Software Development, Lead Associate at Peraton

Peraton

Vicenza

In loco

EUR 57.000 - 92.000

Tempo pieno

5 giorni fa
Candidati tra i primi

Ricevi più risposte dai datori di lavoro

Invia un CV specifico per questa offerta in pochi minuti.

Vantaggi offerti da questo lavoro

Benefits package
On-site in Vicenza

Descrizione del lavoro

Peraton in Vicenza, IT, seeks a Mid-level DevSecOps Engineer to support the security, reliability, and compliance of mission-critical CMS systems. You'll help integrate security throughout the development lifecycle and ensure adherence to federal cybersecurity standards in cloud and on-prem environments.

The ideal candidate will implement security within CI/CD pipelines, manage SSPs/SARs/POA&Ms, and coordinate with DevOps and security teams.

Competenze

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Engineering or related field.
  • 5–7 years of cybersecurity, DevSecOps, or system engineering experience on federal programs.
  • Experience as ISSO or security engineer for FISMA or FedRAMP systems.
  • Strong knowledge of NIST 800‑53, RMF, CMS ARS 5.1, and continuous monitoring.
  • Experience integrating security into CI/CD pipelines and automated deployments.

Mansioni

  • Serve as ISSO for the program, ensuring compliance with FISMA Moderate, FedRAMP Moderate, and CMS ARS 5.1.
  • Prepare and maintain C&A and SA&A docs, SSPs, SARs, POA&Ms, and continuous monitoring updates.
  • Collaborate with DevOps, engineering, and operations to embed security in CI/CD and IaC.

Conoscenze

DevSecOps
ISSO experience
RMF/NIST 800-53
Security in CI/CD
Cloud security

Formazione

Bachelor's degree in Computer Science/Engineering/Cybersecurity

Strumenti

GitLab/GitHub CI/CD
Jenkins
Terraform
Ansible
Tenable/Splunk

Descrizione del lavoro

Apply for Software Development, Lead Associate at Peraton in Vicenza, VEN, IT.

This Full time on site position offers great opportunities for career growth.

About Peraton

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

The Role

Peraton is seeking a Mid‑level DevSecOps Engineer to join our team of qualified, diverse professionals. In this role, you will support the security, reliability, and compliance of mission‑critical systems within the DME Program. The ideal candidate will play a key part in integrating security throughout the development lifecycle, maintaining adherence to federal cybersecurity standards, and ensuring the operational readiness of modernized systems at the Centers for Medicare & Medicaid Services (CMS). This position supports a highly visible environment where strong technical execution, security rigor, and cross‑team collaboration are essential.

Responsibilities

Serve as the Information System Security Officer (ISSO) for the ClaimsCore Program, ensuring full compliance with FISMA Moderate, FedRAMP Moderate, and CMS ARS 5.1 security requirements. Prepare, maintain, and update all Certification and Accreditation (C&A) and Security Assessment and Authorization (SA&A) documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Contingency Plans, and Plan of Action and Milestones (POA&Ms). Conduct and document ongoing risk assessments, vulnerability assessments, and security control evaluations across the program’s cloud and on‑premises environments. Manage and coordinate the Authority to Operate (ATO) lifecycle, including initial authorization, continuous monitoring, control implementation reviews, and audit preparation. Ensure zero open Critical or High vulnerabilities at system go‑live and maintain compliance with vulnerability remediation SLAs. Respond to and manage security incident notifications within required timelines (1 hour for initial reporting). Coordinate with internal security teams and external stakeholders to support incident response processes. Support internal and external audits, including CSRAP, CFO, OMB A‑123, and annual security assessments. Collaborate with DevOps, engineering, and operations teams to integrate security best practices into CI/CD pipelines, infrastructure‑as‑code, and deployment processes. Monitor and enhance security posture using tools such as vulnerability scanners, SIEM platforms, configuration management tools, and compliance automation platforms. Contribute to continuous improvement of security procedures, engineering practices, and system hardening baselines. Assist in the implementation and maintenance of cloud security configurations aligned with agency and program requirements. Provide security guidance during architecture reviews, design sessions, sprint planning, and change control processes. Ensure security documentation, diagrams, inventories, and boundary definitions are accurate and up to date.

Qualifications

Qualifications (Required): Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Engineering, or related field; additional experience may be substituted in lieu of degree. 5 to 7 years of experience in cybersecurity, DevSecOps, or system engineering roles supporting federal programs. Experience acting as an ISSO or security engineer for a FISMA Moderate or FedRAMP Moderate system. Hands‑on experience preparing security authorization documentation such as SSPs, SARs, POA&Ms, and Continuous Monitoring updates. Strong understanding of NIST 800‑53 security controls, Risk Management Framework (RMF), CMS ARS 5.1, and continuous monitoring requirements. Practical experience supporting or integrating security processes in DevSecOps pipelines, CI/CD workflows, or automated deployment environments. Experience with vulnerability management tools and processes, including scanning, analysis, and remediation tracking. Ability to support audits and communicate effectively with assessment teams, program stakeholders, and government security representatives. U.S. citizenship and the ability to obtain and maintain a public trust or equivalent clearance.

Qualifications (Preferred): Experience supporting CMS programs or other HHS components. Familiarity with FedRAMP documentation, cloud boundary definitions, and cloud‑native security practices. Experience with AWS or Azure security services, cloud configuration baselines, and cloud compliance frameworks. Working knowledge of tools commonly used within Peraton and similar enterprises, such as GitLab/GitHub CI/CD, Jenkins, Terraform, Ansible, Tenable, Splunk, or similar platforms. Security certifications such as Security+, CISSP, CISM, CCSP, or AWS/Azure security certifications. Experience integrating legacy systems into modern cloud or hybrid architectures with secure migration practices. Knowledge of container security (Docker, Kubernetes) and infrastructure‑as‑code security scanning.

Details

Target Salary Range: $66,000 - $106,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Benefits Statement: Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays. A full listing of available benefits can be viewed at https://www.careers.peraton.com/benefits.

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Ottieni la revisione del curriculum gratis e riservata.
o trascina qui il file.
Similar jobs

Offerte di lavoro simili che vale la pena confrontare

Software Development, Lead Associate
Software Development, Lead Associate

Peraton • Vicenza

In loco
EUR 95.000 - 138.000
Federal DevSecOps Lead & ISSO (CMS)
Federal DevSecOps Lead & ISSO (CMS)

Peraton • Vicenza

In loco
EUR 95.000 - 138.000
DevSecOps Engineer – Federal Security & Compliance
DevSecOps Engineer – Federal Security & Compliance

Peraton • Vicenza

In loco
EUR 57.000 - 92.000
Benefits package
On-site in Vicenza
Cybersecurity Engineer II
Cybersecurity Engineer II

STERIS • Pomezia

In loco
EUR 40.000 - 70.000
Software Development Engineer - AWS Config - AWS Config
Software Development Engineer - AWS Config - AWS Config

Amazon • Asti

In loco
EUR 125.000 - 169.000
Penetration Tester
Penetration Tester

OMEGA, Inc. • Frascati

In loco
EUR 35.000 - 43.000
Medical benefits
Dental benefits
Vision benefits
+5
Penetration Tester
Penetration Tester

OMEGA, Inc. • Italia

In loco
EUR 40.000 - 50.000
Relocation assistance
Medical insurance
Dental insurance
+3
Staff Windows Low Level C++ Engineer - Endpoint security
Staff Windows Low Level C++ Engineer - Endpoint security

SentinelOne • Italia

Remoto
EUR 90.000 - 120.000
Flexible working hours
Employee stock plan
Yearly bonus
+3
System Administrator
System Administrator

ActioNet, Inc. • Milano

In loco
EUR 35.000 - 55.000
Employee commitment and investment
Diverse workplace culture
Opportunity for career advancement
TRICARE Beneficiary Services Representative - Sigonella, Italy
TRICARE Beneficiary Services Representative - Sigonella, Italy

Leidos LLC • Catania

In loco
EUR 28.000 - 50.000
Health and Wellness programs
Income Protection
Paid Leave
+1