Information Assurance and Security, Advisor
Peraton · UNAVAILABLE, UNAVAILABLE, US
About this role
## Information Assurance and Security — Advisor ### Responsibilities - Serve as **Regulatory and Compliance Lead** for the **CMS Fraud Prevention Services (FPS) Team**, providing the regulatory-and-compliance portion of the **agentic AI vendor evaluation**. - Produce security-and-compliance inputs to the **POC Solution proposal**, including: - Control inheritance - Boundary definition - Data-flow diagrams - Compliance narrative for a **vendor-isolated exclusive environment** - Ensure all security-related activities, POC data paths, and vendor artifacts remain within the **FPS ATO boundary** and comply with **CFACTS, CSRAP, FISMA, and HIPAA PHI** requirements. - Assess candidate agentic AI vendors for **CMS security posture, data-handling, and ATO requirements** as part of the vendor-list assessment. - Coordinate with **FPS ISSO/ISSM** and **CMS security stakeholders** to keep AI tool assessment and POC activity inside the **FPS ATO boundary**. - Own compliance artifacts and cadence for the AI vendor-evaluation effort, including (as applicable): - **SSP inputs** - **POA&M entries** - **PIA/SORN** - Act as the **single point of contact** for security-and-compliance questions from third-party vendors, CMS, and the **Peraton PM**. - Advise the Lead **AI Solutions Architect** on LLM/agentic-AI compliance concerns, such as: - Model-provider data retention - Prompt/response logging - PHI-in-prompt controls - Tool authorization ### Qualifications - **Minimum education/experience**: - 8+ years with **BS/BA**; or - 6+ years with **MS/MA**; or - 3+ years with **PhD** - Experience leading compliance work on **Federal systems** (ideally **CMS**). - Deep working knowledge of CMS (or other Federal agencies) security frameworks: - **CFACTS**, **CSRAP**, and the **ATO lifecycle** (SSP, SAR, POA&M, contingency plan, PIA/SORN) - Practical experience with **FISMA / NIST SP 800-53** control tailoring, including inheritance from cloud providers (e.g., **AWS FedRAMP baselines**) and **boundary definition**. - Experience assessing third-party/vendor security posture (e.g., **SOC 2**, **FedRAMP**, **HIPAA/HITRUST**, penetration-test evidence, vulnerability management). - Familiarity with cloud-native security in **AWS** (e.g., IAM, KMS, GuardDuty, CloudTrail, Config), **Okta SSO/RBAC**, and audit-log routing to **CloudWatch/Splunk**. - Working knowledge of **HIPAA PHI** handling and Federal PII requirements (especially Medicare/Medicaid claims data). - Ability to author security artifacts and briefings for **CMS-level review**; strong technical writing. - **US citizenship** and ability to obtain/maintain a **Public Trust** clearance. ### Preferred Qualifications - **CISSP, CISM, CAP, CISA**, or equivalent certification. - Prior compliance work on **FPS ATO** or another CMS ATO’d system (e.g., IDR, One PI, UCM). - Familiarity with security considerations specific to **LLM and agentic AI** (model-provider data retention, prompt logging, MCP tool authorization, RBAC for LLM outputs). - Experience defining **vendor-isolated enclaves** inside a Federal customer authorization boundary. - Familiarity with **SAFe Agile compliance** patterns (continuous ATO / RMF automation). - Experience with **Databricks** and **Snowflake** governance controls (Unity Catalog, dynamic masking, row/column access policies). ### Peraton Overview Peraton is a next-generation national security company that delivers trusted solutions and enterprise IT servic
Listing freshness
CronJobs last confirmed this listing 2h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.