Information System Security Manager (ISSM)

Peraton Labs

United States

On-site

USD 135,000 - 216,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical
Dental
Vision
Life Insurance
Health Savings Account
Disability Insurance
Employee Assistance Program
Parental Leave
401(k)
Paid Time Off
Company Holidays

Job summary

Peraton Labs is hiring an Information System Security Manager (ISSM) to lead a senior security team and act as the primary client security liaison for Covered California. You will own the security program, drive compliance with NIST SP 800-53 Rev.

5, and manage risk, incidents, and third-party security efforts across cloud and on-prem environments. You will coordinate governance, risk, and compliance activities, mentor senior staff, and ensure timely, high-quality security services for the

Qualifications

  • Bachelor’s degree in cybersecurity, CS, IS, IT, or engineering (or equivalent).
  • 12+ years of progressively responsible cybersecurity experience.
  • Active CISSP or CISM certification.
  • Experience managing security activities against NIST SP 800-53 Rev. 5.
  • Experience owning a risk register and POA&Ms with an enterprise GRC platform.
  • Ability to brief cybersecurity risk credibly to technical and executive audiences.
  • US Citizenship and ability to pass California background clearance.

Responsibilities

  • Lead the security team and coordinate day-to-day activities across seven service areas.
  • Serve as the primary client security liaison, delivering status and risk reporting to security leadership.
  • Own the compliance and GRC engine, driving policies, standards, and plans for NIST SP 800-53 Rev. 5 controls.
  • Drive risk down to closure via risk assessments, control reviews, and POA&Ms.
  • Serve as backup incident manager and coordinate investigations and reporting.
  • Coordinate security reviews across cloud and on-prem environments, including vendor due diligence.
  • Oversee annual independent assessment and penetration testing logistics.

Skills

Leadership
Mentoring
Communication

Education

Bachelor's degree in cybersecurity / CS / IS / IT / engineering
Master's degree in cybersecurity or related field

Tools

GRC platform

Job description

About Peraton

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit peraton.com to learn how we're keeping people around the world safe and secure.

About Peraton

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit peraton.com to learn how we're keeping people around the world safe and secure.

About The Role
  • Position Is Contingent Upon Award**

Peraton Labs is hiring an Information System Security Manager (ISSM) to be the single point of contact to Covered California and the accountable owner of oversight, timely execution, and quality for every security service Peraton delivers to the California health benefit exchange and the CalHEERS eligibility and enrollment system. You will lead a small, senior, multi-disciplinary security team spanning governance and compliance, security architecture and engineering, incident response, third-party risk, technical security, monitoring, and data protection.

What You Will Do In This Role:
  • Lead the security team. Manage and coordinate the day-to-day activities of assigned information security personnel; provide leadership, mentoring, and direction, and own deliverable accuracy, consistency, and schedule adherence across all seven contracted service areas.
  • Serve as the primary client security liaison. Act as the single operational point of contact among contractor personnel, Covered California security leadership, technical teams, project teams, and business stakeholders, and deliver regular status, risk, and escalation reporting to security leadership.
  • Own the compliance and GRC engine. Manage security activities tied to NIST SP 800-53 Rev. 5 controls; coordinate development and review of security policies, procedures, standards, and plans; direct GRC activities and platforms; and maintain the risk register.
  • Drive risk down to closure. Oversee risk assessments, control reviews, gap analyses, and remediation; track weaknesses, findings, and Plans of Action and Milestones (POA&Ms) through verified closure.
  • Serve as backup incident manager. Support the incident response program in coordination with the client Information Security Officer, and coordinate investigations, evidence handling, communications, escalation, reporting, and post-incident review; participate in the on-call incident response rotation.
  • Coordinate technical and third-party security work. Guide security architecture and engineering reviews across cloud and on-premises environments and technical security work spanning network, endpoint, vulnerability management, identity and access management, cloud, and application security; manage vendor security due diligence, assessments, contract and control reviews, and monitoring.
  • Coordinate assessment and penetration testing logistics while preserving assessor independence. Provide evidence, scheduling, and remediation ownership for the annual independent assessment and penetration test cycle without directing or influencing the independent assessors' scope, judgments, or findings.
Qualifications
Required:
  • Bachelor's degree in cybersecurity, computer science, information systems, information technology, or engineering. In lieu of a degree, an equivalent combination of education, professional certification, and additional relevant experience will be considered.
  • 12+ years of progressively responsible cybersecurity experience, including managing security programs, teams, or major security workstreams. (Note: eight years is the absolute floor for equivalency consideration; the posted target is 12+.)
  • Active CISSP or CISM certification.
  • Demonstrated experience managing security activities against the NIST SP 800-53 Rev. 5 control set in a complex enterprise environment.
  • Demonstrated experience owning a risk register and managing POA&Ms, findings, and corrective action plans through closure, using an enterprise GRC platform or comparable control-tracking system.
  • Demonstrated ability to lead and mentor senior technical personnel while working collaboratively with client stakeholders, and to brief cybersecurity risk credibly to both technical and executive audiences in writing and in person.
  • US Citizenship and the abillity to pass a California criminal background clearance (Gov. Code 1043 / 10 CCR 6456) before starting work or accessing any confidential information, PII, PHI, federal tax information, or financial information.
Desired:
  • Master's degree in cybersecurity, computer science, information systems, or a related discipline.
  • PMP certification. CGRC, CRISC, or CCSP are also valued.
  • Hands-on experience with ARC-AMPE (ACA, Medicaid and Partner Entities) security and privacy requirements.
  • Experience with IRS Publication 1075 compliance and federal tax information (FTI) control management.
  • Experience with CMS cybersecurity requirements and the CMS Authority to Connect (ATC) process or comparable federal authorization processes.
  • Experience supporting healthcare eligibility and enrollment, Medicaid, or health insurance exchange systems of CalHEERS scale.
  • Experience supporting annual security and privacy assessments, including CMS Security Assessment Workbooks (SAWs), security assessment reports, POA&Ms, and control evidence packages.
  • Experience in California state government or comparable public-sector cybersecurity environments.
Details

Target Salary Range: $135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

  • medical
  • dental
  • vision
  • life
  • health savings account
  • short/long term disability
  • EAP
  • parental leave
  • 401(k)
  • paid time off (PTO) for vacation
  • company paid holidays

EEO:Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

Peraton • Herndon (VA)

On-site
USD 135,000 - 216,000
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

Peraton • Reston (VA)

On-site
USD 135,000 - 216,000
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

Peraton • United States

On-site
USD 135,000 - 216,000
External Job Posting Title Information System Security Manager (ISSM)
External Job Posting Title Information System Security Manager (ISSM)

Peraton • Northern (KY)

Hybrid
USD 135,000 - 216,000
Principal Information Security Consultant
Principal Information Security Consultant

Peraton Labs • United States

On-site
USD 135,000 - 216,000
Principal Information Security Consultant
Principal Information Security Consultant

Peraton • United States

On-site
USD 135,000 - 216,000
Principal Information Security Consultant
Principal Information Security Consultant

Peraton • Herndon (VA)

On-site
USD 135,000 - 216,000
Principal Information Security Consultant
Principal Information Security Consultant

Peraton • Reston (VA)

On-site
USD 135,000 - 216,000
External Job Posting Title Principal Information Security Consultant
External Job Posting Title Principal Information Security Consultant

Peraton • Northern (KY)

Hybrid
USD 135,000 - 216,000
Senior GRC / Third-Party Risk / Data Protection Analyst
Senior GRC / Third-Party Risk / Data Protection Analyst

Peraton Labs • United States

On-site
USD 104,000 - 166,000
Medical insurance
Dental insurance
Vision insurance
+8