Peraton is searching for an Information Privacy and Security Analyst to join its Citizens Security & Public Services State and Local team. The role supports the Texas Integrated Eligibility Redesign System (customer) Security Team by assisting in the implementation and maintenance of information security measures to protect computer systems, networks, and data. The position works under general direction and applies established security guidelines, policies, and frameworks to support a secure operating environment.
Day-to-Day Roles and Responsibilities:
ARC-AMPE Security Audit Coordination:
- Coordinate customer responses to ARC-AMPE and other security audits, serving as the primary point of contact between the customer Security Team and customer support teams.
- Develop deep familiarity with the ARC-AMPE security controls (a curated subset of NIST 800-53 controls) and their applicability to the customer environment.
- Develop working knowledge of the customer support teams responsible for responding to each control area and maintain awareness of roles and responsibilities across teams.
- Manage and monitor audit responses in the Archer GRC system, ensuring responders submit within required timeframes.
- Meet regularly with control responders to provide consulting assistance on control interpretation, evidence determination, and submission requirements.
CISA and OEM Security Alert Monitoring:
- Subscribe to and monitor CISA and other OEM security alerts for applicability to the customer infrastructure.
- Correlate incoming CISA notifications against the customer architecture; when applicable, communicate findings to the customer within 48 hours of notice.
- Consult with customer on cyber threat remediations as requested.
- Assist in implementing security measures to protect computer systems, networks, and data in accordance with established policies and standards.
- Support efforts to prevent data loss and service interruptions by researching and evaluating new technologies to protect the environment.
- Help ensure all networks have adequate security controls to prevent unauthorized access.
- Maintain security system documentation and assist in keeping security systems current with software or hardware changes.
- Support application security assessments using off-the-shelf tools under general guidance.
- Assist in preparing vulnerability assessment documentation and contributing to security assessment reports.
- Participate in project-related conference calls and security review meetings, providing supporting information as needed.
- Conduct research to identify and understand new threats, vulnerabilities, and exploits, and report findings to the appropriate internal or customer stakeholders.
- Follow established procedures to help ensure the safety of information systems assets and protect systems from intentional or inadvertent access or destruction.
- Support the application of security frameworks including NIST 800-37, NIST 800-53, ARC/AMPE controls, POA&Ms, and Corrective Action Plans under general direction.
- Assist the project team with Disaster Recovery (DR) planning, Business Continuity Plan (BCP), and Continuity of Operations (COOP) documentation and assessments.
- Help prepare impact assessment reports documenting security incidents and contributing to remediation documentation.
- Assist in creating and maintaining standard operating procedure documents in adherence to security policies and standards.
- Document violations of computer security procedures and escalate findings to the appropriate internal or customer stakeholders.
- Interact with users to gather information on computer data access needs and assist in addressing routine security questions.