> Markdown version of [/jobs/ext/3600681-information-assurance-and-security-advisor](https://www.wearedevelopers.com/jobs/ext/3600681-information-assurance-and-security-advisor). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Assurance and Security, Advisor - **Company:** Peraton Inc - **Location:** Colorado Springs, CO, United States (Remote available) - **Experience:** Expert - **Salary:** $104,000.0 - $166,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Cloud Computing Security, Data Retention, Data Flow Control, Identity and Access Management, Cisco Nexus Switches, Role-Based Access Control, Software Vulnerability Management, Data Logging, Okta, Large Language Models, Snowflake, Agentic-AI, Data Management, Splunk, Plan of Action and Milestones, Databricks - **Published:** October 7, 2026 - **Apply:** https://www.builtincolorado.com/job/information-assurance-and-security-advisor/11536078?handler=ApplyRedirect ## About the Role * Minimum of 8 years with BS/BA; Minimum of 6 years with MS/MA; Minimum of 3 years with PhD * Experience leading compliance work on Federal (ideally, CMS) systems. * Deep working knowledge of CMS (or other Federal agencies) security frameworks: CFACTS, CSRAP, and the ATO lifecycle (SSP, SAR, POA&M, contingency plan, PIA/SORN). * Practical experience with FISMA / NIST SP 800-53 control tailoring, inheritance from cloud providers (AWS FedRAMP baselines), and boundary definition. * Experience assessing third-party/vendor security posture: SOC 2, FedRAMP, HIPAA/HITRUST, penetration-test evidence, vulnerability management. * Familiarity with cloud-native security in AWS (IAM, KMS, GuardDuty, CloudTrail, Config), Okta SSO/RBAC, and audit-log routing to CloudWatch/Splunk. * Working knowledge of HIPAA PHI handling and Federal PII requirements, especially for Medicare/Medicaid claims data. * Ability to author security artifacts and briefings for CMS-level review; clear technical writing required. * US citizenship; ability to obtain and maintain a Public Trust clearance. Preferred Qualifications: * CISSP, CISM, CAP, CISA, or equivalent certification. * Prior compliance work on the FPS ATO or another CMS ATO'd system (e.g., IDR, One PI, UCM). * Familiarity with security considerations specific to LLM and agentic AI systems (model-provider data retention, prompt logging, MCP tool authorization, RBAC for LLM outputs). * Experience defining vendor-isolated enclaves inside a Federal customer's authorization boundary. * Familiarity with SAFe Agile compliance patterns (continuous ATO / RMF automation). * Experience with Databricks and Snowflake governance controls (Unity Catalog, dynamic masking, row/column access policies). ## Description Leads regulatory and security compliance for evaluating agentic AI vendors within a CMS Fraud Prevention Services authorization boundary. Assesses vendor security postures, authors control inheritance, boundary, data-flow, SSP, POA&M, PIA/SORN, and compliance artifacts, and coordinates with CMS security stakeholders. Advises on AI-specific risks involving data retention, prompt logging, PHI, tool authorization, and RBAC. Requires extensive federal compliance experience, AWS security knowledge, HIPAA/FISMA expertise, and the ability to obtain Public Trust clearance. The summary above was generated by AI, We are seeking a Regulatory and Compliance Lead on the CMS Fraud Prevention Services (FPS) Team, as a compliance authority for the agentic AI vendor evaluation, producing the regulatory-and-compliance portion of the vendor-list assessment and authoring the security inputs to the Proof of Concept (POC) Solution proposal. The Lead ensures every security-related activity, POC data path, and vendor artifact remain within the FPS ATO boundary and comply with CFACTS, CSRAP, FISMA, and HIPAA PHI requirements., * Assess each candidate agentic AI vendor against CMS security posture, data-handling, and ATO requirements as part of the vendor-list assessment. * Author the security-and-compliance inputs to the POC Solution proposal: control inheritance, boundary definition, data-flow diagrams, and the compliance narrative for the vendor-isolated exclusive environment. * Coordinate with the FPS ISSO/ISSM and CMS security stakeholders to keep AI tool assessment and POC activity inside the FPS ATO boundary. * Own compliance artifacts and cadence (SSP inputs, POA&M entries, PIA/SORN as applicable) for the AI vendor-evaluation effort. * Serve as the single point of contact for security-and-compliance questions raised by third-party vendors, CMS, or the Peraton PM. * Advise the Lead AI Solutions Architect on LLM/agentic-AI-specific compliance concerns (model-provider data retention, prompt/response logging, PHI-in-prompt controls, tool authorization).