Security Control Assessor

Peraton

Fort Belvoir (VA)

On-site

USD 135,000 - 216,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Peraton seeks a Cloud Security Control Assessor to support Army Cyber Command (ARCYBER). Location: Alexandria, VA/Metro Park near Fort Belvoir, VA. The role involves conducting assessments, providing A&A for the ARCYBER cloud infrastructure, and updating the System Security Plan to strengthen security postures.

You will implement RMF controls, review vulnerability scans, and monitor privacy, data residency, and PII considerations. A TS clearance and U.S.

Qualifications

  • Must have IAM Level III certification (e.g., CISM).
  • Extensive cloud security experience across JWICS, SIPRNET, NIPRNET, and commercial Internet.
  • Hands-on eMASS, ACAS, CCSP or Cloud+ experience required.
  • Strong knowledge of RMF, risk management, and cyber threat/vulnerability handling.
  • Deep understanding of confidentiality, integrity, availability, and data protection.

Responsibilities

  • Conduct assessments and facilitate risk mitigation planning.
  • Provide Assessment and Authorization for ARCYBER cloud infrastructure.
  • Execute a security control assessment plan and update the System Security Plan.
  • Review vulnerability scans and remediation activities.
  • Implement risk management programs per RMF, NIST, and IC guidelines.
  • Monitor privacy landscape regarding data privacy, protection, classification, and residency.
  • Scan, test, and validate systems to obtain/maintain an ATO under IC/NIST.

Skills

IAM Level III
CISM
Cloud security
NIST RMF
A&A knowledge
Risk assessment
Vulnerability management
Penetration testing concepts
Privacy and PII
Security controls
IC/NIST guidelines
Threat awareness

Education

BS/BA in a related field
MS/MA in a related field
Ph.D. considered
HS+16 or Associates+14

Tools

eMASS
ACAS
CCSP
CompTIA Cloud+

Job description

Responsibilities

Peraton seeks a Cloud Security Control Assessor to support Army Cyber Command (ARCYBER). Location: Alexandria, VA/Metro Park near Fort Belvoir, VA.

Tasks include:

  • Conduct assessments and facilitate risk mitigation planning
  • Provide Assessment and Authorization (A&A) for the ARCYBER cloud infrastructure
  • Execute a security control assessment plan and update the System Security Plan
  • Review vulnerability scans and remediation
  • Implement risk management programs by utilizing IC, NIST, FISMA, and PII -- and document solutions
  • Monitor the privacy landscape regarding all data (privacy, protection, classification, and residency)
  • Scan, test, and validate systems/networks/applications to obtain/maintain an ATO under IC/NIST guidelines
Qualifications

Required:

  • Minimum experience of 12 years with BS/BA; Minimum of 10 years with MS/MA; Minimum of 7 years with Ph.D. Will consider HS+16 or Associates +14.
  • Must have current IAM level III certification (such as CISM)
  • Must have knowledge of enterprise solutions across multiple cloud operating environments (JWICS, SIPRNET, NIPRNET, and commercial Internet)
  • Must have eMASS, ACAS, and ISC2 Certified Cloud Computing Professional (CCSP) or CompTIA Cloud+ experience
  • Must have knowledge in the following areas:
    • Knowledge of computer networking and/or cloud computing concepts and protocols, and network security methodologies
    • Knowledge of cyber threats and vulnerabilities in a virtualized environment.
    • Knowledge of cybersecurity principles
    • Knowledge of national and international laws, regulations, policies, and ethics as they relate to cybersecurity
    • Knowledge of risk management framework processes (e.g., methods for assessing and mitigating risk)
    • Knowledge of specific operational impacts of cybersecurity lapses
    • Knowledge of industry methods for evaluating, implementing, and disseminating Information Technology (IT) security assessment, monitoring, detection, and remediation tools and procedures using standards-based concepts and capabilities
    • Knowledge of cyber defense and vulnerability assessment tools, including opensource tools, and their capabilities
    • Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
    • Knowledge of cybersecurity principles used to manage risks related to the use, processing, storage, and transmission of information or data in a cloud environment
    • Knowledge of IT and cloud computing security principles and methods (e.g., firewalls, demilitarized zones, encryption)
    • Knowledge of known vulnerabilities from alerts, advisories, errata, and bulletins
    • Knowledge of network and/or cloud computing environment security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth)
    • Knowledge of organization's evaluation and validation requirements
    • Knowledge of penetration testing principles, tools, and techniques
    • Knowledge of relevant laws, policies, procedures, or governance related to critical infrastructure.
    • Knowledge of Risk Management Framework (RMF) requirements
    • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return oriented attacks, malicious code)
    • Knowledge of the Security Assessment and Authorization process
    • Skill in determining how a security and/or cloud computing security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes
    • Skill in discerning the protection needs (i.e., security controls) of information systems and networks and those relating to cloud computing
    • Knowledge of IT supply chain security and risk management policies, requirements, and procedures
    • Knowledge of local specialized system requirements (e.g., critical infrastructure systems that may not use standard IT) for safety, performance, and reliability
    • Knowledge of new and emerging IT and cybersecurity technologies and/or those technologies specific to cloud computing
    • Knowledge of organization's enterprise and/or cloud computing information security architecture system
    • Knowledge of Personal Identifiable Information (PII) data security standards
  • Active TS clearance with ability to obtain/maintain SCI
  • U.S. Citizenship Required
Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.

Target Salary Range

$135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

External Job Posting Title Security Control Assessor
External Job Posting Title Security Control Assessor

Peraton • Fort Belvoir (VA), Northern (KY)

Hybrid
USD 135,000 - 216,000
Cyber Security Specialist, Associate
Cyber Security Specialist, Associate

Peraton • Fort Huachuca (AZ)

On-site
USD 66,000 - 106,000
Cloud Administrator, TS/SCI w/Poly
Cloud Administrator, TS/SCI w/Poly

Peraton • Annapolis (MD)

On-site
USD 176,000 - 282,000
25 days PTO
Discretionary bonus plan
Subsidized employee benefits
Cloud Software Engineer Level 3 AI/ML TS/SCI w Poly
Cloud Software Engineer Level 3 AI/ML TS/SCI w Poly

Peraton • Laurel (MD)

On-site
USD 135,000 - 216,000
25 days PTO
Enhanced employee benefits
Cloud Software Engineer Level 2 - AI/ML TS/SCI w/Poly
Cloud Software Engineer Level 2 - AI/ML TS/SCI w/Poly

Peraton • Laurel (MD)

On-site
USD 146,000 - 234,000
25 days PTO per year
Bonus plan
Professional development opportunities
Cybersecurity Architect
Cybersecurity Architect

Peraton • Linthicum (MD)

On-site
USD 135,000 - 216,000
External Job Posting Title Cloud Software Engineer Level 2 - AI/ML TS/SCI w/Poly
External Job Posting Title Cloud Software Engineer Level 2 - AI/ML TS/SCI w/Poly

Peraton • Maryland

Hybrid
USD 146,000 - 234,000
25 PTO days
Bonus plan
Professional development opportunities
Cyber Risk / Threat Analyst
Cyber Risk / Threat Analyst

Peraton • Fort Meade (MD)

On-site
USD 135,000 - 216,000
External Job Posting Title Cloud Software Engineer Level 2 AI/ML TS/SCI w/Poly
External Job Posting Title Cloud Software Engineer Level 2 AI/ML TS/SCI w/Poly

Peraton • Maryland

On-site
USD 146,000 - 234,000
Subsidized benefits
25 PTO days
Bonus eligibility
Operations Lead / Active Top Secret
Operations Lead / Active Top Secret

Peraton • Beltsville (MD)

On-site
USD 135,000 - 216,000