Principal Information Security Consultant

Peraton

California (MO)

On-site

USD 180,000 - 240,000

Full time

13 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Peraton is seeking a Principal Information Security Consultant to serve as the senior technical authority for secure architecture and engineering across California health exchange environments. You will translate NIST SP 800-53 Rev.

5, ARC-AMPE, and IRS Publication 1075 requirements into practical designs and automated controls, and provide the senior technical review before client delivery. You will collaborate with California security leadership, cloud and infrastructure engineers, application

Qualifications

  • Minimum 12 years experience with BS/BA; 10 years with MS/MA.
  • Active CISSP certification required.
  • Deep experience interpreting NIST SP 800-53 Rev. 5 controls.
  • Hands-on security architecture across cloud and on-prem environments.

Responsibilities

  • Own secure architecture across cloud and on-prem environments.
  • Translate controls into concrete technical configurations and automated controls.
  • Lead security engineering for IAM, network, endpoint, cloud, and application security.
  • Oversee vulnerability management strategy and remediation validation.
  • Advise on CMS Authority to Connect readiness and security authorization activities.
  • Provide senior technical QA, mentorship, and cross-disciplinary leadership.

Skills

Cybersecurity leadership
Security architecture
NIST SP 800-53 Rev. 5
Cloud security (AWS/Azure/GCP)
Vulnerability management
Executive communication
Security governance

Education

BS/BA in CS/Engineering/Cybersecurity
MS/MA in CS/Engineering/Cybersecurity

Tools

Tenable
Qualys
CIS Benchmarks
DISA STIGs

Job description

Required:
  • Minimum of 12 years experience with BS/BA; Minimum of 10 years with MS/MA. Degree in computer science, engineering, or cybersecurity. An additional 4 years of experience may be considered in lieu of a degree.
  • Progressively responsible cybersecurity experience, with significant depth in enterprise security control frameworks and complex regulated environments.
  • Active CISSP certification.
  • Demonstrated experience interpreting and applying NIST SP 800-53 Rev. 5 security and privacy controls within a complex enterprise environment, and translating regulatory control requirements into engineering solutions.
  • Hands‑on security architecture and engineering experience across cloud (AWS, Azure, or GCP) and on‑premises environments, including identity and access management, network security, endpoint security, and application security.
  • Hands‑on experience with enterprise vulnerability management tooling (for example Tenable or Qualys) and with hardening standards such as CIS Benchmarks or DISA STIGs.
  • Demonstrated ability to communicate complex cybersecurity risk to both technical and executive audiences, and executive‑grade technical writing ability.
  • US Citizenship and the abillity to pass a California criminal background clearance (Gov. Code §1043 / 10 CCR §6456) before starting work or accessing any confidential information, PII, PHI, federal tax information, or financial information.
Desired:
  • CCSP, or a cloud security specialty certification: AWS Certified Security – Specialty, Microsoft Azure SC-100, or Google Professional Cloud Security Engineer.
  • CISM, CRISC, CGRC, or GSLC.
  • Experience with ARC-AMPE security and privacy requirements.
  • Experience with IRS Publication 1075 and FTI-bearing environments.
  • Experience with CMS security requirements and the Authority to Connect (ATC) process.
  • Experience with zero‑trust architecture, encryption and key management design, and security control automation.
  • Experience securing or assessing healthcare eligibility and enrollment, Medicaid, or health benefit exchange systems, and large California state government IT or cyber environments.
  • Experience supporting independent assessments and developing or reviewing Security Assessment Reports, CMS Security Assessment Workbooks (SAWs), and POA&Ms.

Position Is Contingent Upon Award

Peraton Labs is hiring a Principal Information Security Consultant to be the senior technical authority and trusted advisor for secure architecture and engineering across the Covered California and CalHEERS environments. You will translate NIST SP 800-53 Rev. 5, ARC-AMPE, and IRS Publication 1075 requirements into practical technical designs and operating controls, and you will provide the senior technical review that our security deliverables pass through before they reach the client.

You will work with Covered California's security leadership, cloud and infrastructure engineers, application teams, and project delivery teams, alongside a small senior Peraton security team. The goal is to raise the real, measured security posture of a cloud‑based health benefit exchange that processes PII, PHI, and federal tax information — not merely to document it.

What You Will Do In This Role:
  • Own secure architecture. Design and review secure architectures, technical designs, security patterns, and proposed solutions across cloud and on‑premises environments; identify risks and recommend proportionate controls.
  • Translate controls into engineering. Interpret and apply NIST SP 800-53 Rev. 5 security and privacy controls, ARC-AMPE requirements, and IRS Publication 1075 safeguards as concrete technical configurations, hardening standards, and automated controls.
  • Lead security engineering across domains. Provide technical leadership for identity and access management, network security, endpoint security, cloud security, and application security, including CSP‑native tooling and configuration review.
  • Direct vulnerability management technically. Own scanning strategy, risk‑based prioritization, hardening baselines (CIS Benchmarks and DISA STIGs), and validation that remediation actually closed the exposure.
  • Evaluate and close control gaps. Assess controls, identify gaps and weaknesses, develop risk‑based remediation strategies, and advise stakeholders on corrective action; support security authorization activities including CMS Authority to Connect readiness.
  • Provide senior technical QA and mentorship. Review security assessments, reports, policies, standards, and artifacts for technical accuracy and defensibility; mentor security professionals and provide technical leadership across multidisciplinary initiatives.
  • Advise on incident response and detection. Support investigation, evidence handling, escalation, reporting, and post‑incident analysis; support threat detection, log monitoring, third‑party risk assessment, data protection, and security control automation; participate in the on‑call incident response rotation.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Information Security Consultant
Principal Information Security Consultant

Peraton Labs • United States

On-site
USD 135,000 - 216,000
Principal Information Security Consultant
Principal Information Security Consultant

Peraton • United States

On-site
USD 135,000 - 216,000
Principal Information Security Consultant
Principal Information Security Consultant

Peraton • Reston (VA)

On-site
USD 135,000 - 216,000
Principal Information Security Consultant
Principal Information Security Consultant

Peraton • Herndon (VA)

On-site
USD 135,000 - 216,000
External Job Posting Title Principal Information Security Consultant
External Job Posting Title Principal Information Security Consultant

Peraton • Northern (KY)

Hybrid
USD 135,000 - 216,000
Senior Information Security Architect & Trusted Advisor
Senior Information Security Architect & Trusted Advisor

Peraton • Herndon (VA)

On-site
USD 135,000 - 216,000
Senior Cloud Security Architect & Trusted Advisor
Senior Cloud Security Architect & Trusted Advisor

Peraton • Northern (KY)

Hybrid
USD 135,000 - 216,000
Senior Information Security Architect — Cloud & Compliance Lead
Senior Information Security Architect — Cloud & Compliance Lead

Peraton • California (MO)

Hybrid
USD 180,000 - 240,000
Information System Security Manager (ISSM)
Information System Security Manager (ISSM)

Peraton Labs • United States

On-site
USD 135,000 - 216,000
Medical
Dental
Vision
+8
Senior InfoSec Architect & Trusted Advisor
Senior InfoSec Architect & Trusted Advisor

Peraton • United States

On-site
USD 135,000 - 216,000