Security Control Assessor
Listed on 2026-08-11
-
IT/Tech
Cybersecurity, Information Security & Data Protection
About Peraton
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace.
The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit to learn how we're keeping people around the world safe and secure.
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world's leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace.
The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees solve the most daunting challenges that our customers face. Visit to learn how we're keeping people around the world safe and secure.
The Role
Peraton seeks a Cloud Security Control Assessor to support the Army Cyber Command (ARCYBER).
Location:
Alexandria, VA/Metro Park near Fort Belvoir, VA.
- Conduct assessments and facilitate risk mitigation planning
- Provide Assessment and Authorization (A&A) for the ARCYBER cloud infrastructure
- Execute a security control assessment plan and update the System Security Plan
- Review vulnerability scans and remediation
- Implement risk management programs by utilizing NIST, FISMA, HIPAA, and PII -- and document solutions
- Monitor the privacy landscape regarding all data (privacy, protection, classification, and residency)
- Assist clients with identifying gaps within existing privacy programs and designing solutions to help address those challenges
- Scan, test, and validate systems/networks/applications to obtain/maintain an ATO under NIST/FISMA guidelines
Required:
- Minimum experience of 12 years with BS/BA;
Minimum of 10 years with MS/MA;
Minimum of 7 years with Ph.D. Will consider HS+16 or Associates +14. - Must have current IAM level III certification (such as CISM)
- Must have knowledge of enterprise solutions across multiple cloud operating environments (JWICS, SIPRNET, NIPRNET, and commercial Internet)
- Must have eMASS, ACAS, and ISC2 Certified Cloud Computing Professional (CCSP) or CompTIA Cloud+ experience
- Must have knowledge in the following areas:
- Knowledge of computer networking and/or cloud computing concepts and protocols, and network security methodologies
- Knowledge of cyber threats and vulnerabilities in a virtualized environment.
- Knowledge of cybersecurity principles
- Knowledge of national and international laws, regulations, policies, and ethics as they relate to cybersecurity
- Knowledge of risk management framework processes (e.g., methods for assessing and mitigating risk)
- Knowledge of specific operational impacts of cybersecurity lapses
- Knowledge of industry methods for evaluating, implementing, and disseminating Information Technology (IT) security assessment, monitoring, detection, and remediation tools and procedures using standards-based concepts and capabilities
- Knowledge of cyber defense and vulnerability assessment tools, including opensource tools, and their capabilities
- Knowledge of cybersecurity principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation)
- Knowledge of cybersecurity principles used to manage risks related to the use, processing, storage, and transmission of information or data in a cloud environment
- Knowledge of IT and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).