Peraton - Herndon, VA

posted 21 days ago

Full-time
Remote - Herndon, VA
Computing Infrastructure Providers, Data Processing, Web Hosting, and Related Services

About the position

The Cloud Security Engineer (DIS SecOps) at Peraton is responsible for ensuring the security and compliance of cloud systems in support of the Federal Reserve Bank Data Integration Service program. This role involves defining information system categorization, managing security assessments, and collaborating with various teams to address security vulnerabilities. The position is remote and requires a strong background in cloud security, particularly within AWS environments.

Responsibilities

  • Define Information System Categorization (High, Moderate, or Low)
  • Determine the Confidentiality, Integrity, and Availability impact rating of data
  • Manage the AWS Cloud Security Score Card for the FAPC Data Integration Service offering
  • Gather daily insights from AWS Security Hub, AWS GuardDuty, AWS Health, AWS Config to mitigate as required
  • Work closely with Platform and Vendor teams to address and mitigate the root cause of ongoing non-compliance
  • Review, investigate and mitigate non-compliant controls, including supporting Terraform IaC code changes
  • Investigate build pipelines, IaC and confirm finding resolution
  • Implement CI/CD DevSecOps requirements for all environments (Dev, Test, UAT, Staging, Prod)
  • Complete System Security Plan in accordance with the system categorization
  • Provide System Security Plan with supporting artifacts
  • Implement System Security Plan on the information system
  • Support Security Control Assessment (SCA)
  • Contextualize assessment results and record in RISC for risk management tracking
  • Support NIRT penetration testing per SAFR CA-8 control requirement
  • Attend scheduled SCA interviews and provide supporting documentation
  • Ensure the system's UAT environment is available for security testing
  • Provision access to UAT to the assessors
  • Assemble Authorization To Operate for AO review and approval
  • Review and maintain accuracy of ATO processes in support of PO activities with Authorizing Official

Requirements

  • Bachelor's Degree and a minimum of 5 years experience (or 4 additional years of experience in lieu of degree)
  • Experience in Federal or Government security domain
  • AWS Security Specialty Certification or one or more leading Security certifications (CISSP, CISM, CISA, CRISC)
  • Experience with ATOs
  • Hands-on enterprise level implementation experience in AWS
  • Experience providing SecOps implementation
  • Working knowledge of source version control, build/release tools and methodologies, NIST Security practices
  • Familiarity with CI/CD pipelines
  • Experience with Terraform IaC coding
  • Experience with software build process
  • Must be a US Citizen
  • Must be able to obtain and maintain the required agency clearance (Public Trust)

Nice-to-haves

  • AWS Professional Level certifications
  • Active Public Trust is a plus

Benefits

  • Tuition reimbursement
  • Tuition assistance
  • Comprehensive medical plans
  • Fertility treatment support
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service