21 ago - Vicenza
Peraton
ph3Qualifications (Required): /h3 ul liBachelor's degree in Computer Science, Information Systems, Cybersecurity, Engineering, or related field; additional experience may be substituted in lieu of degree.
/li li5 to 7 years of experience in cybersecurity, DevSecOps, or system engineering roles supporting federal programs.
/li liExperience acting as an ISSO or security engineer for a FISMA Moderate or FedRAMP Moderate system.
/li liHands?on experience preparing security authorization documentation such as SSPs, SARs, POAMs, and Continuous Monitoring updates.
/li liStrong understanding of NIST ****** security controls, Risk Management Framework (RMF), CMS ARS 5.1, and continuous monitoring requirements.
/li liPractical experience supporting or integrating security processes in DevSecOps pipelines, CI/CD workflows, or automated deployment environments.
/li liExperience with vulnerability management tools and processes, including scanning, analysis, and remediation tracking.
/li liAbility to support audits and communicate effectively with assessment teams, program stakeholders, and government security representatives.
/li liU.S.
citizenship and the ability to obtain and maintain a public trust or equivalent clearance.
/li /ul h3Qualifications (Preferred): /h3 ul liExperience supporting CMS programs or other HHS components.
/li liFamiliarity with FedRAMP documentation, cloud boundary definitions, and cloud?native security practices.
/li liExperience with AWS or Azure security services, cloud configuration baselines, and cloud compliance frameworks.
/li liWorking knowledge of tools commonly used within Peraton and similar enterprises, such as GitLab/GitHub CI/CD, Jenkins, Terraform, Ansible, Tenable, Splunk, or similar platforms.
/li liSecurity certifications such as Security+, CISSP, CISM,
CCSP, or AWS/Azure security certifications.
/li liExperience integrating legacy systems into modern cloud or hybrid architectures with secure migration practices.
/li liKnowledge of container security (Docker, Kubernetes) and infrastructure?as?code security scanning.
/li /ul pPeraton is seeking a Mid?level DevSecOps Engineer to join our team of qualified, diverse professionals.
In this role, you will support the security, reliability, and compliance of mission?critical systems within the DME Program.
The ideal candidate will play a key part in integrating security throughout the development lifecycle, maintaining adherence to federal cybersecurity standards, and ensuring the operational readiness of modernized systems at the Centers for Medicare Medicaid Services (CMS).
This position supports a highly visible environment where strong technical execution, security rigor, and cross?team collaboration are essential.
/p h3Responsibilities: /h3 ul liServe as the Information System Security Officer (ISSO) for the ClaimsCore Program, ensuring full compliance with FISMA Moderate, FedRAMP Moderate, and CMS ARS 5.1 security requirements.
/li liPrepare, maintain, and update all Certification and Accreditation (CA) and Security Assessment and Authorization (SAA) documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Contingency Plans,
and Plan of Action and Milestones (POAMs).
/li liConduct and document ongoing risk assessments, vulnerability assessments, and security control evaluations across the program's cloud and on?premises environments.
/li liManage and coordinate the Authority to Operate (ATO) lifecycle, including initial authorization, continuous monitoring, control implementation reviews, and audit preparation.
/li liEnsure zero open Critical or High vulnerabilities at system go?live and maintain compliance with vulnerability remediation SLAs.
/li liRespond to and manage security incident notifications within required timelines (1 hour for initial reporting).
Coordinate with internal security teams and external stakeholders to support incident response processes.
/li liSupport internal and external audits, including CSRAP, CFO, OMB A?123, and annual security assessments.
/li liCollaborate with DevOps, engineering, and operations teams to integrate security best practices into CI/CD pipelines, infrastructure?as?code, and deployment processes.
/li liMonitor and enhance security posture using tools such as vulnerability scanners, SIEM platforms, configuration management tools, and compliance automation platforms.
/li liContribute to continuous improvement of security procedures, engineering practices, and system hardening baselines.
/li liAssist in the implementation and maintenance of cloud security configurations aligned with agency and program requirements.
/li liProvide security guidance during architecture reviews, design sessions, sprint planning, and change control processes.
/li liEnsure security documentation, diagrams, inventories, and boundary definitions are accurate and up to date.
/li /ul /p #J-*****-Ljbffr
23 ago - Italia
Engel & Völkers Italia - Lago d'Iseo Franciacorta e Ponte di Legno
23 ago - Marina Palmense
Almedia
23 ago - Roma
Michael Page International Italia
23 ago - Padova
Stryker