Peraton Logo

Peraton

Software Development, Lead Associate

Posted 8 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
66K-106K Annually
Senior level
Remote
Hiring Remotely in United States
66K-106K Annually
Senior level
Serve as ISSO for a federal healthcare claims program, managing FISMA and FedRAMP compliance, RMF documentation, ATO activities, risk and vulnerability assessments, audits, incident response, and continuous monitoring. Integrate security into DevSecOps pipelines, cloud configurations, infrastructure-as-code, architecture reviews, and deployment processes while maintaining authorization documentation, remediation timelines, system inventories, and security baselines.
The summary above was generated by AI
Responsibilities

Peraton is seeking a Mid-level DevSecOps Engineer to join our team of qualified, diverse professionals. In this role, you will support the security, reliability, and compliance of mission‑critical systems within the DME Program. The ideal candidate will play a key part in integrating security throughout the development lifecycle, maintaining adherence to federal cybersecurity standards, and ensuring the operational readiness of modernized systems at the Centers for Medicare & Medicaid Services (CMS). This position supports a highly visible environment where strong technical execution, security rigor, and cross‑team collaboration are essential.


Responsibilities:

  • Serve as the Information System Security Officer (ISSO) for the ClaimsCore Program, ensuring full compliance with FISMA Moderate, FedRAMP Moderate, and CMS ARS 5.1 security requirements.
  • Prepare, maintain, and update all Certification and Accreditation (C&A) and Security Assessment and Authorization (SA&A) documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Contingency Plans, and Plan of Action and Milestones (POA&Ms).
  • Conduct and document ongoing risk assessments, vulnerability assessments, and security control evaluations across the program’s cloud and on‑premises environments.
  • Manage and coordinate the Authority to Operate (ATO) lifecycle, including initial authorization, continuous monitoring, control implementation reviews, and audit preparation.
  • Ensure zero open Critical or High vulnerabilities at system go-live and maintain compliance with vulnerability remediation SLAs.
  • Respond to and manage security incident notifications within required timelines (1 hour for initial reporting). Coordinate with internal security teams and external stakeholders to support incident response processes.
  • Support internal and external audits, including CSRAP, CFO, OMB A‑123, and annual security assessments.
  • Collaborate with DevOps, engineering, and operations teams to integrate security best practices into CI/CD pipelines, infrastructure-as-code, and deployment processes.
  • Monitor and enhance security posture using tools such as vulnerability scanners, SIEM platforms, configuration management tools, and compliance automation platforms.
  • Contribute to continuous improvement of security procedures, engineering practices, and system hardening baselines.
  • Assist in the implementation and maintenance of cloud security configurations aligned with agency and program requirements.
  • Provide security guidance during architecture reviews, design sessions, sprint planning, and change control processes.
  • Ensure security documentation, diagrams, inventories, and boundary definitions are accurate and up to date.
Qualifications

Qualifications (Required):

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, Engineering, or related field; additional experience may be substituted in lieu of degree.
  • 5 to 7 years of experience in cybersecurity, DevSecOps, or system engineering roles supporting federal programs.
  • Experience acting as an ISSO or security engineer for a FISMA Moderate or FedRAMP Moderate system.
  • Hands-on experience preparing security authorization documentation such as SSPs, SARs, POA&Ms, and Continuous Monitoring updates.
  • Strong understanding of NIST 800‑53 security controls, Risk Management Framework (RMF), CMS ARS 5.1, and continuous monitoring requirements.
  • Practical experience supporting or integrating security processes in DevSecOps pipelines, CI/CD workflows, or automated deployment environments.
  • Experience with vulnerability management tools and processes, including scanning, analysis, and remediation tracking.
  • Ability to support audits and communicate effectively with assessment teams, program stakeholders, and government security representatives.
  • U.S. citizenship and the ability to obtain and maintain a public trust or equivalent clearance.

Qualifications (Preferred):

  • Experience supporting CMS programs or other HHS components.
  • Familiarity with FedRAMP documentation, cloud boundary definitions, and cloud-native security practices.
  • Experience with AWS or Azure security services, cloud configuration baselines, and cloud compliance frameworks.
  • Working knowledge of tools commonly used within Peraton and similar enterprises, such as GitLab/GitHub CI/CD, Jenkins, Terraform, Ansible, Tenable, Splunk, or similar platforms.
  • Security certifications such as Security+, CISSP, CISM, CCSP, or AWS/Azure security certifications.
  • Experience integrating legacy systems into modern cloud or hybrid architectures with secure migration practices.
  • Knowledge of container security (Docker, Kubernetes) and infrastructure-as-code security scanning.
Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

Target Salary Range$66,000 - $106,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. EEOEEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Similar Jobs

8 Hours Ago
Remote
United States
80K-128K Annually
Senior level
80K-128K Annually
Senior level
Aerospace • Information Technology • Security • Cybersecurity • Defense
Develops, tests, debugs, maintains, and evaluates Oracle-based software systems. Provides technical guidance, supports system design and implementation, identifies software hazards, ensures compliance with safety and government standards, documents mitigations, and may lead software development teams. Works with users to define requirements, plan projects, and resolve issues found through testing or customer feedback.
Top Skills: AgileOracle ApexOracle FormsOracle ReportsPl/Sql
18 Minutes Ago
Remote
United States
140K-140K Annually
Senior level
140K-140K Annually
Senior level
Security • Cybersecurity
Lead hypothesis-driven threat hunts across industrial control system and operational technology networks. Investigate suspicious activity, escalate high-severity alerts, configure Dragos Platform hunt profiles, develop hunting content, analyze network telemetry, and improve detection capabilities. Advise customers during critical security events, produce technical reports, create repeatable tooling, and mentor junior team members on OT protocols, adversary tactics, and threat intelligence.
Top Skills: DnsDragos PlatformFirewallsIcs/OtIds/IpsMitre Att&Ck For IcsPcapSIEMTcp/Ip
25 Minutes Ago
Remote or Hybrid
45K-85K Annually
Junior
45K-85K Annually
Junior
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Handles inbound calls and warm leads to identify customer insurance needs, recommend appropriate Property and Casualty coverages, and convert prospects into policyholders. The role includes paid licensing and training, customer consultation, sales closing, brand representation, and adherence to remote-work requirements. Representatives must work four weekdays and one weekend day, maintain a professional home workspace, and use wired high-speed internet. Training lasts 16–18 weeks depending on licensing status.
Top Skills: Cable InternetDslFiber InternetHigh-Speed InternetPc

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account