> Markdown version of [/jobs/ext/1556113-information-assurance-and-security-lead-associate](https://www.wearedevelopers.com/jobs/ext/1556113-information-assurance-and-security-lead-associate). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance and Security, Lead Associate - **Company:** Peraton Inc - **Location:** United States - **Experience:** Expert - **Salary:** $86,000.0 - $138,000.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Health Informatics, CompTIA Security+, Scrum Methodology, Security Information and Event Management, Data Streaming, Systems Architecture, Systems Integration, Software Vulnerability Management, Security Orchestration, Automation & Response, Plan of Action and Milestones, Vulnerability Analysis - **Published:** July 3, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9010515/information-assurance-and-security-lead-associate ## About the Role * 5 years with BS/BA; 3 years with MS/MA * Demonstrated experience leading security analysis, compliance, and risk management activities for large-scale Federal programs. * Strong understanding of Federal information security standards and frameworks such as FISMA, NIST SP 80053, NIST RMF, and CMS ARS. * Hands-on experience conducting or managing vulnerability assessments, security scanning, POA&M lifecycle management, and risk mitigation planning. * Experience preparing for and supporting Federal security audits, assessments, and ATO activities. * Ability to review system designs, data flows, and architecture diagrams for security considerations and compliance alignment. * Experience working directly with Agile teams and integrating security requirements into Agile SDLC processes. * Excellent written and verbal communication skills, with the ability to communicate with both technical and nontechnical stakeholders. * US. Citizenship required. * Must have the ability to obtain and maintain a Public Trust clearance. * Must reside near or be able to work in alignment with the program's hybrid work expectations., * Experience supporting CMS programs, including familiarity with CMS ARS, ATO processes, and CMS governance expectations. * Relevant security certifications such as CISSP, CISM, Security+, CEH, or equivalent. * Experience with vulnerability management platforms, SIEM tools, and security automation technologies. * Prior experience in healthcare IT and knowledge of compliance requirements such as HIPAA. * Experience integrating or modernizing systems in environments with legacy system dependencies. * Experience supporting large-scale, multi-team modernization or transformation initiatives. ## Description Peraton is seeking a Lead Security Analyst to join our team of qualified, diverse professionals supporting the Health State and Local Sector. The ideal candidate will lead security analysis, compliance oversight, and risk management efforts across a complex, mission critical environment. This role plays a pivotal part in ensuring secure and compliant solutions, guiding vulnerability management activities, and supporting major modernization efforts for the Centers for Medicare & Medicaid Services (CMS). The Lead Security Analyst will help shape and maintain a robust security posture, ensuring that all program capabilities adhere to CMS and Federal security standards. Lead Security Analyst's responsibilities shall include, but are not limited to: * Leading all security analysis, compliance, and oversight activities for the Program. * Conducting comprehensive security assessments, including evaluation of system architecture, data flows, interfaces, and inherited controls. * Developing, maintaining, and enforcing program-wide security policies, procedures, and documentation consistent with Federal and CMS security requirements. * Managing the program's vulnerability assessment program, including vulnerability scanning, analysis, reporting, and coordination of remediation activities. * Leading the development of risk mitigation strategies and providing recommendations to address findings from scans, assessments, POA&Ms, and audits. * Preparing and supporting all security audits, reviews, and checkpoints, including CMS security assessments, FISMA reviews, and relevant ATO activities. * Ensuring security requirements are integrated into Agile development workflows, providing direct guidance to Scrum teams, architects, and developers. * Reviewing technical designs, user stories, and system enhancements for security impacts and compliance alignment. * Monitoring regulatory and CMS security updates to ensure program compliance remains current and accurate. * Collaborating with cross functional stakeholders including engineering, operations, compliance, and program leadership to ensure secure-by-design solution delivery. * Developing and delivering security awareness and compliance training tailored to the Program needs. * Maintaining accurate and up-to-date security documentation, dashboards, and metrics reporting for program leadership. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [ShapeShift: Reinventing Agile for a B2B SaaS Scale-Up](https://www.wearedevelopers.com/videos/1655-shapeshift-reinventing-agile-for-a-b2b-saas-scale-up) - [Python-Based Data Streaming Pipelines Within Minutes](https://www.wearedevelopers.com/videos/1233-python-based-data-streaming-pipelines-within-minutes) - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [From Punch Cards to AI-assisted Development](https://www.wearedevelopers.com/videos/611-from-punch-cards-to-ai-assisted-development) - [Why and when should we consider Stream Processing frameworks in our solutions](https://www.wearedevelopers.com/videos/1085-why-and-when-should-we-consider-stream-processing-frameworks-in-our-solutions) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers)