Be part of our exciting team supporting a robust, world-wide communications network, providing office automation packages; document and information management tools; and collaboration, voice, and video tools in a secure, flexible, distributed architecture supporting a classified DoD IT system deployed worldwide. Peraton is seeking an Information Systems Security Engineering (ISSE) to collaborate on design efforts, provide security engineering, and lead the engineering of RMF B0E artifacts of a large-scale enterprise Information Technology (IT) program. Responsibilities include:
- Provide ISSE expertise for all assigned engineering tasks and projects.
- Provide guidance describing the system and its functions, information types, operating environments, and security requirements.
- Review the adequacy of the security controls and their ability to protect the information system and its information; assist in tailoring security controls, as appropriate.
- Assist in determining the assurance measures that can be used to meet assurance requirements.
- Integrate ISSE team members into all Scrum and project teams to provide for all requisite RMF security related support.
- Work collaboratively with Systems, Network, and other engineers throughout the service design lifecycle to design and implement security controls, and best practices such as Zero Trust Architecture, including engineering of assigned RMF BoE documentation.
- Conduct Assessment and Accreditation (A&A) activities, following security processes and coordinating with the Designated Authorizing Official (DAO) representatives and appropriate security teams.
- Create and update assigned RMF documentation and artifacts for each service, as required.
- Provides technical and programmatic information assurance services to internal and external customers in support of network and information security systems.
- Designs, develops, and implements security requirements within an organization’s business processes.
- Prepares documentation from information obtained from customer using accepted guidelines.
- Prepares security test and evaluation plans.
- Provides certification and accreditation support in the development of security and contingency plans and conducts complex risk and vulnerability assessments.
- Analyzes policies and procedures against Federal laws and regulations and provides recommendations for closing gaps.
- Recommends system enhancements to improve security deficiencies.
- Develops, tests, and integrates computer and network security tools.
- Secures system configurations and installs security tools, scans systems to determine compliancy and report results and evaluates products and various aspects of system administration.
- Conducts security program audits and develops solutions to lessen identified risks.
- Provides information assurance support for the development and implementation of security architectures to meet new and evolving security requirements.
- Provides assistance in computer incident investigations.
- Performs vulnerability assessments including development of risk mitigation strategies.