Responsibilities**Position Is Contingent Upon Award**
Peraton Labs is hiring an Information System Security Manager (ISSM) to be the single point of contact to Covered California and the accountable owner of oversight, timely execution, and quality for every security service Peraton delivers to the California health benefit exchange and the CalHEERS eligibility and enrollment system. You will lead a small, senior, multi-disciplinary security team spanning governance and compliance, security architecture and engineering, incident response, third-party risk, technical security, monitoring, and data protection.
You will work directly with Covered California's CISO and Information Security Officer, technical and project teams, business stakeholders, and independent assessors. The goal is to keep a system that carries the personal, health, and financial information of millions of Californians measurably secure, continuously compliant with NIST SP 800-53 Rev. 5, ARC-AMPE, and IRS Publication 1075, and ready for CMS Authority to Connect review.
What You Will Do In This Role:
- Lead the security team. Manage and coordinate the day-to-day activities of assigned information security personnel; provide leadership, mentoring, and direction, and own deliverable accuracy, consistency, and schedule adherence across all seven contracted service areas.
- Serve as the primary client security liaison. Act as the single operational point of contact among contractor personnel, Covered California security leadership, technical teams, project teams, and business stakeholders, and deliver regular status, risk, and escalation reporting to security leadership.
- Own the compliance and GRC engine. Manage security activities tied to NIST SP 800-53 Rev. 5 controls; coordinate development and review of security policies, procedures, standards, and plans; direct GRC activities and platforms; and maintain the risk register.
- Drive risk down to closure. Oversee risk assessments, control reviews, gap analyses, and remediation; track weaknesses, findings, and Plans of Action and Milestones (POA&Ms) through verified closure.
- Serve as backup incident manager. Support the incident response program in coordination with the client Information Security Officer, and coordinate investigations, evidence handling, communications, escalation, reporting, and post-incident review; participate in the on-call incident response rotation.
- Coordinate technical and third-party security work. Guide security architecture and engineering reviews across cloud and on-premises environments and technical security work spanning network, endpoint, vulnerability management, identity and access management, cloud, and application security; manage vendor security due diligence, assessments, contract and control reviews, and monitoring.
- Coordinate assessment and penetration testing logistics while preserving assessor independence. Provide evidence, scheduling, and remediation ownership for the annual independent assessment and penetration test cycle without directing or influencing the independent assessors' scope, judgments, or findings.
Qualifications
Required:
- Bachelor's degree in cybersecurity, computer science, information systems, information technology, or engineering. In lieu of a degree, an equivalent combination of education, professional certification, and additional relevant experience will be considered.
- 12+ years of progressively responsible cybersecurity experience, including managing security programs, teams, or major security workstreams. (Note: eight years is the absolute floor for equivalency consideration; the posted target is 12+.)
- Active CISSP or CISM certification.
- Demonstrated experience managing security activities against the NIST SP 800-53 Rev. 5 control set in a complex enterprise environment.
- Demonstrated experience owning a risk register and managing POA&Ms, findings, and corrective action plans through closure, using an enterprise GRC platform or comparable control-tracking system.
- Demonstrated ability to lead and mentor senior technical personnel while working collaboratively with client stakeholders, and to brief cybersecurity risk credibly to both technical and executive audiences in writing and in person.
- US Citizenship and the abillity to pass a California criminal background clearance (Gov. Code a71043 / 10 CCR a76456) before starting work or accessing any confidential information, PII, PHI, federal tax information, or financial information.
Desired:
- Master's degree in cybersecurity, computer science, information systems, or a related discipline.
- PMP certification. CGRC, CRISC, or CCSP are also valued.
- Hands-on experience with ARC-AMPE (ACA, Medicaid and Partner Entities) security and privacy requirements.
- Experience with IRS Publication 1075 compliance and federal tax information (FTI) control management.
- Experience with CMS cybersecurity requirements and the CMS Authority to Connect (ATC) process or comparable federal authorization processes.
- Experience supporting healthcare eligibility and enrollment, Medicaid, or health insurance exchange systems of CalHEERS scale.
- Experience supporting annual security and privacy assessments, including CMS Security Assessment Workbooks (SAWs), security assessment reports, POA&Ms, and control evidence packages.
- Experience in California state government or comparable public-sector cybersecurity environments.
Target Salary Range$135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individuale28099s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.