Cybersecurity / Compliance Engineer

Peraton

Chantilly (VA)

On-site

USD 112,000 - 179,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Peraton is seeking Cybersecurity / Compliance Engineers in Chantilly, VA to implement and sustain security controls, authorization evidence, and continuous-monitoring across enterprise environments. You will work with platform, cloud, DevSecOps, IAM, observability, and application teams to weave security into engineering and operations processes.

The role blends RMF/compliance with practical security engineering, ongoing authorization, and evidence-management responsibilities in a fully onsite

Qualifications

  • Active TS/SCI clearance with CI Polygraph.
  • Approximately 6–10 years of cybersecurity/ISSE/RMF/security engineering experience.
  • BS/BA required; 9 years may substitute for degree.
  • Experience supporting RMF, security authorization, and continuous-monitoring activities.
  • Experience implementing, assessing, or documenting technical security controls.
  • Working knowledge of cloud security, DevSecOps, IAM, network security, and vulnerability mgmt.
  • Strong technical writing, documentation, and communication skills.

Responsibilities

  • Support RMF, security assessment, authorization, and continuous-monitoring activities.
  • Maintain security evidence, control implementation information, POA&M inputs, and authorization docs.
  • Assess security impacts of platform, infra, application, and 3rd-party changes.
  • Coordinate with security, engineering, and ops to address control gaps.
  • Define and review security requirements for cloud, Kubernetes, CI/CD, identity, network, and apps.
  • Integrate security validation into engineering and delivery workflows.
  • Support vulnerability scanning, triage, remediation tracking, and risk acceptance.
  • Support zero trust, RBAC/ABAC, encryption, secrets management, logging, and workload security.

Skills

TS/SCI clearance with CI Polygraph
6–10 years cybersecurity experience
RMF / security authorization
Cloud security / DevSecOps / IAM
Technical writing / documentation
Security controls implementation

Education

BS/BA in related field

Tools

Kubernetes security
AWS security services

Job description

Responsibilities

We are seeking Cybersecurity / Compliance Engineers to implement and sustain security controls, authorization evidence, continuous monitoring, vulnerability management, software-security requirements, and common-control responsibilities across enterprise environments.

These engineers will work closely with platform, cloud, DevSecOps, IAM, observability, and application teams to ensure security requirements are incorporated into engineering and operational processes. The role combines technical security engineering with Risk Management Framework (RMF), authorization, compliance, and continuous-monitoring activities.

Responsibilities
Risk Management & Authorization
  • Support RMF, security assessment, authorization, and continuous-monitoring activities for enterprise services and environments.

  • Maintain security evidence, control implementation information, Plan of Action and Milestones (POA&M) inputs, and authorization documentation.

  • Assess and document security impacts associated with platform, infrastructure, application, and commercial or government-off-the-shelf software changes.

  • Support common-control and inherited-control documentation and implementation activities where applicable.

  • Coordinate with security, engineering, and operational stakeholders to address control gaps and authorization requirements.

Technical Security Engineering
  • Define and review security requirements for cloud, Kubernetes, CI/CD, identity, network, and application services.

  • Integrate security validation and evidence collection into engineering and software-delivery workflows.

  • Support vulnerability scanning, vulnerability triage, remediation tracking, and risk-acceptance processes.

  • Support implementation of Zero Trust, RBAC/ABAC, encryption, secrets management, logging, and workload-security requirements.

  • Evaluate technical implementations against established security requirements and identify potential risks or control deficiencies.

  • Collaborate with engineering teams to develop practical approaches for implementing and sustaining security controls.

Software & Supply-Chain Security
  • Support security reviews of COTS, GOTS, FOSS, software artifacts, containers, and third-party dependencies.

  • Coordinate security evidence and documentation requirements associated with software and infrastructure changes.

  • Support software supply-chain security, artifact integrity, provenance, and dependency-management practices.

  • Partner with DevSecOps and engineering teams to integrate security controls into development and delivery processes.

  • Identify security risks associated with software components and recommend appropriate mitigation or remediation actions.

Continuous Monitoring & Compliance
  • Support continuous security monitoring and assessment activities.

  • Track security findings, vulnerabilities, control deficiencies, and remediation activities.

  • Maintain accurate security documentation, evidence repositories, and compliance records.

  • Support audits, assessments, inspections, and other security compliance activities.

  • Monitor changes to enterprise systems and evaluate potential impacts to existing security controls and authorization requirements.

Location: This position is fully onsite in Chantilly, VA

Qualifications
Required Qualifications
  • Active TS/SCI clearance with CI Polygraph.

  • Approximately 6-10 years of experience in cybersecurity, Information Systems Security Engineering (ISSE), RMF, security compliance, or security engineering.

  • 6 years of experience with a BS/BA, 9 years of experience may be considered in lieu of a degree.
  • Experience supporting RMF, security authorization, and continuous-monitoring activities.

  • Experience implementing, assessing, or documenting technical security controls.

  • Working knowledge of cloud security, DevSecOps, identity and access management, network security, and vulnerability management concepts.

  • Experience developing authorization packages, security evidence, assessment documentation, or continuous-monitoring artifacts.

  • Strong technical writing, documentation, and communication skills.

Desired Qualifications

Experience with one or more of the following:

  • Continuous authorization or cATO practices.

  • Cloud security services, including AWS security services.

  • Kubernetes security.

  • Software supply-chain security.

  • Security automation and automated evidence collection.

  • Security compliance within classified or highly regulated environments.

  • ServiceNow or comparable security/RMF workflow platforms.

  • Experience supporting large-scale enterprise security authorization programs.

Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Target Salary Range

$112,000 - $179,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

External Job Posting Title Cybersecurity / Compliance Engineer
External Job Posting Title Cybersecurity / Compliance Engineer

Peraton • Chantilly (VA), Northern (KY)

Hybrid
USD 112,000 - 179,000
External Job Posting Title Cyber Security Engineer
External Job Posting Title Cyber Security Engineer

Peraton • Northern (KY)

On-site
USD 112,000 - 179,000
Cyber Security Engineer
Cyber Security Engineer

Peraton • Herndon (VA)

On-site
USD 112,000 - 179,000
External Job Posting Title Chief Engineer/Architect
External Job Posting Title Chief Engineer/Architect

Peraton • Chantilly (VA), Northern (KY)

On-site
USD 146,000 - 234,000
Cybersecurity Architect
Cybersecurity Architect

Peraton • Linthicum (MD)

On-site
USD 135,000 - 216,000
Deputy Operations Lead / Active Top Secret
Deputy Operations Lead / Active Top Secret

Peraton • Beltsville (MD)

On-site
USD 86,000 - 138,000
Operations Lead / Active Top Secret
Operations Lead / Active Top Secret

Peraton • Beltsville (MD)

On-site
USD 135,000 - 216,000
External Job Posting Title Operations Lead / Active Top Secret
External Job Posting Title Operations Lead / Active Top Secret

Peraton • Beltsville (MD)

On-site
USD 135,000 - 216,000
Systems Security Engineer SME
Systems Security Engineer SME

Peraton • Maryland

On-site
USD 190,000 - 304,000
Cloud Engineer - Governance, Risk, and Compliance (GRC)
Cloud Engineer - Governance, Risk, and Compliance (GRC)

Peraton • Reston (VA)

Remote
USD 112,000 - 179,000