Hiring.Camp

Principal Information Security Consultant

Peraton

·

Yesterday

Salary
$135k – $216k
Location
, US
Workplace
Remote
Type
Full-time
Department
IT
Seniority
Lead
Experience
12+ years
Closing date
Today
Source
iCIMS

Description

Responsibilities

**Position Is Contingent Upon Award**

Peraton Labs is hiring a Principal Information Security Consultant to be the senior technical authority and trusted advisor for secure architecture and engineering across the Covered California and CalHEERS environments. You will translate NIST SP 800-53 Rev. 5, ARC-AMPE, and IRS Publication 1075 requirements into practical technical designs and operating controls, and you will provide the senior technical review that our security deliverables pass through before they reach the client.

You will work with Covered California's security leadership, cloud and infrastructure engineers, application teams, and project delivery teams, alongside a small senior Peraton security team. The goal is to raise the real, measured security posture of a cloud-based health benefit exchange that processes PII, PHI, and federal tax information — not merely to document it.

What You Will Do In This Role:

  • Own secure architecture. Design and review secure architectures, technical designs, security patterns, and proposed solutions across cloud and on-premises environments; identify risks and recommend proportionate controls.
  • Translate controls into engineering. Interpret and apply NIST SP 800-53 Rev. 5 security and privacy controls, ARC-AMPE requirements, and IRS Publication 1075 safeguards as concrete technical configurations, hardening standards, and automated controls.
  • Lead security engineering across domains. Provide technical leadership for identity and access management, network security, endpoint security, cloud security, and application security, including CSP-native tooling and configuration review.
  • Direct vulnerability management technically. Own scanning strategy, risk-based prioritization, hardening baselines (CIS Benchmarks and DISA STIGs), and validation that remediation actually closed the exposure.
  • Evaluate and close control gaps. Assess controls, identify gaps and weaknesses, develop risk-based remediation strategies, and advise stakeholders on corrective action; support security authorization activities including CMS Authority to Connect readiness.
  • Provide senior technical QA and mentorship. Review security assessments, reports, policies, standards, and artifacts for technical accuracy and defensibility; mentor security professionals and provide technical leadership across multidisciplinary initiatives.
  • Advise on incident response and detection. Support investigation, evidence handling, escalation, reporting, and post-incident analysis; support threat detection, log monitoring, third-party risk assessment, data protection, and security control automation; participate in the on-call incident response rotation.

Qualifications

Required:

  • Minimum of 12 years experience with BS/BA; Minimum of 10 years with MS/MA. Degree in computer science, engineering, or cybersecurity. An additional 4 years of experience may be considered in lieu of a degree.
  • Progressively responsible cybersecurity experience, with significant depth in enterprise security control frameworks and complex regulated environments.
  • Active CISSP certification.
  • Demonstrated experience interpreting and applying NIST SP 800-53 Rev. 5 security and privacy controls within a complex enterprise environment, and translating regulatory control requirements into engineering solutions.
  • Hands-on security architecture and engineering experience across cloud (AWS, Azure, or GCP) and on-premises environments, including identity and access management, network security, endpoint security, and application security.
  • Hands-on experience with enterprise vulnerability management tooling (for example Tenable or Qualys) and with hardening standards such as CIS Benchmarks or DISA STIGs.
  • Demonstrated ability to communicate complex cybersecurity risk to both technical and executive audiences, and executive-grade technical writing ability.
  • US Citizenship and the abillity to pass a California criminal background clearance (Gov. Code §1043 / 10 CCR §6456) before starting work or accessing any confidential information, PII, PHI, federal tax information, or financial information.

Desired:

  • CCSP, or a cloud security specialty certification: AWS Certified Security – Specialty, Microsoft Azure SC-100, or Google Professional Cloud Security Engineer.
  • CISM, CRISC, CGRC, or GSLC.
  • Experience with ARC-AMPE security and privacy requirements.
  • Experience with IRS Publication 1075 and FTI-bearing environments.
  • Experience with CMS security requirements and the Authority to Connect (ATC) process.
  • Experience with zero-trust architecture, encryption and key management design, and security control automation.
  • Experience securing or assessing healthcare eligibility and enrollment, Medicaid, or health benefit exchange systems, and large California state government IT or cyber environments.
  • Experience supporting independent assessments and developing or reviewing Security Assessment Reports, CMS Security Assessment Workbooks (SAWs), and POA&Ms.

Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

Target Salary Range

$135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Skills

AWSAzureGCPCybersecurityTechnical WritingAWS CertifiedCISSP

Similar Jobs

24

Sr. Principal Information Security Engineer (ISSO)

Clarity Innovations · Columbia, MD; Herndon, VA +2

2 weeks ago

Principal Information Security Engineer

AJ Bell · Manchester or London / Hybrid, United Kingdom · Hybrid

3 weeks ago

Principal Information Security Engineer

Clarity Innovations · Fort Meade, MD +1

3 weeks ago

Principal Information Security Engineer - Cyber Ops

Svb · IND - KA - Bangalore - Outer Ring Road, India · Hybrid

1 month ago

Principal Information Security Analyst

Providence Health & Services · Renton, WA, United States, US · Onsite

1 month ago

Principal Information Security Engineer (supporting Naval Research Lab)

ASRC Federal · Welcome, MD 20693, USA

1 month ago

Principal Information Security Architect - Data Security

Highmarkhealth · PA, Working at Home - Pennsylvania, United States of America +50 · Remote

1 month ago

Principal Information Security Engineer - Blockchain Technology

Mastercard · Dublin, Ireland

1 month ago

Principal Information Security Engineer

Sentilink · United States · Remote

2 months ago

Principal Information Security Engineer

Reyes Holdings Our Culture · Rosemont, IL, US

1+ year ago

Information Security Cybersecurity Principal

Multicare · Working Virtually, United States of America · Remote

4 days ago

Principal Information System Security Engineer (ISSE)

Redhorse · Chantilly, VA · Onsite

4 days ago

Principal Information Systems Security Engineer (ISSE)

KBR Careers · USA, Beavercreek, 2647 Commons Boulevard, Ohio, United States of America

2 weeks ago

Senior Principal Information System Security Officer - Big Data

Clarity Innovations · Herndon, VA; Columbia, MD +2

2 weeks ago

Principal Business Information Security Officer

Quickenloans · Seattle - Hill7, United States of America

1 month ago

Principal Technical Information Security Specialist

Cae · Montreal - 8585 Cote-De-Liesse, QC, Canada

1 month ago

Principal Information Systems Security Engineer

Leidos · 5946 Undisclosed MD Customer Site 21090, United States of America

1 month ago

Principal Business Information Security Officer (BISO)

Lplfinancial · Fort Mill/Charlotte, United States of America +1

2 months ago

Principal Information Systems Security Engineer

Leidos · 5946 Undisclosed MD Customer Site 21090, United States of America

5 months ago

Information Security Architect - Principal, Application Security

Deluxe · Chennai-TN-IND, India

5 months ago

Principal Expert Information Security Officer (m/w/d) | HCP

Atruvia · Karlsruhe, Deutschland · Hybrid

7 months ago

Principal Information Systems Security Engineer

Fuse Engineering Llc · Annapolis Junction, MD

1+ year ago

Cyber Security Engineer - Information Systems Security Engineer (ISSE) - Senior Principal

Modern Technology Solutions Inc · Wright-Patterson AFB, OH,US, US +1

1 month ago

(USA) Principal, Systems and Infrastructure Engineer, Information Security

Walmart · (USA) VIZIO SERVICES DENVER CO DENVER Home Office, United States of America

6 months ago