Information Assurance and Security, Advisor

Peraton•,
•$104,000 - $166,000

About The Position

We are seeking a Regulatory and Compliance Lead on the CMS Fraud Prevention Services (FPS) Team, as a compliance authority for the agentic AI vendor evaluation, producing the regulatory-and-compliance portion of the vendor-list assessment and authoring the security inputs to the Proof of Concept (POC) Solution proposal. The Lead ensures every security-related activity, POC data path, and vendor artifact remain within the FPS ATO boundary and comply with CFACTS, CSRAP, FISMA, and HIPAA PHI requirements.

Requirements

  • Minimum of 8 years with BS/BA; Minimum of 6 years with MS/MA; Minimum of 3 years with PhD
  • Experience leading compliance work on Federal (ideally, CMS) systems.
  • Deep working knowledge of CMS (or other Federal agencies) security frameworks: CFACTS, CSRAP, and the ATO lifecycle (SSP, SAR, POA&M, contingency plan, PIA/SORN).
  • Practical experience with FISMA / NIST SP 800-53 control tailoring, inheritance from cloud providers (AWS FedRAMP baselines), and boundary definition.
  • Experience assessing third-party/vendor security posture: SOC 2, FedRAMP, HIPAA/HITRUST, penetration-test evidence, vulnerability management.
  • Familiarity with cloud-native security in AWS (IAM, KMS, GuardDuty, CloudTrail, Config), Okta SSO/RBAC, and audit-log routing to CloudWatch/Splunk.
  • Working knowledge of HIPAA PHI handling and Federal PII requirements, especially for Medicare/Medicaid claims data.
  • Ability to author security artifacts and briefings for CMS-level review; clear technical writing required.
  • US citizenship; ability to obtain and maintain a Public Trust clearance.

Nice To Haves

  • CISSP, CISM, CAP, CISA, or equivalent certification.
  • Prior compliance work on the FPS ATO or another CMS ATO'd system (e.g., IDR, One PI, UCM).
  • Familiarity with security considerations specific to LLM and agentic AI systems (model-provider data retention, prompt logging, MCP tool authorization, RBAC for LLM outputs).
  • Experience defining vendor-isolated enclaves inside a Federal customer's authorization boundary.
  • Familiarity with SAFe Agile compliance patterns (continuous ATO / RMF automation).
  • Experience with Databricks and Snowflake governance controls (Unity Catalog, dynamic masking, row/column access policies).

Responsibilities

  • Assess each candidate agentic AI vendor against CMS security posture, data-handling, and ATO requirements as part of the vendor-list assessment.
  • Author the security-and-compliance inputs to the POC Solution proposal: control inheritance, boundary definition, data-flow diagrams, and the compliance narrative for the vendor-isolated exclusive environment.
  • Coordinate with the FPS ISSO/ISSM and CMS security stakeholders to keep AI tool assessment and POC activity inside the FPS ATO boundary.
  • Own compliance artifacts and cadence (SSP inputs, POA&M entries, PIA/SORN as applicable) for the AI vendor-evaluation effort.
  • Serve as the single point of contact for security-and-compliance questions raised by third-party vendors, CMS, or the Peraton PM.
  • Advise the Lead AI Solutions Architect on LLM/agentic-AI-specific compliance concerns (model-provider data retention, prompt/response logging, PHI-in-prompt controls, tool authorization).

Benefits

  • Overtime
  • Shift differential
  • Discretionary bonus
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service