Hiring.Camp

Information System Security Manager (ISSM)

Peraton

·

Yesterday

Salary
$135k – $216k
Location
, US
Workplace
Remote
Type
Full-time
Department
Security
Seniority
Manager
Education
Master
Closing date
Today
Source
iCIMS

Description

Responsibilities

**Position Is Contingent Upon Award**

Peraton Labs is hiring an Information System Security Manager (ISSM) to be the single point of contact to Covered California and the accountable owner of oversight, timely execution, and quality for every security service Peraton delivers to the California health benefit exchange and the CalHEERS eligibility and enrollment system. You will lead a small, senior, multi-disciplinary security team spanning governance and compliance, security architecture and engineering, incident response, third-party risk, technical security, monitoring, and data protection.

You will work directly with Covered California's CISO and Information Security Officer, technical and project teams, business stakeholders, and independent assessors. The goal is to keep a system that carries the personal, health, and financial information of millions of Californians measurably secure, continuously compliant with NIST SP 800-53 Rev. 5, ARC-AMPE, and IRS Publication 1075, and ready for CMS Authority to Connect review.

What You Will Do In This Role:

  • Lead the security team. Manage and coordinate the day-to-day activities of assigned information security personnel; provide leadership, mentoring, and direction, and own deliverable accuracy, consistency, and schedule adherence across all seven contracted service areas.
  • Serve as the primary client security liaison. Act as the single operational point of contact among contractor personnel, Covered California security leadership, technical teams, project teams, and business stakeholders, and deliver regular status, risk, and escalation reporting to security leadership.
  • Own the compliance and GRC engine. Manage security activities tied to NIST SP 800-53 Rev. 5 controls; coordinate development and review of security policies, procedures, standards, and plans; direct GRC activities and platforms; and maintain the risk register.
  • Drive risk down to closure. Oversee risk assessments, control reviews, gap analyses, and remediation; track weaknesses, findings, and Plans of Action and Milestones (POA&Ms) through verified closure.
  • Serve as backup incident manager. Support the incident response program in coordination with the client Information Security Officer, and coordinate investigations, evidence handling, communications, escalation, reporting, and post-incident review; participate in the on-call incident response rotation.
  • Coordinate technical and third-party security work. Guide security architecture and engineering reviews across cloud and on-premises environments and technical security work spanning network, endpoint, vulnerability management, identity and access management, cloud, and application security; manage vendor security due diligence, assessments, contract and control reviews, and monitoring.
  • Coordinate assessment and penetration testing logistics while preserving assessor independence. Provide evidence, scheduling, and remediation ownership for the annual independent assessment and penetration test cycle without directing or influencing the independent assessors' scope, judgments, or findings.

Qualifications

Required:

  • Bachelor's degree in cybersecurity, computer science, information systems, information technology, or engineering. In lieu of a degree, an equivalent combination of education, professional certification, and additional relevant experience will be considered.
  • 12+ years of progressively responsible cybersecurity experience, including managing security programs, teams, or major security workstreams. (Note: eight years is the absolute floor for equivalency consideration; the posted target is 12+.)
  • Active CISSP or CISM certification.
  • Demonstrated experience managing security activities against the NIST SP 800-53 Rev. 5 control set in a complex enterprise environment.
  • Demonstrated experience owning a risk register and managing POA&Ms, findings, and corrective action plans through closure, using an enterprise GRC platform or comparable control-tracking system.
  • Demonstrated ability to lead and mentor senior technical personnel while working collaboratively with client stakeholders, and to brief cybersecurity risk credibly to both technical and executive audiences in writing and in person.
  • US Citizenship and the abillity to pass a California criminal background clearance (Gov. Code §1043 / 10 CCR §6456) before starting work or accessing any confidential information, PII, PHI, federal tax information, or financial information.

Desired:

  • Master's degree in cybersecurity, computer science, information systems, or a related discipline.
  • PMP certification. CGRC, CRISC, or CCSP are also valued.
  • Hands-on experience with ARC-AMPE (ACA, Medicaid and Partner Entities) security and privacy requirements.
  • Experience with IRS Publication 1075 compliance and federal tax information (FTI) control management.
  • Experience with CMS cybersecurity requirements and the CMS Authority to Connect (ATC) process or comparable federal authorization processes.
  • Experience supporting healthcare eligibility and enrollment, Medicaid, or health insurance exchange systems of CalHEERS scale.
  • Experience supporting annual security and privacy assessments, including CMS Security Assessment Workbooks (SAWs), security assessment reports, POA&Ms, and control evidence packages.
  • Experience in California state government or comparable public-sector cybersecurity environments.

Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

Target Salary Range

$135,000 - $216,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Skills

CybersecurityPenetration TestingCompliancePMPCISSP

Similar Jobs

30

Information System Security Officer (ISSO) - Tucson, AZ

RTX · US-AZ-TUCSON-M05 ~ 1151 E Hermans Rd ~ BLDG M05 (External Site), United States of America · Onsite

Yesterday

STIP Information System Security Officer

JRAD · Stafford, VA

Yesterday

Information System Security Officer, Senior

AIS Careers · Client Site - Washington, D.C., United States of America · Onsite

2 days ago

Information System Security Officer

AIS Careers · Client Site - Washington, D.C., United States of America · Onsite

2 days ago

Information System Security Officer (ISSO) - Woburn, MA

RTX · US-MA-WOBURN-WB2 ~ 225 Presidential Way ~ GODDARD BLDG, United States of America · Onsite

2 days ago

Information System Security Officer (ISSO)

Caci · 999 REMOTE, United States of America · Remote

2 days ago

Senior Information System Security Officer

Caci · CNL SPRINGFIELD VA (TSA HQ), United States of America · Hybrid

2 days ago

NOSR - SISS2 -Specialist, Information System Security II (ATO/RMF Manager)

Pae · US-VA-Norfolk-5425 Robin Hood Rd (VA973), United States of America · Onsite

2 days ago

Information System Security Officer - Senior

Pae · US-VA-Warrenton-2 Shipmadilly (VA227), United States of America · Onsite

3 days ago

Information System Security Officer Senior (ISSO)

Pae · US-DC-Washington-8 1500 Penn (DC114), United States of America · Onsite

3 days ago

Senior Information System Security Officer (ISSO)

Tyto Athene · Washington, DC, US

3 days ago

Information System Security Officer III,

"Targeted Solutions, LLC" · Bedford, Massachusetts

3 days ago

Information System Security Officer (ISSO)

Asec Inc · Lemoore, CA · Onsite

3 days ago

Information System Security Officer III

Global Resource Solutions · Boston, MA

3 days ago

Information System Security Officer III

Global Resource Solutions · Boston, MA

3 days ago

Information System Security Officer

Radiancetech · Wright-Patt AFB, OH - NASIC FME, United States of America

4 days ago

Information System Security Officer (ISSO)

Leidos · 10493 Lorton VA, United States of America +1 · Remote, Onsite

4 days ago

Information System Security Manager (ISSM)

Leidos · 10493 Lorton VA, United States of America +1 · Remote, Onsite

4 days ago

Senior Information System Security Officer (ISSO)

ERP International · Laurel, MD, US

4 days ago

Information System Security Officer (ISSO) - Tucson, AZ

RTX · US-AZ-TUCSON-M05 ~ 1151 E Hermans Rd ~ BLDG M05 (External Site), United States of America · Onsite

4 days ago

Information System Security Manager (ISSM)

RTX · US-CA-ANAHEIM-406 ~ 160 N Riverview Dr ~ BLDG 406, Ste 150, United States of America · Onsite

4 days ago

Information System Security Engineer (ISSE)

Anavationllc · Huntsville, AL · Onsite

4 days ago

Principal Information System Security Engineer (ISSE)

Redhorse · Chantilly, VA · Onsite

4 days ago

Senior Information System Security Engineer

Redhorse · Chantilly, VA · Onsite

4 days ago

Information System Security Officer

Leidos · 2683 Huntsville AL, United States of America

1 week ago

Information System Security Officer

Leidos · 2682 Huntsville AL, United States of America · Remote, Onsite

1 week ago

Information System Security Manager

CNI Careers · SD Ellsworth AFB G Ellsworth 1000 Ste 1200, United States of America

1 week ago

Information System Security Officer

CNI Careers · SD Ellsworth AFB G Ellsworth 1000 Ste 1200, United States of America

1 week ago

Information System Security Manager

Caci · 448 FLORHAM PARK NJ, United States of America · Onsite

1 week ago

Senior Information System Security Officer (Senior ISSO) (R-00185)

True Zero Technologies · 100% Remote · Remote

1 week ago
Remote Information System Security Manager (ISSM) at Peraton • $135k – $216k | Hiring.Camp