21 hours ago
Base Salary
$104k - $166k/yr
Responsibilities
- Design and implement security architecture for AWS workloads aligned with FedRAMP Moderate controls.
- Build and maintain AWS security guardrails using IAM, GuardDuty, Security Hub, Config, CloudTrail, KMS, WAF, Macie, and Inspector.
- Implement Infrastructure as Code security controls using Terraform or CloudFormation, including policy as code.
- Support System Security Plans, ATO activities, POA&M remediation, continuous monitoring, and federal assessments.
- Manage vulnerability scanning, patch-management tracking, centralized logging, SIEM integration, and audit-trail retention.
- Implement least-privilege IAM, service control policies, cross-account access, encryption, and FIPS-aligned controls.
- Respond to security incidents, perform root-cause analysis, and support cloud incident-response playbooks.
- Collaborate with DevOps and platform teams to embed security into CI/CD pipelines.
- Maintain control documentation, architecture diagrams, audit evidence, boundary definitions, and system categorization artifacts.
Requirements
- US citizenship and the ability to obtain and maintain a Top Secret-eligible clearance are required.
- At least 8 years of work experience with a BS/BA in computer science, or 10 years with an AA/AS in Information Systems or a related field, or equivalent experience.
- At least 5 years of hands-on AWS engineering experience, including 3 or more years in cloud security roles.
- Experience with FedRAMP, DoD IL4/IL5, or an equivalent federal compliance environment, including SSP and RMF processes.
- Hands-on experience with AWS security services, federal AWS environments, IAM, GuardDuty, Security Hub, AWS Config, CloudTrail, KMS, WAF, Macie, Inspector, and Systems Manager.
- Understanding of NIST SP 800-53 Rev. 5 control families and experience mapping implementations to controls.
- At least 3 years of Infrastructure as Code experience with Terraform and/or CloudFormation, including security scanning and policy-as-code tools.
- Knowledge of VPC design, security groups, NACLs, PrivateLink, Transit Gateway, network segmentation, vulnerability management, Zero Trust Architecture, and SIEM or log aggregation.
- Scripting ability in Python or Bash and understanding of FIPS 140-2/140-3 and TLS 1.2+ requirements.
- One of AWS Certified Security – Specialty, AWS Certified Solutions Architect – Professional with a security focus, CISSP, CISM, or Security+ with strong AWS experience is required.
- Preferred qualifications include container security, AWS Control Tower, multi-account governance, continuous ATO evidence automation, hybrid or multi-cloud architecture, Azure, Microsoft .NET, AI security, and federal or national-security mission experience.
Benefits
- 100% remote position.
- Target base salary range of $104,000 to $166,000, with possible eligibility for overtime, shift differential, and discretionary bonus.
About Peraton
Peraton builds and integrates mission systems, cyber, space, and intelligence solutions for U.S. defense, intelligence, and civil agencies. It delivers enterprise IT, satellite and terrestrial communications, and spectrum management under government contracts. Founded in 2017, the company is headquartered in Reston, Virginia and is privately held by Veritas Capital.
