Full-Time

Security Control Assessor

Confirmed live in the last 24 hours

Peraton

Peraton

10,001+ employees

Provides advanced technology solutions for government

Compensation Overview

$146k - $234k/yr

Expert

Alexandria, VA, USA

In Person

US Citizenship, US Top Secret Clearance Required

Category
Cybersecurity
IT & Security
Required Skills
Computer Networking
Requirements
  • Minimum of 12 years experience with BS/BA; Minimum of 10 years with MS/MA; Minimum of 7 years with Ph.D.
  • Must have current IAM level III certification (such as CISM)
  • Must have knowledge of enterprise solutions across multiple cloud operating environments (JWICS, SIPRNET, NIPRNET, and commercial Internet)
  • Must have eMASS, ACAS, and ISC2 Certified Cloud Computing Professional (CCSP) or CompTIA Cloud+ experience
  • Must have knowledge in the following areas (via skills assessment): Knowledge of computer networking and/or cloud computing concepts and protocols, and network security methodologies; Knowledge of cyber threats and vulnerabilities in a virtualized environment; Knowledge of cybersecurity principles; Knowledge of national and international laws, regulations, policies, and ethics as they relate to cybersecurity; Knowledge of risk management framework processes (e.g., methods for assessing and mitigating risk); Knowledge of specific operational impacts of cybersecurity lapses; Knowledge of industry methods for evaluating, implementing, and disseminating Information Technology (IT) security assessment, monitoring, detection, and remediation tools and procedures using standards-based concepts and capabilities; Knowledge of cyber defense and vulnerability assessment tools, including opensource tools, and their capabilities; Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation); Knowledge of cybersecurity principles used to manage risks related to the use, processing, storage, and transmission of information or data in a cloud environment; Knowledge of IT and cloud computing security principles and methods (e.g., firewalls, demilitarized zones, encryption); Knowledge of known vulnerabilities from alerts, advisories, errata, and bulletins; Knowledge of network and/or cloud computing environment security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth); Knowledge of organization's evaluation and validation requirements; Knowledge of penetration testing principles, tools, and techniques; Knowledge of relevant laws, policies, procedures, or governance related to critical infrastructure; Knowledge of Risk Management Framework (RMF) requirements; Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, returnoriented attacks, malicious code); Knowledge of the Security Assessment and Authorization process; Skill in determining how a security and/or cloud computing security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes; Skill in discerning the protection needs (i.e., security controls) of information systems and networks and those relating to cloud computing; Knowledge of IT supply chain security and risk management policies, requirements, and procedures; Knowledge of local specialized system requirements (e.g., critical infrastructure systems that may not use standard IT) for safety, performance, and reliability; Knowledge of new and emerging IT and cybersecurity technologies and/or those technologies specific to cloud computing; Knowledge of organization's enterprise and/or cloud computing information security architecture system; Knowledge of Personal Identifiable Information (PII) data security standards; Knowledge of Personal Health Information (PHI) data security standards.
  • DoD TS SCI clearance
  • U.S Citizenship Required
Responsibilities
  • Conduct assessments and facilitate risk mitigation planning
  • Provide Assessment and Authorization (A&A) for the ARCYBER cloud infrastructure
  • Execute a security control assessment plan and update the System Security Plan
  • Review vulnerability scans and remediation
  • Implement risk management programs by utilizing NIST, FISMA, HIPAA, and PII -- and document solutions
  • Monitor the privacy landscape regarding all data (privacy, protection, classification, and residency)
  • Assist clients with identifying gaps within existing privacy programs and designing solutions to help address those challenges
  • Scan, test, and validate systems/networks/applications to obtain/maintain an ATO under NIST/FISMA guidelines.
Desired Qualifications
  • DoD TS SCI w/poly

Peraton provides advanced technology solutions and services primarily for government clients in the defense, intelligence, and critical infrastructure sectors. The company focuses on creating cyber-hardened systems, systems engineering, and mission-critical support to address complex challenges in national security. Peraton's business model relies on long-term contracts with government agencies, which often involve high-value projects requiring specialized expertise. A key aspect of Peraton's approach is its partnerships with other firms, which enhance its capabilities through clear communication and joint marketing efforts. Additionally, Peraton actively recruits veterans and military spouses, valuing the unique skills they bring to the workforce. The company's goal is to contribute to national security and technological advancement while supporting the military community.

Company Size

10,001+

Company Stage

Grant

Total Funding

$60M

Headquarters

Herndon, Virginia

Founded

2017

Simplify Jobs

Simplify's Take

What believers are saying

  • Tony Encinias' appointment may drive innovation in state and local government services.
  • Recognition as a VETS Indexes Employer enhances workforce diversity and expertise.
  • Finalist for Garner Marketing Awards strengthens brand presence and client engagement.

What critics are saying

  • Layoffs in Maryland suggest potential instability in securing future contracts.
  • New leadership may disrupt current operations or client relationships.
  • AI tool integration challenges may affect contract performance with government systems.

What makes Peraton unique

  • Peraton specializes in defense, intelligence, and critical infrastructure for government clients.
  • The company emphasizes veteran recruitment, enhancing workforce diversity and expertise.
  • Peraton's AI-enabled Rapid Fraud Intelligence tool leads in government fraud detection.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Paid Vacation

Performance Bonus

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
GovBrew
Jul 7th, 2025
Peraton Appoints Paul Aronhime as Citizen Security & Public Services Sector CGO

Peraton has announced Paul Aronhime as Citizen Security & Public Services Sector CGO.

Peraton
Jun 12th, 2025
Peraton Takes a Swing for Charity at the 34th Annual DSF Golf Outing

Peraton takes a swing for Charity at the 34th Annual DSF Golf Outing.

Peraton
May 7th, 2025
Your Future, Our Mission: Find High-Impact Careers at Peraton's Virtual Hiring Event on May 21

Your future, its mission: find high-impact careers at Peraton's Virtual Hiring Event on May 21.

ExecutiveBiz
May 6th, 2025
Peraton Launches AI-Enabled Anti-Fraud Tool

Peraton launches ai-enabled anti-fraud tool.

Peraton
May 5th, 2025
Peraton Introduces Rapid Fraud Intelligence to Revolutionize Government Fraud Detection

Peraton today announced the launch of Rapid Fraud Intelligence (Rapid FI), an advanced fraud detection and prevention solution that combines artificial intelligence with decades of federal fraud-fighting expertise.