> Markdown version of [/jobs/ext/1363986-information-assurance-and-security-engineer](https://www.wearedevelopers.com/jobs/ext/1363986-information-assurance-and-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance and Security Engineer - **Company:** Peraton Inc - **Location:** United States - **Experience:** Expert - **Salary:** $86,000.0 - $138,000.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Microsoft Azure, Cloud Computing Security, CompTIA Security+, Cyber Security, System Configuration, Github, Information Security Management, Network Security, Automation of Marketing, Network Segmentation, Scrum Methodology, Role-Based Access Control, Azure Active Directory, Cloud Services, Azure DevOps Pipelines, Zero Trust Network Access, Software Engineering, Nessus, Devsecops, Security Orchestration, Automation & Response, Key Vault, Vulnerability Analysis - **Published:** July 21, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9042520/information-assurance-and-security-engineer ## About the Role * Bachelors degree and 5 years of experience, or an Associates degree and 7 year of experience or a High School diploma/equivalent and 9 years of experience. * Must be a U.S. Citizen with the ability to obtain and maintain a DHS Public Trust clearance. * Demonstrated experience performing Information System Security Officer (ISSO) duties in a Federal or regulated environment, including creating and maintaining RMF documentation, SSPs, POA&Ms, security test plans, and continuous monitoring artifacts. * Proven experience supporting software development teams delivering Azure-based cloud solutions, including familiarity with Azure AD, App Services, Key Vault, App Gateway/WAF, and cloud-native security controls. * Hands-on experience identifying, tracking, and managing security vulnerabilities, including interpreting scan results (e.g., Tenable/Nessus, Microsoft Defender) and working with engineering teams on mitigation strategies. * Strong understanding of NIST 800-53, 800-30, 800-37, and 800-171 frameworks. * Active CISSP certification, or the ability to obtain within 6 months of hire. * Strong communication skills, including developing briefing materials, presenting technical concepts to nontechnical stakeholders, and supporting customer engagements., * Working knowledge of DHS security policies, controls, and compliance requirements, including DHS 4300A/B, 4300A Sensitive System Handbook, and associated RMF processes. * Knowledge of Azure security architecture patterns such as Zero Trust, RBAC, network segmentation, PIM/PIM, and least-privilege design. * Strong understanding of Agile methodologies and successful collaboration within cross-functional Agile teams, including participation in sprint planning, backlog refinement, and security-focused reviews. * Experience with security automation and DevSecOps workflows (e.g., GitHub Actions, Azure DevOps pipelines, IaC security scanning). * Experience implementing Continuous Monitoring plans, dashboards, and automated control reporting. * Additional security certifications such as ISC2 CAP, ISC2 CCSP, CompTIA Security+, or Azure Security Engineer Associate (AZ-500). ## Description Peraton is seeking a seasoned Information Assurance and Security Engineer to serve as an Information System Security Officer (ISSO) for a cloud-hosted, Azure-based system. The ideal candidate brings deep security expertise, strong stakeholder communication skills, and hands-on experience supporting Agile software development teams delivering mission critical solutions within DHS or other Federal environments. This position is remote. Day to Day Roles and Responsibilities: * Provide technical and programmatic information assurance support to internal and external customers for network and information security systems. * Design, develop, and implement security requirements across enterprise and program-level business processes. * Prepare documentation and security artifacts based on customer input and industry standard guidelines (e.g., NIST RMF, DHS 4300A). Lead certification and accreditation activities for the program. * Develop and maintain security test and evaluation plans and contingency plans. * Conduct risk and vulnerability assessments and prepare formal reports and recommendations. * Analyze existing policies and procedures for compliance with Federal laws, regulations, and standards; recommend remediation strategies to close security gaps. * Recommend system enhancements to address identified deficiencies and improve the overall security posture. * Design, test, and integrate computer and network security tools; secure system configurations and ensure compliant deployments. * Perform system scans, interpret results, and support system administrators in resolving findings. * Conduct internal security program audits and develop mitigation strategies to address identified risks. * Provide technical guidance for secure architecture design supporting evolving mission needs. * Support security incident investigations, root-cause analysis, and response. * Perform vulnerability assessments and develop, document, and track corrective action plans. ## Related Videos - [Best Practices for Using GitHub Secrets](https://www.wearedevelopers.com/videos/1214-best-practices-for-using-github-secrets) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Develop enterprise-ready applications for Microsoft Teams with Azure resources on modern web technologies](https://www.wearedevelopers.com/videos/187-develop-enterprise-ready-applications-for-microsoft-teams-with-azure-resources-on-modern-web-technologies) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Bringing AI Model Testing and Prompt Management to Your Codebase with GitHub Models](https://www.wearedevelopers.com/videos/1536-bringing-ai-model-testing-and-prompt-management-to-your-codebase-with-github-models) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)