Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit peraton.com to learn how we’re keeping people around the world safe and secure.
Peraton is seeking an Information Assurance RMF Compliance Specialist to support the Department of Defense's next-generation enterprise Identity, Credential, and Access Management (ICAM) platform that is replacing DS Logon and providing secure authentication services for millions of Service Members, Veterans, Family Members, and Beneficiaries.
The Alternative Multi-factor Authentication Support Services (AMASS) Program provides secure, scalable identity and access management services across the Department of Defense, enabling authentication, authorization, and digital identity interoperability for high visibility DoD systems.
In this role, you will specialize in cybersecurity engineering, Risk Management Framework (RMF) compliance, Authority to Operate (ATO) lifecycle support, and secure implementation of enterprise Identity, Credential, and Access Management (ICAM) solutions for the Department of Defense's next-generation myAuth platform.
This is a 100% remote role.
Responsibilities:
• Develop, update, and maintain AMASS Information Assurance (IA) policies and Standard Operating Procedures (SOPs) in alignment with RMF and all applicable DoD and Federal requirements.
• Update and maintain the AMASS System Security Plan (SSP) and Implementation Plan within eMASS in compliance with government requirements.
• Update and maintain RMF compliance artifacts to include hardware/software inventories (myAuth), Ports, Protocols, and Services Management (PPSM) Bulk Upload files, Security Technical Implementation Guide (STIG) checklists, network diagrams, and other required artifacts.
• Support DoD RMF continuous monitoring requirements and update annual test results in eMASS.
• Support IA compliance status reporting to government stakeholders.
• Assist with migrating the myAuth RMF control baseline from NIST SP 800‑63 Rev. 4 to NIST SP 800‑63 Rev. 5 as directed.
• Support alignment with emerging IA requirements, including FedRAMP, as applicable.
• Support the myAuth cyber hardening application release approval process, including use of Fortify Software Security Center (SSC) to generate and track Plans of Action and Milestones (POA&Ms) and new findings.
• Collaborate with cross‑functional teams to ensure consistent application of IA and cybersecurity requirements.
Required Qualifications
Preferred Qualifications:
EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.