About Peraton
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.
Responsibilities
Currently seeking an Information Systems Security Engineers (ISSE) to support an Intel Community (IC) customer in the Herndon, Virginia area
The ISSE responsibilities for conducting information system security engineering activities for new or existing system(s) may include:
- Develop, customize, and configure Splunk applications and dashboards.
- Develops and implements security designs ensure that the hardware, operating systems and software applications adequately address cyber security requirements and Security Controls Traceability Matrix (SCTM).
- Develop Security Test Procedure (STP), conducts self-assessments to verify compliance with required configuration guidance and support A&A testing and validation of security designs.
- Implement, validate Security Technical Implementation Guide (STIG) requirements and/or perform SRG assessments for all development and implementation projects.
- Conducting risk analysis reviewing ACAS, CVEs, plugins, CWEs, research, collaborate with System Administrators to mitigate identified vulnerabilities and/or author Plans of Actions and Milestones (PO&AM) as needed.
- Defines information security requirements and their integration into information systems and its technology component through purposeful security design.
- Identify points of vulnerability, non-compliance with established Information Assurance (IA) standards and regulations and recommend mitigation strategies.
- Execution of continuous monitoring efforts responds to data calls, scan requests, and various weekly and monthly security metrics reporting requirements.
- Validate control implementations provide enforcement of the require data access and network flow restrictions align with the continuous monitoring strategy.
- Participates in Agile Planning Events to provide technical input.
- Support government activities and reporting to appropriate IC and DoD authorities (i.e., USCYBERCOM, IC-SCC)
- Support security authorization activities in compliance with the customer Information System Certification and Accreditation Process following the NIST Risk Management Framework (RMF), CNSSI No 1243 and other prescribed business processes for security engineering.
- Assist architects and systems developers in the identification and implementation of appropriate information security functionality to ensure uniform application of Agency security policy and enterprise solutions.
- Apply system security engineering expertise in one or more of the following to: system security design process; engineering life cycle; information domain; cross domain solutions; commercial off-the-shelf and government off-the-shelf cryptography; identification; authentication; and authorization; system integration; risk management; intrusion detection; contingency planning; incident handling; configuration control; change management; auditing; certification and accreditation process; principles of IA (confidentiality, integrity, non-repudiation, availability, and access control); and security testing.
Qualifications
Minimum of 8 years with BS/BA; Minimum of 6 years with MS/MA; Minimum of 3 years with PhD
Required Qualifications:
- 10 years of experience and a Bachelor’s degree in Computer Science, Information Assurance, Information Security System Engineering, or related discipline from an accredited college or university is required. A Master’s degree in Computer Science, Information Assurance, Information Security System Engineering, or related discipline may be substituted for two (2) years of additional experience. Four (4) years of additional ISSE experience may be substituted for a bachelor’s degree.
- DoD 8570 compliance with IASAE Level 3 is required
- One (1) year of experience with IC Community
- Three (3) years of experience in scripting languages, Linux/RedHat, and/or Database Management.
- Develop, customize, and configure Splunk applications and dashboards.
- Active TS/SCI security clearance with the ability to obtain polygraph is required
Desire Qualifications:
- Information Systems Security Engineering Professional (ISSEP) or CISSP Certifications are required
- Demonstrated experience with DISA Security Technical Implementation Guide (STIG) implementation and Security Content Automation Protocol (SCAP) tool usage
- Skilled in implementing mitigation strategies and how to resolve problems, and to re-test/ re-evaluate systems
- Possess a working knowledge of administrating servers, system and application security threats and vulnerabilities
- Experience extending existing applications in areas such as security, monitoring, task automation, continuous integration, deployment, and performance optimization
- Demonstrate writing of your own project in scripting/programming (use of Shell scripting, Python, JavaScript, PowerShell) in a Linux or Windows environment to support the various Cyber Security tools and applications required
- Provide guidance on vulnerability and malware remediation.
- Experience analyzing vulnerabilities, establishing cause and impact, and identifying the corrective action needed to eliminate and prevent the event from happening in the future.
Target Salary Range
$135,000 - $216,000. This represents the typical salary range for this position based on experience and other factors.
SCA / Union / Intern Rate or Range
EEO
An Equal Opportunity Employer including Disability/Veteran.