Cyber Systems Engineer
Responsibilities
Peraton is actively seeking a Cybersecurity Engineer to support our Defense Mission and Health Solutions Sector on the Defense Travel System (DTS) program.
- Must be US Citizen and have active/current DoW Public Trust designation and Common Access Card or be able to obtain prior to starting.
- This is a remote opportunity, but you must reside in the U.S. to be considered.
- Hold current (non-expired) DoW 8140 approved Cybersecurity Certification: Security+ CE or CISSP.
The DTS Security Team is responsible for maintaining Authorization to Operate and compliance with DoW Cybersecurity requirements.
The successful candidate will:
- Perform cybersecurity requirements analysis and security systems engineering functions necessary to integrate new cybersecurity requirements and maintain DTS’s security posture
- Serve as a liaison to the DTS Program Management Office (PMO) and customer technical SMEs for cybersecurity tool compliance.
- Coordinate the integration of new cybersecurity requirements within DTS Program Teams
- Support program application security compliance efforts, including processing Fortify and Sonatype workflows in GitLab, and managing application POA&Ms in Fortify SSC for release approval
- Assist with automating STIG checklist compliance and remediation monitoring
- Utilize approved DoW AI resources to support enhanced analysis of audit log and vulnerability scan data, and automate compliance processes
Qualifications
Required Qualifications:
- Minimum of 12 years with BS/BA; Minimum of 10 years with MS/MA; Minimum of 7 years with Ph.D, 16 years with HS diploma.
- US Citizen
- Must have active Public Trust clearance
- Hold current (non-expired) DoW 8140 approved Cybersecurity Certification: Security+ CE or CISSP
- Excellent communication skills with a diverse technical background, ability to interface with senior technical staff in government and on the program
- Experience presenting status and compliance information to leadership
- Ability to manage positive cross-team relationships within DTS and the government
- Ability to assess and communicate potential risks to the program associated with new security requirements
- Minimum 5 years of experience performing Cybersecurity requirements analysis and Cybersecurity systems engineering in a DoW environment or similar
- Minimum 5 years of Linux systems administration experience
- Minimum 5 years of experience with Wireshark, tcpdump, packet captures, and ability to converse with Network Engineers regarding security compliance for network infrastructure (Firewalls, Load Balancers, IDS/IPS), WANs, LANs, VPNs, ports and protocols
- Minimum 5 years of experience integrating one or more of the following Cybersecurity tools into a DoW or similar operational environment: Trellix ESS, Tanium, ACAS, Nessus Network Monitor, Splunk
- Minimum 5 years of systems and network infrastructure vulnerability management experience using Nessus or ACAS
- Minimum of 5 years of experience analyzing application security vulnerabilities
- Minimum 5 years of experience with software development lifecycles, DevSecOps, and on-prem or cloud environments
- Minimum 5 years of experience completing and maintaining STIG checklists
- Basic understanding of how to read code, including Java, SQL, and shell scripts
- Background performing security requirements analysis, including translating customer security requirements to actionable program requirements
- Ability to quickly learn new technologies and processes
- Strong technical writing skills
- Experience supporting 24x7 operational environments
- Ability to support surges in workloads and meet deadlines as new compliance requirements are released by the customer
- Ability to work with minimal oversight and direction, motivated performer and ability to quickly re-prioritize tasks
- Ability to support a flexible work schedule which may include weekend and after-hours support of the operational environment
Preferred Qualifications:
- Experience complying with DoW Cybersecurity requirements for ZeroTrust, E-ICAM, and Web Application Firewalls
- Experience in a Cyber Incident Response role
- Experience processing JFHQ/DCDC OPORDs and TASKORDs
- Project management experience including history of maintaining project schedules, assigning tasks, and reporting status
- Experience with RMF/NIST SP-800-53, CMMC/NIST SP 800-171, and SSAE-18/SOC-1 compliance processes
- Knowledge of AI Cyber Attack methods and mitigations
Peraton Overview
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.