Information System Security Engineer (ISSE)
Job Description
Benefits and culture
Peraton supports a comprehensive package designed to protect your wellbeing and long-term success. Eligible employees gain medical, dental, and vision coverage along with life insurance and a health savings account. The role also includes short and long term disability, access to an employee assistance program, parental leave, a 401(k) plan, paid time off for vacation, and company paid holidays. This is an on-site position at our Annapolis Junction, MD location, with a collaborative environment focused on protecting critical DoD systems and advancing secure architectures.
About the role
The Information System Security Engineer (ISSE) will operate on-site supporting DoD and NIST-aligned security architecture, vulnerability management, incident response, and accreditation across the system development lifecycle. The role emphasizes hands-on security engineering, integration of security controls across Windows and Linux environments, cloud and virtualization platforms, and containerized applications, with a focus on continuous monitoring and ongoing authorization programs.
Responsibilities
- Design and maintain an enterprise security architecture aligned with NIST RMF, DoD STIGs, CIS benchmarks, and internal policies.
- Lead vulnerability management using Tenable Nessus, ACAS, and Qualys to identify, assess, and remediate findings.
- Incorporate cybersecurity requirements into Windows and Linux servers, cloud environments, virtualization, and containerized apps.
- Support incident response and forensics by examining security logs, SIEM alerts, network traffic, and endpoint telemetry with Splunk Enterprise.
- Develop automation scripts in PowerShell, Bash, and Python to streamline remediation, auditing, reporting, and monitoring tasks.
- Collaborate with system administrators, network engineers, ISSOs, and application teams to remediate findings and establish secure baselines.
- Perform security impact analyses for changes, deployments, and upgrades to sustain compliance and secure operations.
- Engineer endpoint protection and hardening using Trellix ePO on-site, host-based firewalls, and application whitelisting.
- Evaluate and implement cybersecurity tools to enhance posture, monitoring, and threat detection capabilities.
- Produce technical security documentation, architecture diagrams, SOPs, and executive-level risk assessments.
- Administer and troubleshoot CyberArk core modules such as EPV, PVWA, CPM, and PSM.
- Monitor, analyze, and detect cyber events within information systems and networks under general supervision.
- Assist with integrated cyber defense and maintain security toolsets to support continuous monitoring and authorization programs.
- Establish a framework for measuring and quantifying cyber risk in the marketplace.
- Determine security requirements by evaluating business aims, standards, and risk analyses; assess architecture and integration issues; prepare cost estimates.
- Implement security systems by specifying intrusion detection methodologies, installing and calibrating equipment, managing keys, and documenting procedures.
- Maintain security by ensuring compliance with standards and procedures, conducting incident analyses, and delivering training programs.
- Design and integrate DoD information assurance architectures for computing, networking, and enclave environments, ensuring secure and functional development and operation.
Qualifications
- 5 years with a BS or BA; 3 years with an MS or MA; or 0 years with a PhD combined with 4+ years of relevant experience in lieu of a degree.
- Active Top Secret with SCI Eligibility required.
- DoD 8570.1-M / 8140 IAT Level III certification compliant (SecurityX CASP, GCIH, CISA, CISSP).
- Strong background in networking (TCP/IP, firewalls, VPNs), cloud security (AWS/Azure), Kubernetes, and DevSecOps.
- Deep knowledge of NIST SP 800-161, NIST RMF, FedRAMP, Common Criteria, ATO package development, and STIGs.
- Hands-on experience with Tenable Nessus, CyberArk, Trellix, Splunk Enterprise, VMware vSphere, GitLab, Windows Server, RHEL, and Ubuntu Linux.
- Proficiency in scripting and automation using PowerShell, Python, Bash, and Ansible.
- Proven ability to lead projects and mentor junior ISSEs; capable of presenting to leadership teams.
Technologies
- Tenable Nessus, ACAS, Qualys
- Splunk Enterprise
- PowerShell, Bash, Python
- Trellix ePO, CyberArk EPV, PVWA, CPM, PSM
- VMware vSphere
- Windows Server, RHEL, Ubuntu
- GitLab, Kubernetes, Ansible
- AWS, Azure
Details
Target Salary Range: $135,000 - $216,000 per year. This range reflects typical compensation and may be adjusted based on experience, education, location, and contract requirements. The role may include overtime or discretionary bonus opportunities depending on program needs.
Benefits: Peraton offers a broad benefits package including medical, dental, vision, life, health savings account, short and long term disability, EAP, parental leave, 401(k), PTO, and company paid holidays. A full listing of benefits is available at the Peraton careers site.
Application timeline: The posting states an estimated 30 day application period, subject to change based on business needs and candidate availability. Applicants may be asked to participate in on-camera interviews and identity verification during the review process.
EEO: Peraton is an equal opportunity employer, including disability and protected veteran status, or other characteristics protected by law.