Jobs and Careers
PE

Security Control Assessor

Peraton
Alexandria, Egyptfull_timeVerifiedPosted 5 Aug 2026
💰 $234,000/yr($146,000/yr$234,000/yr)

About the role

<h2>Responsibilities</h2> <p>Peraton seeks a <strong>Cloud Security Control Assessor</strong> to support the Army Cyber Command (ARCYBER).   Location:  Alexandria, VA/Metro Park near Fort Belvoir, VA.</p> <p> </p> <p>Tasks include:</p> <ul> <li>Conduct assessments and facilitate risk mitigation planning</li> <li>Provide Assessment and Authorization (A&amp;A) for the ARCYBER cloud infrastructure</li> <li>Execute a security control assessment plan and update the System Security Plan</li> <li>Review vulnerability scans and remediation</li> <li>Implement risk management programs by utilizing NIST, FISMA, HIPAA, and PII -- and document solutions</li> <li>Monitor the privacy landscape regarding all data (privacy, protection, classification, and residency)</li> <li>Assist clients with identifying gaps within existing privacy programs and designing solutions to help address those challenges</li> <li>Scan, test, and validate systems/networks/applications to obtain/maintain an ATO under NIST/FISMA guidelines</li> </ul> <h2>Qualifications</h2> <p><strong>Required:</strong></p> <ul> <li>Minimum experience of 12 years with BS/BA; Minimum of 10 years with MS/MA; Minimum of 7 years with Ph.D. Will consider HS+16 or Associates +14.</li> <li>Must have current IAM level III certification (such as CISM)</li> <li>Must have knowledge of enterprise solutions across multiple cloud operating environments (JWICS, SIPRNET, NIPRNET, and commercial Internet)</li> <li>Must have eMASS, ACAS, and ISC2 Certified Cloud Computing Professional (CCSP) or CompTIA Cloud+ experience</li> <li>Must have knowledge in the following areas: <ul> <li>Knowledge of computer networking and/or cloud computing concepts and protocols, and network security methodologies</li> <li>Knowledge of cyber threats and vulnerabilities in a virtualized environment.</li> <li>Knowledge of cybersecurity principles</li> <li>Knowledge of national and international laws, regulations, policies, and ethics as they relate to cybersecurity</li> <li>Knowledge of risk management framework processes (e.g., methods for assessing and mitigating risk)</li> <li>Knowledge of specific operational impacts of cybersecurity lapses</li> <li>Knowledge of industry methods for evaluating, implementing, and disseminating Information Technology (IT) security assessment, monitoring, detection, and remediation tools and procedures using standards-based concepts and capabilities</li> <li>Knowledge of cyber defense and vulnerability assessment tools, including opensource tools, and their capabilities</li> <li>Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)</li> <li>Knowledge of cybersecurity principles used to manage risks related to the use, processing, storage, and transmission of information or data in a cloud environment</li> <li>Knowledge of IT and cloud computing security principles and methods (e.g., firewalls, demilitarized zones, encryption)</li> <li>Knowledge of known vulnerabilities from alerts, advisories, errata, and bulletins</li> <li>Knowledge of network and/or cloud computing environment security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth)</li> <li>Knowledge of organization's evaluation and validation requirements</li> <li>Knowledge of penetration testing principles, tools, and techniques</li> <li>Knowledge of relevant laws, policies, procedures, or governance related to critical infrastructure.</li> <li>Knowledge of Risk Management Framework (RMF) requirements</li> <li>Knowledge of system and application security threats and vulnerabilities (e.g., buffer overflow, mobile code, cross-site scripting, Procedural Language/Structured Query Language [PL/SQL] and injections, race conditions, covert channel, replay, return oriented attacks, malicious code)</li> <li>Knowledge of the Security Assessment and Authorization process</li> <li>Skill in determining how a security and/or cloud computing security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes</li> <li>Skill in discerning the protection needs (i.e., security controls) of information systems and networks and those relating to cloud computing</li> <li>Knowledge of IT supply chain security and risk management policies, requirements, and procedures</li> <li>Knowledge of local specialized system requirements (e.g., critical infrastructure systems that may not use standard IT) for safety, performance, and reliability</li> <li>Knowledge of new and emerging IT and cybersecurity technologies and/or those technologies specific to cloud computing</li> <li>Knowledge of organization's enterprise and/or cloud computing information security architecture system</li> <li>Knowledge of Personal Identifiable Information (PII) data security standards</li> <

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Peraton

View company profile →