Cybersecurity / Compliance Engineer
Peraton · Chantilly, VA, US
About this role
## Cybersecurity / Compliance Engineer ### Responsibilities - Implement and sustain security controls, authorization evidence, continuous monitoring, vulnerability management, and software-security requirements across enterprise environments. - Partner with platform, cloud, DevSecOps, IAM, observability, and application teams to ensure security requirements are built into engineering and operational processes. - Support Risk Management Framework (RMF), authorization, compliance, and continuous-monitoring activities. **Risk Management & Authorization Support** - Perform RMF, security assessment, authorization, and continuous-monitoring activities for enterprise services and environments. - Maintain security evidence, control implementation information, POA&M inputs, and authorization documentation. - Assess and document security impacts for platform, infrastructure, application, and COTS/GOTS software changes. - Support common-control and inherited-control documentation/implementation where applicable. - Coordinate with security, engineering, and operational stakeholders to address control gaps and authorization requirements. **Technical Security Engineering** - Define and review security requirements for cloud, Kubernetes, CI/CD, identity, network, and application services. - Integrate security validation and evidence collection into engineering and software-delivery workflows. - Support vulnerability scanning, triage, remediation tracking, and risk-acceptance processes. - Support Zero Trust, RBAC/ABAC, encryption, secrets management, logging, and workload-security requirements. - Evaluate technical implementations against security requirements and identify risks/control deficiencies. - Collaborate with engineering teams to develop practical approaches for implementing and sustaining security controls. **Software & Supply-Chain Security** - Conduct security reviews of COTS, GOTS, FOSS, software artifacts, containers, and third-party dependencies. - Coordinate security evidence and documentation for software and infrastructure changes. - Support software supply-chain security, artifact integrity/provenance, and dependency-management practices. - Integrate security controls into development and delivery processes with DevSecOps and engineering. - Identify software-component security risks and recommend mitigation/remediation actions. **Continuous Monitoring & Compliance** - Support continuous security monitoring and assessment activities. - Track security findings, vulnerabilities, control deficiencies, and remediation activities. - Maintain accurate security documentation, evidence repositories, and compliance records. - Support audits, assessments, inspections, and other compliance activities. - Monitor changes to enterprise systems and evaluate impacts to existing security controls and authorization requirements. ### Location - Fully onsite in **Chantilly, VA** ### Qualifications **Required** - Active **TS/SCI clearance with CI Polygraph**. - ~**6–10 years** of experience in cybersecurity, ISSE, RMF, security compliance, or security engineering. - 6 years of experience with a BS/BA; **9 years** may be considered in lieu of a degree. - Experience supporting **RMF, security authorization, and continuous-monitoring**. - Experience implementing, assessing, or documenting technical security controls. - Working knowledge of cloud security, DevSecOps, IAM, network security, and vulnerability management. - Experience developing authoriz
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.