Peraton is seeking a Lead Security Analyst to join our team of qualified, diverse professionals supporting the Health State and Local Sector. The ideal candidate will lead security analysis, compliance oversight, and risk management efforts across a complex, mission critical environment. This role plays a pivotal part in ensuring secure and compliant solutions, guiding vulnerability management activities, and supporting major modernization efforts for the Centers for Medicare & Medicaid Services (CMS). The Lead Security Analyst will help shape and maintain a robust security posture, ensuring that all program capabilities adhere to CMS and Federal security standards.
Lead Security Analyst’s responsibilities shall include, but are not limited to:
- Leading all security analysis, compliance, and oversight activities for the Program.• Conducting comprehensive security assessments, including evaluation of system architecture, data flows, interfaces, and inherited controls.• Developing, maintaining, and enforcing program-wide security policies, procedures, and documentation consistent with Federal and CMS security requirements.• Managing the program’s vulnerability assessment program, including vulnerability scanning, analysis, reporting, and coordination of remediation activities.• Leading the development of risk mitigation strategies and providing recommendations to address findings from scans, assessments, POA&Ms, and audits.• Preparing and supporting all security audits, reviews, and checkpoints, including CMS security assessments, FISMA reviews, and relevant ATO activities.• Ensuring security requirements are integrated into Agile development workflows, providing direct guidance to Scrum teams, architects, and developers.• Reviewing technical designs, user stories, and system enhancements for security impacts and compliance alignment.• Monitoring regulatory and CMS security updates to ensure program compliance remains current and accurate.• Collaborating with cross functional stakeholders including engineering, operations, compliance, and program leadership to ensure secure-by-design solution delivery.• Developing and delivering security awareness and compliance training tailored to the Program needs.• Maintaining accurate and up-to-date security documentation, dashboards, and metrics reporting for program leadership.
Basic Qualifications:
- 5 years with BS/BA; 3 years with MS/MA
- Demonstrated experience leading security analysis, compliance, and risk management activities for large-scale Federal programs.
- Strong understanding of Federal information security standards and frameworks such as FISMA, NIST SP 80053, NIST RMF, and CMS ARS.
- Hands-on experience conducting or managing vulnerability assessments, security scanning, POA&M lifecycle management, and risk mitigation planning.
- Experience preparing for and supporting Federal security audits, assessments, and ATO activities.
- Ability to review system designs, data flows, and architecture diagrams for security considerations and compliance alignment.
- Experience working directly with Agile teams and integrating security requirements into Agile SDLC processes.
- Excellent written and verbal communication skills, with the ability to communicate with both technical and nontechnical stakeholders.
- US. Citizenship required.
- Must have the ability to obtain and maintain a Public Trust clearance.
- Must reside near or be able to work in alignment with the program’s hybrid work expectations.
Preferred Qualifications:
- Experience supporting CMS programs, including familiarity with CMS ARS, ATO processes, and CMS governance expectations.
- Relevant security certifications such as CISSP, CISM, Security+, CEH, or equivalent.
- Experience with vulnerability management platforms, SIEM tools, and security automation technologies.
- Prior experience in healthcare IT and knowledge of compliance requirements such as HIPAA.
- Experience integrating or modernizing systems in environments with legacy system dependencies.
- Experience supporting large-scale, multi-team modernization or transformation initiatives.
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.
Target Salary Range$86,000 - $138,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay. EEOEEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.Skills Required
- Bachelor’s degree and 5 years of experience, or master’s degree and 3 years of experience
- Experience leading security analysis, compliance, and risk management for large-scale Federal programs
- Knowledge of FISMA, NIST SP 800-53, NIST RMF, and CMS ARS
- Experience with vulnerability assessments, security scanning, POA&M lifecycle management, and risk mitigation planning
- Experience supporting Federal security audits, assessments, and ATO activities
- Ability to review system designs, data flows, and architecture diagrams for security and compliance considerations
- Experience integrating security requirements into Agile SDLC processes
- Excellent written and verbal communication skills with technical and nontechnical stakeholders
- U.S. citizenship
- Ability to obtain and maintain a Public Trust clearance
- Ability to meet the program’s hybrid work expectations while residing nearby or working in alignment with the program
- Experience supporting CMS programs and familiarity with CMS ARS, ATO processes, and CMS governance
- CISSP, CISM, Security+, CEH, or equivalent security certification
- Experience with vulnerability management platforms, SIEM tools, and security automation technologies
- Prior healthcare IT experience and knowledge of HIPAA compliance requirements
- Experience integrating or modernizing systems with legacy dependencies
- Experience supporting large-scale, multi-team modernization or transformation initiatives
Peraton Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Peraton and has not been reviewed or approved by Peraton.
-
Healthcare Strength — Healthcare offerings are described as broad, including medical, dental, vision, mental health support, and specialty programs like virtual physical therapy and surgical/cancer care navigation. Medical coverage is also characterized as a standout part of the overall package in terms of perceived quality.
-
Retirement Support — Retirement support includes a 401(k) with employer matching and is repeatedly positioned as a strong component of total rewards. The 401(k) benefit is frequently singled out as one of the most valued parts of the package.
-
Leave & Time Off Breadth — Time-off benefits are positioned as robust, including PTO, holidays, paid sick days, and floating holidays, with some roles offering notably generous accrual. Leave breadth is reinforced by related programs such as short/long-term disability and bereavement leave.
Peraton Insights
What We Do
Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.
Why Work With Us
We are fearlessly solving the world’s most complex challenges to keep people safe and secure. You can be a part of protecting and promoting that freedom around the world.









