Skip to main content
← Back to Jobs

Principal Information Security Consultant

PeratonUnited States🌍 Remote
Full-time7-15
$135k - $216k
per year
👁️ 0 views📝 0 applicationsPosted 8/16/2026Expires 9/15/2026
Tailor Resume for This JobCheck ATS Score

Get alerts for roles like this

More Principal Information Security Consultant roles in United States — straight to your inbox. No account needed.

Applying to this role? Tailor your résumé to this job description in one click, then download it clean — no watermark, no subscription.

Job Description

Responsibilities **Position Is Contingent Upon Award** Peraton Labs is hiring a Principal Information Security Consultant to be the senior technical authority and trusted advisor for secure architecture and engineering across the Covered California and CalHEERS environments. You will translate NIST SP 800-53 Rev.

5, ARC-AMPE, and IRS Publication 1075 requirements into practical technical designs and operating controls, and you will provide the senior technical review that our security deliverables pass through before they reach the client.

You will work with Covered California's security leadership, cloud and infrastructure engineers, application teams, and project delivery teams, alongside a small senior Peraton security team.

The goal is to raise the real, measured security posture of a cloud-based health benefit exchange that processes PII, PHI, and federal tax information — not merely to document it.

What You Will Do

In This Role: Own secure architecture. Design and review secure architectures, technical designs, security patterns, and proposed solutions across cloud and on-premises environments; identify risks and recommend proportionate controls. Translate controls into engineering. Interpret and apply NIST SP 800-53 Rev.

5 security and privacy controls, ARC-AMPE requirements, and IRS Publication 1075 safeguards as concrete technical configurations, hardening standards, and automated controls. Lead security engineering across domains.

Provide technical leadership for identity and access management, network security, endpoint security, cloud security, and application security, including CSP-native tooling and configuration review. Direct vulnerability management technically.

Own scanning strategy, risk-based prioritization, hardening baselines (CIS Benchmarks and DISA STIGs), and validation that remediation actually closed the exposure. Evaluate and close control gaps. Assess controls, identify gaps and weaknesses, develop risk-based remediation strategies, and

Required Skills

NIST SP 800-53 Rev. 5ARC-AMPEIRS Publication 1075cloud securityidentity and access managementnetwork securityendpoint securityapplication securityCIS BenchmarksDISA STIGs

The best-paying roles in your field. Every week. Free.

Join 10,000+ professionals getting job alerts and salary insights in their inbox

We respect your privacy. Unsubscribe anytime with one click.