Security Control Assessor

3 hours ago


Linthicum, Maryland, United States Peraton Full time

About Peraton

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit to learn how we're keeping people around the world safe and secure.

Program Overview

About The Role

We are seeking an experienced Security Control Assessor professional to accomplish the following:

  • Conduct assessments and facilitate risk mitigation planning.
  • Provide Assessment and Authorization (A&A) for the ARCYBER cloud infrastructure.
  • Execute a security control assessment plan and update the System Security Plan.
  • Review vulnerability scans and remediation.
  • Implement risk management programs by utilizing NIST, FISMA, HIPAA, and PII - and document solutions.
  • Monitor the privacy landscape regarding all data (privacy, protection, classification, and residency).
  • Assist clients with identifying gaps within existing privacy programs and designing solutions to help address those challenges.
  • Scan, test, and validate systems/networks/applications to obtain/maintain an ATO under NIST/FISMA guidelines.

Location: Baltimore metropolitan area

Qualifications

Required Qualifications:

  • Bachelor's degree in one of the following fields: Computer Science, Cybersecurity, Data Science, Information Systems, Mathematics, Software Engineering, or Information Technology with 8+ years of relevant experience; or Master's with 6+ years of relevant experience. In lieu of a Bachelor's degree in one of these fields of study, candidate must possess a HS Diploma with 12+ years of relevant experience and one of the following active certifications: GMON, Security X/CASP+, CCSP, CISSO, Cloud+, CSSLP, FITSP-D, GCSA, GSEC, CCNP Enterprise, CISM, CISSP-ISSAP, CISSP-ISSEP, GCIA, GDSA, or GICSP.
  • Active TS clearance with SCI eligibility.
  • Active IAT Level II certification (such as CompTIA Security+).
  • Active IAM level III certification (such as CISM).
  • Must have knowledge of enterprise solutions across multiple cloud operating environments (JWICS, SIPRNET, NIPRNET, and commercial Internet).
  • Must have eMASS, ACAS, and ISC2 Certified Cloud Computing Professional (CCSP) or CompTIA Cloud+ experience.
  • Must have knowledge in the following areas:
  • Knowledge of computer networking and/or cloud computing concepts and protocols, and network security methodologies.
  • Knowledge of cyber threats and vulnerabilities in a virtualized environment.
  • Knowledge of national and international laws, regulations, policies, and ethics as they relate to cybersecurity.
  • Knowledge of risk management framework processes (e.g., methods for assessing and mitigating risk).
  • Knowledge of specific operational impacts of cybersecurity lapses.
  • Knowledge of industry methods for evaluating, implementing, and disseminating Information Technology (IT) security assessment, monitoring, detection, and remediation tools and procedures using standards-based concepts and capabilities.
  • Knowledge of cyber defense and vulnerability assessment tools, including opensource tools, and their capabilities.
  • Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
  • Knowledge of cybersecurity principles used to manage risks related to the use, processing, storage, and transmission of information or data in a cloud environment.
  • Knowledge of IT and cloud computing security principles and methods (e.g., firewalls, demilitarized zones, encryption).
  • Knowledge of known vulnerabilities from alerts, advisories, errata, and bulletins.
  • Knowledge of network and/or cloud computing environment security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
  • Knowledge of penetration testing principles, tools, and techniques..
  • Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, returnoriented attacks, malicious code).
  • Knowledge of the Security Assessment and Authorization process.
  • Skill in determining how a security and/or cloud computing security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
  • Skill in discerning the protection needs (i.e., security controls) of information systems and networks and those relating to cloud computing.
  • Knowledge of local specialized system requirements (e.g., critical infrastructure systems that may not use standard IT) for safety, performance, and reliability.
  • Knowledge of new and emerging IT and cybersecurity technologies and/or those technologies specific to cloud computing.

SCA / Union / Intern Rate or Range

Details

Target Salary Range: $135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

Benefits Statement: Peraton offers eligible employees a variety of benefits including medical, dental, vision, life, health savings account, short/long term disability, EAP, parental leave, 401(k), paid time off (PTO) for vacation, and company paid holidays. A full listing of available benefits can be viewed at

Application Duration Statement: The application period for the job is estimated to be 30 days from the job posting date. However, this timeline may be shortened or extended depending on business needs and the availability of qualified candidates.

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.



  • Linthicum, Maryland, United States ClearEdge Full time

    Join ClearEdge and be part of a mission-focused team solving some of the DoD's most complex technical challenges. Every day, ClearEdge supports government and industry customers by delivering innovative solutions that enable critical operations and mission success. ClearEdge offers an extremely competitive benefits package—including a $10k annual training...

  • Cloud Security Engineer

    6 minutes ago


    Linthicum, Maryland, United States Peraton Full time $112,000 - $179,000

    ResponsibilitiesA Cloud Security Engineer is needed to assist in the planning, building and management of cybersecurity for a federal customer's Cloud Environment. These responsibilities would require a technical understanding and include addressing the cybersecurity of cloud deployments by ensuring the design, configuration, implementation, data controls,...


  • Linthicum, Maryland, United States Peraton Full time $112,000 - $179,000

    ResponsibilitiesPeraton has an opening for an Information Systems Security Officer (ISSO) with a proven track record of DevSecOps success to include a combination of technical skills, communication skills, and cybersecurity skills. The successful candidate will be responsible for ensuring the implementation and maintenance of security controls in accordance...


  • Linthicum, Maryland, United States Johnson Controls Full time

    Build your best future with the Johnson Controls teamAs a global leader in smart, healthy and sustainable buildings, our mission is to reimagine the performance of buildings to serve people, places and the planet. Join a winning team that enables you to build your best future Our teams are uniquely positioned to support a multitude of industries across the...


  • Linthicum, Maryland, United States Northrop Grumman Full time $123,400 - $185,000

    RELOCATION ASSISTANCE: Relocation assistance may be availableCLEARANCE TYPE: A US Government security clearance per customer's requirements.TRAVEL: Yes, 10% of the TimeDescriptionAt Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come....


  • Linthicum, Maryland, United States Johnson Controls Full time $68,000 - $85,000

    Build your best future with the Johnson Controls teamAs a global leader in smart, healthy, and sustainable buildings, our mission is to reimagine the performance of buildings to serve people, places, and the planet. Join a winning team that enables you to build your best futureOur teams are uniquely positioned to support a multitude of industries across the...


  • Linthicum, Maryland, United States Northrop Grumman Full time

    RELOCATION ASSISTANCE: Relocation assistance may be availableCLEARANCE TYPE: Top SecretTRAVEL: Yes, 25% of the TimeDescriptionAt Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world today, and for generations to come. Our pioneering and inventive spirit has enabled us to...


  • Linthicum, Maryland, United States Amentum Full time $185,000 - $210,000

    Purpose and Impact: Amentum is seeking an Information Systems Security Officer (ISSO) 3 for a prime contract that is based out of our Linthicum, MD office.  Essential Responsibilities:Provide support for a program, organization, system, or enclave's information assurance program.Provide support for proposing, coordinating, implementing, and enforcing...


  • Linthicum, Maryland, United States Leidos Full time $131,300 - $237,350

    As a Senior Information Security Systems Engineer (ISSE) you will join a small team of security engineers providing Information Assurance (IA) Architecture Analysis and Security Engineering Support for the implementation and fielding of the National Leadership Command Capability in support of Nuclear Command, Control, and Communications (NC3), Continuity of...


  • Linthicum, Maryland, United States Amentum Full time $170,000 - $195,000

    our Impact:Are you interested in using your skills to help shape the Cyber, Security, & Intel space?  If so, look no further. Amentum is seeking an Information Systems Security Officer (ISSO) to join our team of passionate individuals in Linthicum, MD. In this role you will support challenging, mission-critical projects that make a direct impact on the...