Information Assurance and Security Engineer

🔥 18 hours ago

🇺🇸 United States – Remote

💵 $86k - $138k / year

⏰ Full Time

🟡 Mid-level

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Peraton

Peraton

10,000+ employees

💼 Consulting

🏥 Healthcare

📦 Logistics

Consulting • Healthcare • Logistics

Peraton is a mission-focused enterprise that supports national security initiatives through advanced IT and cyber services. They provide capabilities in areas such as cyber defense, cloud operations, engineering, and intelligence. With a commitment to solving complex challenges, Peraton integrates data-driven technologies to ensure mission success for their military and government clients.

📋 Description

• Provide technical and programmatic information assurance services for network and information security systems across the DEERS application portfolio • Design, develop, and implement security requirements in business processes, DevSecOps pipelines, OCI cloud migration, and Agile development sprints • Prepare and maintain SSPs, SARs, POA&Ms, STIG checklists, and implementation plans in eMASS • Prepare ST&E plans and support formal security assessments with DMDC CSD and Enterprise ISSOs • Provide C&A/A&A support, including security and contingency plans, aligned with DoDI 8510.01 and NIST SP 800-37 RMF • Conduct risk and vulnerability assessments and develop mitigation strategies • Analyze policies and procedures against federal laws and regulations and recommend compliance-gap remediation • Implement security enhancements and support IAVA monitoring and monthly resolution activities • Develop, test, and integrate Fortify, Sonatype, and BURP security scanning into the DevSecOps pipeline • Secure system configurations, conduct STIG and NIST baseline compliance scans, and report results • Conduct security program audits and support 1–3 external audits annually • Support security architecture and OCI cloud migration at DISA IL-4/IL-5 authorization levels • Assist with computer incident investigations and report cyber incidents within required timelines • Submit and update POA&Ms according to vulnerability-severity deadlines • Support ISCM activities and report weekly vulnerability scan status during IPRs • Maintain ATOs and A&I packages through the full RMF lifecycle • Implement JFHQ-DODIN and USCYBERCOM CTOs • Ensure cybersecurity workforce personnel are screened, trained, and certified under DoD 8140.03 and CMMC requirements • Conduct mandatory security training covering OPSEC, CUI, Insider Threat, Privacy Act/PII, IT Security, Counterintelligence, Antiterrorism, and Records Management

🎯 Requirements

• Minimum of 8 years with BS/BA; minimum of 6 years with MS/MA; minimum of 3 years with PhD; 12 years with high school diploma • Ability to obtain and maintain DoD Public Trust • Hands-on experience with DoD Risk Management Framework (RMF) and eMASS • In-depth knowledge of NIST SP 800-53 Rev 5, NIST SP 800-37, NIST SP 800-171 Rev 2, NIST SP 800-137, FISMA, DoDI 8510.01, and DoDI 8500.01 • Experience conducting vulnerability assessments, developing POA&Ms, and managing the full A&A lifecycle including ATO package development • Experience with Fortify, Sonatype, and BURP application security scanning tools • Familiarity with OWASP secure coding practices • Working knowledge of STIG compliance verification, checklist preparation, and remediation • Demonstrated experience supporting DevSecOps security practices within Agile development environments • DoD 8140.03 / DoD 8570.01-M compliant IAT/IAM Level II certification, such as CISSP, CASP+, CEH, Security+, or equivalent • Preferred: active Public Trust clearance • Preferred: CISSP or equivalent advanced certification • Preferred: cloud security experience at FedRAMP Moderate, DISA IL-4, or DISA IL-5 authorization levels; OCI security configuration familiarity • Preferred: familiarity with CMMC • Preferred: external DoD financial/operational audit experience • Preferred: ServiceNow, JIRA, and SharePoint • Preferred: DFARS 252.204-7012 cyber incident reporting knowledge • Preferred: JFHQ-DODIN or USCYBERCOM CTO implementation experience • Preferred: prior S-ISSO experience in a large-scale DoD program environment

🏖️ Benefits

• Potential eligibility for overtime • Shift differential • Discretionary bonus • Equal opportunity employment, including disability and protected veterans

Apply Now

Similar Jobs

🔥 22 hours ago

TBI

5001 - 10000

🏗️ Construction

🏠 Real Estate

Personnel Security Specialist supporting GovStrive’s federal agency clients with background investigations, vetting, onboarding, and personnel security compliance. Managing eAPP cases, fingerprints, and sensitive records remotely.

🔥 22 hours ago

phia, LLC

11 - 50

💼 Consulting

🎖️ Defense

📦 Logistics

Senior PKI cybersecurity engineer supporting phia’s federal agency certificate operations. Automating Venafi/CyberArk certificate management, advising stakeholders, and strengthening enterprise encryption infrastructure.

🕒 Yesterday

W.C. Bradley Co.

501 - 1000

🍽️ Food & Beverage

🏨 Hospitality

🛒 Retail

EHSS leader standardizing safety, environmental compliance, and operational risk across W.C. Bradley’s U.S. pellet mills and distribution centers. Leading site managers, audits, training, investigations, and corrective actions.

🕒 Yesterday

COFENSE

201 - 500

🔒 Cybersecurity

☁️ SaaS

🤝 B2B

Information security program manager managing Cofense customer portfolios and simulated phishing defense programs. Delivering security guidance, remediation reporting, and product adoption support across the United States.

🕒 Yesterday

Imagineeer

11 - 50

🏛️ Government

🔒 Cybersecurity

💼 Consulting

Security Control Assessor applying NIST frameworks to evaluate federal HHS-ACF system security. Documenting evidence, testing controls, supporting vulnerability analysis, and developing compliance deliverables.