> Markdown version of [/jobs/ext/2081870-software-development-lead-associate](https://www.wearedevelopers.com/jobs/ext/2081870-software-development-lead-associate). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Software Development, Lead Associate - **Company:** Peraton Inc - **Location:** Herndon, VA, United States - **Experience:** Expert - **Salary:** $66,000.0 - $106,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Amazon Web Services, Systems Engineering, Microsoft Azure, Cloud Computing Security, Cloud Engineering, CompTIA Security+, Cyber Security, Information Systems, Continuous Integration, DevOps, Github, Information Security Management, Scrum Methodology, Ansible, Security Information and Event Management, Software Engineering, Systems Integration, Software Vulnerability Management, SARS Software Products, Software Security, Gitlab, Kubernetes, Infrastructure Automation Frameworks, Information Technology, Deployment Automation, Terraform, Splunk, Devsecops, Docker, Legacy Systems, Jenkins, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 16, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88056638/1 ## About the Role Qualifications (Required): * Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, or related field; additional experience may be substituted in lieu of degree. * 5 to 7 years of experience in cybersecurity, DevSecOps, or system engineering roles supporting federal programs. * Experience acting as an ISSO or security engineer for a FISMA Moderate or FedRAMP Moderate system. * Hands-on experience preparing security authorization documentation such as SSPs, SARs, POA&Ms, and Continuous Monitoring updates. * Strong understanding of NIST 80053 security controls, Risk Management Framework (RMF), CMS ARS 5.1, and continuous monitoring requirements. * Practical experience supporting or integrating security processes in DevSecOps pipelines, CI/CD workflows, or automated deployment environments. * Experience with vulnerability management tools and processes, including scanning, analysis, and remediation tracking. * Ability to support audits and communicate effectively with assessment teams, program stakeholders, and government security representatives. * U.S. citizenship and the ability to obtain and maintain a public trust or equivalent clearance. Qualifications (Preferred): * Experience supporting CMS programs or other HHS components. * Familiarity with FedRAMP documentation, cloud boundary definitions, and cloud-native security practices. * Experience with AWS or Azure security services, cloud configuration baselines, and cloud compliance frameworks. * Working knowledge of tools commonly used within Peraton and similar enterprises, such as GitLab/GitHub CI/CD, Jenkins, Terraform, Ansible, Tenable, Splunk, or similar platforms. * Security certifications such as Security+, CISSP, CISM, CCSP, or AWS/Azure security certifications. * Experience integrating legacy systems into modern cloud or hybrid architectures with secure migration practices. * Knowledge of container security (Docker, Kubernetes) and infrastructure-as-code security scanning. ## Description Peraton is seeking a Mid-level DevSecOps Engineer to join our team of qualified, diverse professionals. In this role, you will support the security, reliability, and compliance of missioncritical systems within the DME Program. The ideal candidate will play a key part in integrating security throughout the development lifecycle, maintaining adherence to federal cybersecurity standards, and ensuring the operational readiness of modernized systems at the Centers for Medicare & Medicaid Services (CMS). This position supports a highly visible environment where strong technical execution, security rigor, and crossteam collaboration are essential., Serve as the Information System Security Officer (ISSO) for the ClaimsCore Program, ensuring full compliance with FISMA Moderate, FedRAMP Moderate, and CMS ARS 5.1 security requirements. * Prepare, maintain, and update all Certification and Accreditation (C&A) and Security Assessment and Authorization (SA&A) documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Contingency Plans, and Plan of Action and Milestones (POA&Ms). * Conduct and document ongoing risk assessments, vulnerability assessments, and security control evaluations across the program's cloud and onpremises environments. * Manage and coordinate the Authority to Operate (ATO) lifecycle, including initial authorization, continuous monitoring, control implementation reviews, and audit preparation. * Ensure zero open Critical or High vulnerabilities at system go-live and maintain compliance with vulnerability remediation SLAs. * Respond to and manage security incident notifications within required timelines (1 hour for initial reporting). Coordinate with internal security teams and external stakeholders to support incident response processes. * Support internal and external audits, including CSRAP, CFO, OMB A123, and annual security assessments. * Collaborate with DevOps, engineering, and operations teams to integrate security best practices into CI/CD pipelines, infrastructure-as-code, and deployment processes. * Monitor and enhance security posture using tools such as vulnerability scanners, SIEM platforms, configuration management tools, and compliance automation platforms. * Contribute to continuous improvement of security procedures, engineering practices, and system hardening baselines. * Assist in the implementation and maintenance of cloud security configurations aligned with agency and program requirements. * Provide security guidance during architecture reviews, design sessions, sprint planning, and change control processes. * Ensure security documentation, diagrams, inventories, and boundary definitions are accurate and up to date. ## Related Videos - [WeAreDevelopers LIVE - Modern DevOps for IoT Devices and More](https://www.wearedevelopers.com/videos/1805-wearedevelopers-live-modern-devops-for-iot-devices-and-more) - [Docker Compose: Rediscovered](https://www.wearedevelopers.com/videos/1978-docker-compose-rediscovered) - [Innovating Developer Tools with AI: Insights from GitHub Next](https://www.wearedevelopers.com/videos/1268-innovating-developer-tools-with-ai-insights-from-github-next) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enabling automated 1-click customer deployments with built-in quality and security](https://www.wearedevelopers.com/videos/83-enabling-automated-1-click-customer-deployments-with-built-in-quality-and-security) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)