Peraton is seeking a Mid‑level Dev Sec Ops Engineer to join our team of qualified, diverse professionals. In this role, you will support the security, reliability, and compliance of mission‑critical systems within the DME Program. The ideal candidate will play a key part in integrating security throughout the development lifecycle, maintaining adherence to federal cybersecurity standards, and ensuring the operational readiness of modernized systems at the Centers for Medicare & Medicaid Services (CMS). This position supports a highly visible environment where strong technical execution, security rigor, and cross‑team collaboration are essential.
Responsibilities: Serve as the Information System Security Officer (ISSO) for the Claims Core Program, ensuring full compliance with FISMA Moderate, Fed RAMP Moderate, and CMS ARS 5.1 security requirements. Prepare, maintain, and update all Certification and Accreditation (C&A) and Security Assessment and Authorization (SA&A) documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Contingency Plans, and Plan of Action and Milestones (POA&Ms). Conduct and document ongoing risk assessments, vulnerability assessments, and security control evaluations across the program’s cloud and on‑premises environments. Manage and coordinate the Authority to Operate (ATO) lifecycle, including initial authorization, continuous monitoring, control implementation reviews, and audit preparation. Ensure zero open Critical or High vulnerabilities at system go‑live and maintain compliance with vulnerability remediation SLAs. Respond to and manage security incident notifications within required timelines (1 hour for initial reporting). Coordinate with internal security teams and external stakeholders to support incident response processes. Support internal and external audits, including CSRAP, CFO, OMB A‑123, and annual security assessments. Collaborate with Dev Ops, engineering, and operations teams to integrate security best practices into CI/CD pipelines, infrastructure‑as‑code, and deployment processes. Monitor and enhance security posture using tools such as vulnerability scanners, SIEM platforms, configuration management tools, and compliance automation platforms. Contribute to continuous improvement of security procedures, engineering practices, and system hardening baselines. Assist in the implementation and maintenance of cloud security configurations aligned with agency and program requirements. Provide security guidance during architecture reviews, design sessions, sprint planning, and change control processes. Ensure security documentation, diagrams, inventories, and boundary definitions are accurate and up to date. #J-18808-LjbffrBy continuing you agree to our Terms & Privacy Policy.