Security Control Assessor

Peraton

Linthicum (MD)

On-site

USD 135,000 - 216,000

Full time

6 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Peraton is seeking a Security Control Assessor in our Linthicum, MD office to support a DoD customer in cyber investigations, forensics, threat analysis, and mission support. You will conduct risk assessments, manage A&A activities, and ensure compliance with NIST/FISMA across cloud and on-premises environments.

The role requires active TS clearance with SCI eligibility, Security+ and IAM Level III certifications, and experience with eMASS/ACAS.

Qualifications

  • Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Software Engineering, or Data Science with 6–8+ years of relevant experience, or higher degrees with fewer years.
  • Active TS clearance with SCI eligibility.
  • Active CompTIA Security+ certification.
  • Active IAM level III certification (e.g., CISM).
  • Experience with enterprise cloud environments (JWICS, SIPRNET, NIPRNET, and commercial Internet).
  • Experience with eMASS, ACAS, and CCSP or CompTIA Cloud+.
  • Knowledge of risk management framework and security controls in cloud environments.
  • Familiarity with cyber threats, vulnerabilities, and security assessment tools.

Responsibilities

  • Conduct security control assessments and drive risk mitigation planning.
  • Provide A&A for ARCYBER cloud infrastructure.
  • Execute security control assessment plans and update System Security Plans.
  • Review vulnerability scans and remediation efforts.
  • Apply risk management practices using NIST, FISMA, HIPAA, and PII frameworks.
  • Monitor data privacy across data handling, protection, and residency.
  • Assist clients in identifying gaps and designing privacy solutions.
  • Scan and validate systems to obtain/maintain ATO under NIST/FISMA.

Skills

Risk management
Cloud security
Security controls
Cybersecurity principles
NIST framework

Education

Bachelor's degree in IT/CS/Cybersecurity

Tools

eMASS
ACAS
CCSP
CompTIA Cloud+

Job description

Responsibilities

Peraton is seeking a Security Control Assessor in our Linthicum, MD office in support of our Department of Defense (DoD) customer as part of a highly talented, highly motivated, and high-performing team. This position offers a unique opportunity to work at the forefront of cyber investigations, digital forensics, cyber threat analysis, and mission support in a dynamic and collaborative environment. The successful candidate will contribute to protecting national security interests by leveraging technical expertise, analytical skills, and innovative problem-solving to address complex cyber challenges. Individuals who are passionate about cybersecurity, committed to excellence, and eager to make a meaningful impact are encouraged to apply.

In this role you will accomplish the following:

  • Conduct assessments and facilitate risk mitigation planning.
  • Provide Assessment and Authorization (A&A) for the ARCYBER cloud infrastructure.
  • Execute a security control assessment plan and update the System Security Plan.
  • Review vulnerability scans and remediation.
  • Implement risk management programs by utilizing NIST, FISMA, HIPAA, and PII -- and document solutions.
  • Monitor the privacy landscape regarding all data (privacy, protection, classification, and residency).
  • Assist clients with identifying gaps within existing privacy programs and designing solutions to help address those challenges.
  • Scan, test, and validate systems/networks/applications to obtain/maintain an ATO under NIST/FISMA guidelines.
Qualifications

Required Qualifications:

  • Bachelor’s degree and 8+ years of experience, or Master’s and 6+ years of experience, or PhD and 3+ years of experience. A degree in one of the following fields of study is highly desired: Information Technology, Computer Science, Cybersecurity, Information Systems, Software Engineering, or Data Science. An additional 4 years of experience or specialized training may be considered in lieu of Bachelor's degree.
  • Active TS clearance with SCI eligibility.
  • Active CompTIA Security+ certification.
  • Active IAM level III certification (such as CISM).
  • Must have knowledge of enterprise solutions across multiple cloud operating environments (JWICS, SIPRNET, NIPRNET, and commercial Internet).
  • Must have eMASS, ACAS, and ISC2 Certified Cloud Computing Professional (CCSP) or CompTIA Cloud+ experience.
  • Must have knowledge in the following areas:
    • Knowledge of computer networking and/or cloud computing concepts and protocols, and network security methodologies.
    • Knowledge of cyber threats and vulnerabilities in a virtualized environment.
    • Knowledge of national and international laws, regulations, policies, and ethics as they relate to cybersecurity.
    • Knowledge of risk management framework processes (e.g., methods for assessing and mitigating risk).
    • Knowledge of specific operational impacts of cybersecurity lapses.
    • Knowledge of industry methods for evaluating, implementing, and disseminating Information Technology (IT) security assessment, monitoring, detection, and remediation tools and procedures using standards-based concepts and capabilities.
    • Knowledge of cyber defense and vulnerability assessment tools, including opensource tools, and their capabilities.
    • Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
    • Knowledge of cybersecurity principles used to manage risks related to the use, processing, storage, and transmission of information or data in a cloud environment.
    • Knowledge of IT and cloud computing security principles and methods (e.g., firewalls, demilitarized zones, encryption).
    • Knowledge of known vulnerabilities from alerts, advisories, errata, and bulletins.
    • Knowledge of network and/or cloud computing environment security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
    • Knowledge of penetration testing principles, tools, and techniques..
    • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, returnoriented attacks, malicious code).
    • Knowledge of the Security Assessment and Authorization process.
    • Skill in determining how a security and/or cloud computing security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
    • Skill in discerning the protection needs (i.e., security controls) of information systems and networks and those relating to cloud computing.
    • Knowledge of local specialized system requirements (e.g., critical infrastructure systems that may not use standard IT) for safety, performance, and reliability.
    • Knowledge of new and emerging IT and cybersecurity technologies and/or those technologies specific to cloud computing.
Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

Target Salary Range

$135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Control Assessor
Security Control Assessor

Peraton • Alexandria (VA)

On-site
USD 146,000 - 234,000
Medical benefits
401(k) retirement plan
Paid time off
Cyber Security Specialist, Associate
Cyber Security Specialist, Associate

Peraton • Fort Huachuca (AZ)

On-site
USD 66,000 - 106,000
Cyber R&D Analyst/Service Manager
Cyber R&D Analyst/Service Manager

Peraton • Linthicum (MD)

On-site
USD 112,000 - 179,000
Cloud Software Engineer Level 3 AI/ML TS/SCI w Poly
Cloud Software Engineer Level 3 AI/ML TS/SCI w Poly

Peraton • Laurel (MD)

On-site
USD 135,000 - 216,000
25 days PTO
Enhanced employee benefits
Task Lead (CIO Services)
Task Lead (CIO Services)

Peraton • Linthicum (MD)

On-site
USD 176,000 - 282,000
Information Assurance - SME
Information Assurance - SME

Peraton • Bethesda (MD)

On-site
USD 135,000 - 216,000
25 days PTO
Bonus plan
Heavily subsidized benefits
Senior Cyber Systems Engineer
Senior Cyber Systems Engineer

Peraton • Corridor North (MD)

On-site
USD 135,000 - 216,000
Operations Lead / Active Top Secret
Operations Lead / Active Top Secret

Peraton • Beltsville (MD)

On-site
USD 135,000 - 216,000
External Job Posting Title Operations Lead / Active Top Secret
External Job Posting Title Operations Lead / Active Top Secret

Peraton • Beltsville (MD)

On-site
USD 135,000 - 216,000
External Job Posting Title Cyber R&D Analyst/Service Manager
External Job Posting Title Cyber R&D Analyst/Service Manager

Peraton • Linthicum (MD)

On-site
USD 112,000 - 179,000