Security Control Assessor
Peraton · Linthicum, MD, US
About this role
**Security Control Assessor** **Overview** Peraton is seeking a **Security Control Assessor** in our **Linthicum, MD** office in support of a **Department of Defense (DoD)** customer. This role supports cyber investigations, digital forensics, cyber threat analysis, and mission support in a dynamic, collaborative environment. **Key Responsibilities** - Conduct assessments and facilitate **risk mitigation planning** - Provide **Assessment and Authorization (A&A)** for **ARCYBER cloud infrastructure** - Execute a **security control assessment plan** and update the **System Security Plan** - Review **vulnerability scans** and support **remediation** - Implement **risk management programs** using **NIST, FISMA, HIPAA, and PII**; document solutions - Monitor the **privacy landscape** (privacy, protection, classification, and residency) - Identify gaps in existing **privacy programs** and design solutions to address them - Scan, test, and validate systems/networks/applications to obtain/maintain an **ATO** under **NIST/FISMA** guidelines **Required Qualifications** - **Bachelor’s + 8+ years**, or **Master’s + 6+ years**, or **PhD + 3+ years** - Degree in one of the following is highly desired: **Information Technology, Computer Science, Cybersecurity, Information Systems, Software Engineering, or Data Science** - **Active TS clearance with SCI eligibility** - **Active CompTIA Security+** - **Active IAM level III certification** (e.g., **CISM**) - Knowledge of enterprise solutions across multiple cloud environments: **JWICS, SIPRNET, NIPRNET, and commercial Internet** - Experience with **eMASS**, **ACAS**, and **ISC2 CCSP** or **CompTIA Cloud+** **Additional Knowledge/Skills** - Computer networking and/or cloud computing concepts, protocols, and network security methodologies - Cyber threats and vulnerabilities in virtualized environments - National/international laws, regulations, policies, and ethics related to cybersecurity - Risk management framework processes (assessing and mitigating risk) - Operational impacts of cybersecurity lapses - IT security assessment/monitoring/detection/remediation tools and procedures using standards-based concepts - Cyber defense and vulnerability assessment tools (including open-source) and their capabilities - Cybersecurity principles and organizational requirements (CIA, authentication, non-repudiation) *Note: The provided description appears truncated at the end of the qualifications section.*
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.