Information Assurance and Security Engineer
Peraton · UNAVAILABLE, UNAVAILABLE, US
About this role
## Information Assurance and Security Engineer (ISSO) — Remote ### Responsibilities - Provide technical and programmatic information assurance support for network and information security systems. - Design, develop, and implement security requirements across enterprise and program-level business processes. - Prepare security documentation and artifacts aligned to customer input and industry standards (e.g., **NIST RMF**, **DHS 4300A**). - Lead **certification and accreditation (C&A)** activities for the program. - Develop and maintain security **test and evaluation plans** and **contingency plans**. - Conduct **risk and vulnerability assessments**, and produce formal reports with recommendations. - Analyze policies/procedures for compliance with Federal laws, regulations, and standards; recommend remediation strategies. - Recommend system enhancements to improve overall security posture. - Design, test, and integrate computer/network security tools; secure configurations and ensure compliant deployments. - Perform system scans, interpret results, and support administrators in resolving findings. - Conduct internal security program audits and develop mitigation strategies. - Provide technical guidance for secure architecture design supporting evolving mission needs. - Support security incident investigations, root-cause analysis, and response. - Perform vulnerability assessments and develop/track **corrective action plans**. ### Qualifications **Basic Qualifications** - Bachelor’s + **8 years** experience, or Master’s + **6 years**, or Associate’s + **10 years**, or High School + **12 years**. - **U.S. Citizen** with ability to obtain and maintain a **DHS Public Trust** clearance. - Demonstrated ISSO experience in a Federal/regulated environment, including RMF documentation (e.g., **SSPs**, **POA&M(s)**, security test plans, continuous monitoring artifacts). - Experience supporting **Agile** software development teams delivering **Azure** cloud solutions (e.g., **Azure AD**, **App Services**, **Key Vault**, **App Gateway/WAF**, cloud-native security controls). - Hands-on vulnerability management (e.g., interpreting scan results such as **Tenable/Nessus** and **Microsoft Defender**) and partnering with engineering teams on mitigation. - Strong knowledge of **NIST** frameworks: **800-53**, **800-30**, **800-37**, **800-171**. - **Active CISSP** (or ability to obtain within **6 months** of hire). - Strong communication skills for briefing materials and presenting to nontechnical stakeholders. **Preferred Qualifications** - Working knowledge of **DHS** security policies/controls/compliance (e.g., **DHS 4300A/B**, Sensitive System Handbook, RMF processes). - Knowledge of Azure security architecture patterns (e.g., **Zero Trust**, **RBAC**, network segmentation, **PIM**, least-privilege). - Agile experience (sprint planning, backlog refinement, security-focused reviews). - DevSecOps/security automation experience (e.g., **GitHub Actions**, **Azure DevOps pipelines**, IaC security scanning). - Experience implementing **Continuous Monitoring** plans, dashboards, and automated control reporting. - Additional certifications (e.g., **ISC2 CAP/CCSP**, **CompTIA Security+**, **AZ-500**). ### Pay Range - **$86,000 – $138,000** (typical range; final offer depends on experience, location, and contract factors). ### Company Peraton — a national security company delivering mission-critical enterprise IT and mission capability integration. *EEO: Equa
Listing freshness
CronJobs last confirmed this listing 23h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.