Peraton is seeking a Senior Information Systems Engineer (Endpoint Security & C&A) to provide advanced security engineering, endpoint device management, certification/accreditation (C&A), and federal vulnerability reporting support. The position will be in support of the Information Technology Service Desk and Engineering Support program for a Contract at U. S. Department of Health and Human Services. The Information Systems Engineer will play a critical role in designing, testing, and implementing endpoint and network security solutions, ensuring compliance with NIST, FISMA, FedRAMP, CISA Binding Operational Directives (BODs), and HHS OIG standards. This position requires hands-on expertise in endpoint engineering, vulnerability reporting, security architecture, and certification/accreditation processes, with an emphasis on presenting security findings and remediation strategies to management. What you'll do: Security Engineering Support Government-furnished security services assets plus systems, including refreshes and upgrades. Deliver monthly status reports. Engineer security solutions for hardware, software, and services to protect networks from unauthorized devices, users, and malicious code. Provide security engineering support in compliance with federal and HHS security mandates, including NIST SP 800-53, NIST SP 800-207 (Zero Trust), DISA STIGs, FedRAMP, and FIPS standards. Conduct security reviews of network configurations, firewall rules, and endpoint solutions, providing recommendations for continuous improvements. Safeguard Personally Identifiable Information (PII) in compliance with NIST SP 800-122. Provide real-time or near real-time log forwarding to SIEM systems and support audit requirements. Vulnerability & Compliance Reporting Monitor and assess CVE and Known Exploited Vulnerability (KEV) catalogs published by CISA. Develop, document, and deliver reports on CVE/KEV findings, remediation timelines, and risk ratings. Track and report compliance with CISA Binding Operational Directives (BODs), including mandated remediation deadlines. Prepare executive summaries and technical reports on vulnerability management activities for leadership. Present vulnerability, risk, and remediation findings to management and stakeholders in a clear, actionable manner. Endpoint Engineering & Certification/Accreditation Provide engineering support for endpoint devices (desktops, laptops, thin clients, tablets, mobile phones, and wearables). Develop technical plans for endpoint engineering, covering design, scheduling, resources, and monitoring. Conduct endpoint integration and security testing to ensure compliance with defined requirements and HHS-OIG policies. Develop and maintain endpoint-related SOPs, requirements documentation, and acceptance criteria. Perform regular technical reviews with Government staff and present recommendations to improve efficiency and cybersecurity concerns. Assist with System Security Plans (SSPs), Contingency Plans, POA&Ms, and Penetration Test Reports. Mitigate high-risk vulnerabilities within 30 days and moderate-risk vulnerabilities within 90 days. Collaborate with HHS OIG and internal technical teams regarding incidents, escalations and reporting.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Education Level
Associate degree