Peraton - Reston, VA

posted 21 days ago

Full-time
Remote - Reston, VA
Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services

About the position

The Cloud Security Engineer (DIS SecOps) at Peraton is responsible for ensuring the security and compliance of cloud systems in support of the Federal Reserve Bank Data Integration Service program. This role involves defining information system categorization, managing AWS security tools, and collaborating with various teams to address security vulnerabilities and compliance issues. The position is remote and requires a strong background in cloud security, particularly within the AWS environment.

Responsibilities

  • Define Information System Categorization (High, Moderate, or Low)
  • Determine the Confidentiality, Integrity, and Availability impact rating of data
  • Manage the AWS Cloud Security Score Card for the FAPC Data Integration Service offering
  • Gather daily insights from AWS Security Hub, AWS GuardDuty, AWS Health, AWS Config to mitigate as required
  • Work closely with Platform and Vendor teams to address and mitigate the root cause of ongoing non-compliance
  • Review, investigate and mitigate non-compliant controls, including supporting Terraform IaC code changes
  • Investigate build pipelines, IaC and confirm finding resolution
  • Complete System Security Plan in accordance with the system categorization
  • Provide System Security Plan (~400 controls for CFS.20 Baseline) with supporting artifacts
  • Implement System Security Plan on the information system
  • Support Security Control Assessment (SCA) - technical and non-technical review of the information system(s) controls performed by a third-party assessor
  • Contextualize assessment results and record in RISC for risk management tracking
  • Support NIRT penetration testing per SAFR CA-8 control requirement
  • Attend the scheduled SCA interviews and provide supporting documentation at the interviewer's request
  • Ensure the system's UAT environment is available for security testing
  • Provision access to UAT to the assessors
  • Assemble Authorization To Operate for AO review and approval at consultation meeting
  • Review and maintain accuracy of ATO processes in support of PO activities with Authorizing Official

Requirements

  • Bachelor's Degree and a minimum of 5 years experience (or 4 additional years of experience in lieu of degree)
  • Experience in Federal or Government security domain
  • AWS Security Specialty Certification or one or more leading Security certifications (i.e. CISSP, CISM, CISA, CRISC)
  • Experience with ATOs
  • Hands-on enterprise level implementation experience in AWS
  • Experience providing SecOps implementation
  • Working knowledge of source version control, build/release tools and methodologies, NIST Security practices
  • Familiarity with CI/CD pipelines
  • Experience with Terraform IaC coding
  • Experience with software build process
  • Must be a US Citizen
  • Must be able to obtain and maintain the required agency clearance (Public Trust)

Nice-to-haves

  • AWS Professional Level certifications
  • Active Public Trust is a plus

Benefits

  • Comprehensive medical plans
  • Tuition reimbursement
  • Tuition assistance
  • Fertility treatment support
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service