Cybersecurity / Compliance Engineer
Job Locations
US-VA-Chantilly
| Requisition ID |
2026-172158
|
Position Category |
Information Technology
|
Clearance |
Top Secret/SCI w/Poly
|
Responsibilities
We are seeking Cybersecurity / Compliance Engineers to implement and sustain security controls, authorization evidence, continuous monitoring, vulnerability management, software-security requirements, and common-control responsibilities across enterprise environments. These engineers will work closely with platform, cloud, DevSecOps, IAM, observability, and application teams to ensure security requirements are incorporated into engineering and operational processes. The role combines technical security engineering with Risk Management Framework (RMF), authorization, compliance, and continuous-monitoring activities.
Responsibilities
Risk Management & Authorization
Support RMF, security assessment, authorization, and continuous-monitoring activities for enterprise services and environments.
Maintain security evidence, control implementation information, Plan of Action and Milestones (POA&M) inputs, and authorization documentation. Assess and document security impacts associated with platform, infrastructure, application, and commercial or government-off-the-shelf software changes. Support common-control and inherited-control documentation and implementation activities where applicable. Coordinate with security, engineering, and operational stakeholders to address control gaps and authorization requirements.
Technical Security Engineering
Define and review security requirements for cloud, Kubernetes, CI/CD, identity, network, and application services. Integrate security validation and evidence collection into engineering and software-delivery workflows. Support vulnerability scanning, vulnerability triage, remediation tracking, and risk-acceptance processes. Support implementation of Zero Trust, RBAC/ABAC, encryption, secrets management, logging, and workload-security requirements. Evaluate technical implementations against established security requirements and identify potential risks or control deficiencies. Collaborate with engineering teams to develop practical approaches for implementing and sustaining security controls.
Software & Supply-Chain Security
Support security reviews of COTS, GOTS, FOSS, software artifacts, containers, and third-party dependencies. Coordinate security evidence and documentation requirements associated with software and infrastructure changes. Support software supply-chain security, artifact integrity, provenance, and dependency-management practices. Partner with DevSecOps and engineering teams to integrate security controls into development and delivery processes. Identify security risks associated with software components and recommend appropriate mitigation or remediation actions.
Continuous Monitoring & Compliance
Support continuous security monitoring and assessment activities. Track security findings, vulnerabilities, control deficiencies, and remediation activities. Maintain accurate security documentation, evidence repositories, and compliance records. Support audits, assessments, inspections, and other security compliance activities. Monitor changes to enterprise systems and evaluate potential impacts to existing security controls and authorization requirements.
Location: This position is fully onsite in Chantilly, VA
Qualifications
Required Qualifications
Active TS/SCI clearance with CI Polygraph. Approximately 6-10 years of experience in cybersecurity, Information Systems Security Engineering (ISSE), RMF, security compliance, or security engineering. - 6 years of experience with a BS/BA, 9 years of experience may be considered in lieu of a degree.
Experience supporting RMF, security authorization, and continuous-monitoring activities. Experience implementing, assessing, or documenting technical security controls. Working knowledge of cloud security, DevSecOps, identity and access management, network security, and vulnerability management concepts. Experience developing authorization packages, security evidence, assessment documentation, or continuous-monitoring artifacts. Strong technical writing, documentation, and communication skills.
Desired Qualifications
Experience with one or more of the following:
Continuous authorization or cATO practices. Cloud security services, including AWS security services. Kubernetes security. Software supply-chain security. Security automation and automated evidence collection. Security compliance within classified or highly regulated environments. ServiceNow or comparable security/RMF workflow platforms. Experience supporting large-scale enterprise security authorization programs.
Peraton Overview
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can't be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we're keeping people around the world safe and secure.
Target Salary Range
$112,000 - $179,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual's experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.
EEO
EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.
|