远程工作雷达

信息安全工程师

Information Assurance and Security Engineer

开发工程限定地区(需当地身份)
公司Peraton
薪资$86,000 - $138,000/年
工作地点United States
地域资格限定地区(需当地身份)
时区要求日间重叠约 9 小时,基本正常作息
用工类型Full Time
发布时间今天
数据来源Himalayas
前往 Himalayas 查看并投递 →
注意地域限制:该职位明确限定在 United States 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

职责
Peraton正在寻找一位经验丰富的信息安全与安全工程师,担任基于Azure的云托管系统的信息系统安全官(ISSO)。理想的候选人具备深厚的安全专业知识、强大的利益相关者沟通能力,并有在DHS或其他联邦环境中支持敏捷软件开发团队交付关键任务解决方案的实际经验。

此职位为远程办公。

日常职责:

  • 为内部和外部客户提供网络和信息安全系统的专业技术和支持。
  • 在企业级和项目级业务流程中设计、开发和实施安全需求。
  • 根据客户输入和行业标准指南(如NIST RMF、DHS 4300A)准备文档和安全工件。主导项目的认证和授权活动。
  • 制定和维护安全测试和评估计划以及应急计划。
  • 进行风险和漏洞评估,并准备正式报告和建议。
  • 分析现有政策和流程是否符合联邦法律、法规和标准;推荐补救策略以弥补安全差距。
  • 建议系统改进措施,以解决已识别的不足并提高整体安全态势。
  • 设计、测试和集成计算机和网络安全工具;确保系统配置安全并合规部署。
  • 执行系统扫描,解释结果,并协助系统管理员解决发现的问题。
  • 进行内部安全程序审计,并制定缓解策略以应对已识别的风险。
  • 为支持不断变化的任务需求的安全架构设计提供技术指导。
  • 支持安全事件调查、根本原因分析和响应。
  • 执行漏洞评估,并制定、记录和跟踪纠正行动计划。

资格要求
基本要求:

  • 本科学位并有8年工作经验,或硕士学位并有6年工作经验,或专科学位并有10年工作经验,或高中文凭/同等学历并有12年工作经验。
  • 必须是美国公民,能够获得并保持DHS公共信任级别许可。
  • 在联邦或受监管环境中展示过信息系统安全官(ISSO)职责的经验,包括创建
查看英文原文

Responsibilities
Peraton is seeking a seasoned Information Assurance and Security Engineer to serve as an Information System Security Officer (ISSO) for a cloud-hosted, Azure-based system. The ideal candidate brings deep security expertise, strong stakeholder communication skills, and hands-on experience supporting Agile software development teams delivering mission critical solutions within DHS or other Federal environments.
This position is remote.
Day to Day Roles and Responsibilities:

  • Provide technical and programmatic information assurance support to internal and external customers for network and information security systems.
  • Design, develop, and implement security requirements across enterprise and program-level business processes.
  • Prepare documentation and security artifacts based on customer input and industry standard guidelines (e.g., NIST RMF, DHS 4300A). Lead certification and accreditation activities for the program.
  • Develop and maintain security test and evaluation plans and contingency plans.
  • Conduct risk and vulnerability assessments and prepare formal reports and recommendations.
  • Analyze existing policies and procedures for compliance with Federal laws, regulations, and standards; recommend remediation strategies to close security gaps.
  • Recommend system enhancements to address identified deficiencies and improve the overall security posture.
  • Design, test, and integrate computer and network security tools; secure system configurations and ensure compliant deployments.
  • Perform system scans, interpret results, and support system administrators in resolving findings.
  • Conduct internal security program audits and develop mitigation strategies to address identified risks.
  • Provide technical guidance for secure architecture design supporting evolving mission needs.
  • Support security incident investigations, root-cause analysis, and response.
  • Perform vulnerability assessments and develop, document, and track corrective action plans.

Qualifications
Basic Qualifications:

  • Bachelors degree and 8 years of experience or a Masters degree and 6 years of experience or an Associates degree and 10 year of experience or a High School diploma/equivalent and 12 years of experience.
  • Must be a U.S. Citizen with the ability to obtain and maintain a DHS Public Trust clearance.
  • Demonstrated experience performing Information System Security Officer (ISSO) duties in a Federal or regulated environment, including creating and maintaining RMF documentation, SSPs, POA&Ms, security test plans, and continuous monitoring artifacts.
  • Proven experience supporting software development teams delivering Azure-based cloud solutions, including familiarity with Azure AD, App Services, Key Vault, App Gateway/WAF, and cloud-native security controls.
  • Hands-on experience identifying, tracking, and managing security vulnerabilities, including interpreting scan results (e.g., Tenable/Nessus, Microsoft Defender) and working with engineering teams on mitigation strategies.
  • Strong understanding of NIST 800-53, 800-30, 800-37, and 800-171 frameworks.
  • Active CISSP certification, or the ability to obtain within 6 months of hire.
  • Strong communication skills, including developing briefing materials, presenting technical concepts to nontechnical stakeholders, and supporting customer engagements.

Preferred Qualifications:

  • Working knowledge of DHS security policies, controls, and compliance requirements, including DHS 4300A/B, 4300A Sensitive System Handbook, and associated RMF processes.
  • Knowledge of Azure security architecture patterns such as Zero Trust, RBAC, network segmentation, PIM/PIM, and least-privilege design.
  • Strong understanding of Agile methodologies and successful collaboration within cross-functional Agile teams, including participation in sprint planning, backlog refinement, and security-focused reviews.
  • Experience with security automation and DevSecOps workflows (e.g., GitHub Actions, Azure DevOps pipelines, IaC security scanning).
  • Experience implementing Continuous Monitoring plans, dashboards, and automated control reporting.
  • Additional security certifications such as ISC2 CAP, ISC2 CCSP, CompTIA Security+, or Azure Security Engineer Associate (AZ-500).

Peraton Overview
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.
Target Salary Range
$86,000 - $138,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.EEO
EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.Originally posted on Himalayas

本页面信息整理自 Himalayas,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

软件开发顾问

PeratonUnited States$104,000 - $166,000/年Full Time今天
开发工程限定地区(需当地身份)

监控雷达技术顾问

PeratonUnited States$104,000 - $166,000/年Full Time今天
开发工程限定地区(需当地身份)

云平台技术负责人

PeratonUnited States$112,000 - $179,000/年Full Time今天
开发工程限定地区(需当地身份)

← 返回全部职位