track corrective action plans
Requirements:
- Bachelors degree and 5 years of experience, or an Associates degree and 7 year of experience or a High School diploma/equivalent and 9 years of experience
- Must be a U.S. Citizen with the ability to obtain and maintain a DHS Public Trust clearance
- Demonstrated experience performing Information System Security Officer (ISSO) duties in a Federal or regulated environment, including creating and maintaining RMF documentation, SSPs, POA&Ms, security test plans, and continuous monitoring artifacts
- Proven experience supporting software development teams delivering Azure-based cloud solutions, including familiarity with Azure AD, App Services, Key Vault, App Gateway/WAF, and cloud-native security controls
- Hands-on experience identifying, tracking, and managing security vulnerabilities, including interpreting scan results (e.g., Tenable/Nessus, Microsoft Defender) and working with engineering teams on mitigation strategies
- Strong understanding of NIST 800-53, 800-30, 800-37, and 800-171 frameworks
- Active CISSP certification, or the ability to obtain within 6 months of hire
- Strong communication skills, including developing briefing materials, presenting technical concepts to nontechnical stakeholders, and supporting customer engagements
- Working knowledge of DHS security policies, controls, and compliance requirements, including DHS 4300A/B, 4300A Sensitive System Handbook, and associated RMF processes
- Knowledge of Azure security architecture patterns such as Zero Trust, RBAC, network segmentation, PIM/PIM, and least-privilege design
- Strong understanding of Agile methodologies and successful collaboration within cross-functional Agile teams, including participation in sprint planning, backlog refinement, and security-focused reviews
- Experience with security automation and DevSecOps workflows (e.g., GitHub Actions, Azure DevOps pipelines, IaC security scanning)
- Experience implementing Continuous Monitoring plans, dashboards, and automated control reporting
- Additional security certifications such as ISC2 CAP, ISC2 CCSP, CompTIA Security+, or Azure Security Engineer Associate (AZ-500)