Peraton
• $112K — $179K *Qualifications
Responsibilities
Benefits
We are seeking Cybersecurity / Compliance Engineers to implement and sustain security controls, authorization evidence, continuous monitoring, vulnerability management, software-security requirements, and common-control responsibilities across enterprise environments.
These engineers will work closely with platform, cloud, DevSecOps, IAM, observability, and application teams to ensure security requirements are incorporated into engineering and operational processes. The role combines technical security engineering with Risk Management Framework (RMF), authorization, compliance, and continuous-monitoring activities.
Responsibilities Risk Management & AuthorizationSupport RMF, security assessment, authorization, and continuous-monitoring activities for enterprise services and environments.
Maintain security evidence, control implementation information, Plan of Action and Milestones (POA&M) inputs, and authorization documentation.
Assess and document security impacts associated with platform, infrastructure, application, and commercial or government-off-the-shelf software changes.
Support common-control and inherited-control documentation and implementation activities where applicable.
Coordinate with security, engineering, and operational stakeholders to address control gaps and authorization requirements.
Define and review security requirements for cloud, Kubernetes, CI/CD, identity, network, and application services.
Integrate security validation and evidence collection into engineering and software-delivery workflows.
Support vulnerability scanning, vulnerability triage, remediation tracking, and risk-acceptance processes.
Support implementation of Zero Trust, RBAC/ABAC, encryption, secrets management, logging, and workload-security requirements.
Evaluate technical implementations against established security requirements and identify potential risks or control deficiencies.
Collaborate with engineering teams to develop practical approaches for implementing and sustaining security controls.
Support security reviews of COTS, GOTS, FOSS, software artifacts, containers, and third-party dependencies.
Coordinate security evidence and documentation requirements associated with software and infrastructure changes.
Support software supply-chain security, artifact integrity, provenance, and dependency-management practices.
Partner with DevSecOps and engineering teams to integrate security controls into development and delivery processes.
Identify security risks associated with software components and recommend appropriate mitigation or remediation actions.
Support continuous security monitoring and assessment activities.
Track security findings, vulnerabilities, control deficiencies, and remediation activities.
Maintain accurate security documentation, evidence repositories, and compliance records.
Support audits, assessments, inspections, and other security compliance activities.
Monitor changes to enterprise systems and evaluate potential impacts to existing security controls and authorization requirements.
Location: This position is fully onsite in Chantilly, VA
Qualifications Required QualificationsActive TS/SCI clearance with CI Polygraph.
Approximately 6–10 years of experience in cybersecurity, Information Systems Security Engineering (ISSE), RMF, security compliance, or security engineering.
Experience supporting RMF, security authorization, and continuous-monitoring activities.
Experience implementing, assessing, or documenting technical security controls.
Working knowledge of cloud security, DevSecOps, identity and access management, network security, and vulnerability management concepts.
Experience developing authorization packages, security evidence, assessment documentation, or continuous-monitoring artifacts.
Strong technical writing, documentation, and communication skills.
Experience with one or more of the following:
Continuous authorization or cATO practices.
Cloud security services, including AWS security services.
Kubernetes security.
Software supply-chain security.
Security automation and automated evidence collection.
Security compliance within classified or highly regulated environments.
ServiceNow or comparable security/RMF workflow platforms.
Experience supporting large-scale enterprise security authorization programs.
Our team will look into this right away.