Information Assurance and Security Engineer

atPeratonRemoteUS flagUnited StatesFull-timeCybersecurity / Security EngineerMid-levelSenior$86k – $138k/year

Posted Sep 16

This is a fully remote position, open to applicants in United States.

📋 Description

• Deliver technical and programmatic information assurance services for network and information security systems within the DEERS application portfolio.

• Create, develop, and execute security requirements within business processes, DevSecOps pipelines, OCI cloud migration, and Agile development sprints.

• Prepare and sustain SSPs, SARs, POA&Ms, STIG checklists, and implementation plans utilizing eMASS.

• Formulate ST&E plans and assist in formal security assessments alongside DMDC CSD and Enterprise ISSOs.

• Provide C&A/A&A support, including security and contingency plans, in accordance with DoDI 8510.01 and NIST SP 800-37 RMF.

• Perform risk and vulnerability assessments while devising mitigation strategies.

• Evaluate policies and procedures against federal laws and regulations, advising on compliance-gap remediation.

• Execute security enhancements and assist with IAVA monitoring and monthly resolution tasks.

• Develop, test, and integrate Fortify, Sonatype, and BURP security scanning tools into the DevSecOps pipeline.

• Secure system configurations, carry out STIG and NIST baseline compliance scans, and report findings.

• Conduct security program audits and facilitate 1–3 external audits each year.

• Aid in security architecture and OCI cloud migration at DISA IL-4/IL-5 authorization levels.

• Assist with computer incident investigations and report cyber incidents within mandated timelines.

• Submit and revise POA&Ms based on vulnerability-severity deadlines.

• Support ISCM activities and provide weekly vulnerability scan status updates during IPRs.

• Maintain ATOs and A&I packages throughout the entire RMF lifecycle.

• Implement JFHQ-DODIN and USCYBERCOM CTOs.

• Ensure cybersecurity workforce personnel are screened, trained, and certified according to DoD 8140.03 and CMMC requirements.

• Conduct mandatory security training on OPSEC, CUI, Insider Threat, Privacy Act/PII, IT Security, Counterintelligence, Antiterrorism, and Records Management.


⛳️ Requirements

• A minimum of 8 years of experience with a BS/BA; 6 years with an MS/MA; 3 years with a PhD; or 12 years with a high school diploma.

• Capability to obtain and retain DoD Public Trust.

• Practical experience with the DoD Risk Management Framework (RMF) and eMASS.

• Comprehensive knowledge of NIST SP 800-53 Rev 5, NIST SP 800-37, NIST SP 800-171 Rev 2, NIST SP 800-137, FISMA, DoDI 8510.01, and DoDI 8500.01.

• Experience in conducting vulnerability assessments, creating POA&Ms, and managing the complete A&A lifecycle, including ATO package development.

• Familiarity with Fortify, Sonatype, and BURP application security scanning tools.

• Knowledge of OWASP secure coding principles.

• Working knowledge of STIG compliance verification, checklist preparation, and remediation.

• Proven experience in supporting DevSecOps security practices in Agile development settings.

• DoD 8140.03 / DoD 8570.01-M compliant IAT/IAM Level II certification, such as CISSP, CASP+, CEH, Security+, or an equivalent certification.

• Preferred: active Public Trust clearance.

• Preferred: CISSP or equivalent advanced certification.

• Preferred: cloud security experience at FedRAMP Moderate, DISA IL-4, or DISA IL-5 authorization levels; familiarity with OCI security configuration.

• Preferred: knowledge of CMMC.

• Preferred: experience with external DoD financial/operational audits.

• Preferred: familiarity with ServiceNow, JIRA, and SharePoint.

• Preferred: understanding of DFARS 252.204-7012 cyber incident reporting requirements.

• Preferred: experience in implementing JFHQ-DODIN or USCYBERCOM CTOs.

• Preferred: prior S-ISSO experience within a large-scale DoD program environment.


🏝️ Benefits

• Potential eligibility for overtime.

• Shift differential.

• Discretionary bonus.

• Equal opportunity employment, including for individuals with disabilities and protected veterans.

People also viewed

Sony Interactive Entertainment17 hours ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads18 hours ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Neo4j18 hours ago

Senior Director, Product, Security and Privacy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$260k – $300k/year
ApplyView job
PingWind Inc. (SDVOSB)19 hours ago

Cloud Security Architect – Engineer

US flagAlabama, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
CSCI Consulting19 hours ago

SAP S/4HANA Defense & Security Functional Lead

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Strategic Systems International20 hours ago

AI Security Engineer – AI, Agentic Security

MX flagMexico, +4 more countriesFreelanceCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers