Information System Security Officer

Base-2 Solutions, LLC
Elkridge, MD, United States
about 1 month ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$10,000.0
Working hours
Regular working hours

Tech stack

Xacta Monitoring of Systems Information Security Management Software Engineering Information Technology

Job description

Base-2 Solutions is seeking a Security Compliance Specialist to work with application leads, system administrators, database administrators, developers, and testers to ensure assigned systems are security compliant and achieve or maintain Authority to Operate (ATO). The role includes following the Risk Management Framework (RMF) process for full test, partial test, continuous monitoring (CONMON), and no test scenarios, updating Xacta documentation including System Security Plans (SSPs), Security Control Trace Matrices (SCTM), Security Test Plans (STPs), and Plans of Action and Milestones (POAMs). The specialist will load artifacts such as Security Technical Implementation Guide (STIG) checklists and ACAS scans, help implement STIG checklists, mitigate scan findings, and support security assessment events by responding to questions from the Security Test and Evaluation (ST&E) team, Information System Security Managers (ISSMs), and Security Control Assessors (SCAs).

  • Work with application leads, system administrators, database administrators, developers, and testers to ensure assigned systems are security compliant and achieve or maintain ATO.
  • Follow the RMF process for full test, partial test, continuous monitoring (CONMON), and no test scenarios.
  • Update Xacta documentation including SSPs, SCTM, STPs, and POAMs.
  • Load artifacts such as STIG checklists and ACAS scans.
  • Help implement STIG checklists and mitigate scan findings.
  • Answer questions to ensure systems are developed with security compliance built in.
  • Support security assessment events and respond to all questions from the PAT team, ISSMs, and SCAs.

Requirements

  • Bachelor’s degree in computer science, software engineering, or a field applicable to the position required.
  • 9 or more years of relevant experience required with a Bachelor’s degree.
  • Additional experience may be considered in lieu of degree.
  • Demonstrated experience in developing, implementing, and enforcing security policies, standards, and procedures to ensure regulatory compliance and protect organizational information assets.
  • Proven track record in conducting risk assessments and identifying vulnerabilities in systems, networks, and applications.
  • Experience in developing and overseeing implementation of mitigation strategies to reduce security risks.
  • Strong background in monitoring systems and networks for security breaches and suspicious activity.
  • Successful history of responding to security incidents, investigating root causes, and implementing corrective actions.

  • Comprehensive knowledge of relevant laws, regulations, and industry standards.
  • Experience conducting audits and assessments to verify adherence to security requirements.

  • High School with 13 years of experience.
  • Associates with 11 years of experience.
  • Bachelor’s with 9 years of experience.
  • Master’s with 7 years of experience.
  • PhD with 5 years of experience.

Benefits & conditions

  • Competitive fixed salary or hourly pay (based on experience, skills, location, and internal equity).
  • Employee referral bonuses up to $10,000 per hired referral.
  • Additional bonus opportunities for exceptional performance and contributions to business development and company growth (role-dependent).

  • 100% company-paid medical premiums for employees and eligible dependents.
  • Choose from multiple plan options with CareFirst, Kaiser, and UnitedHealthcare, including PPO, POS, HMO, and HSA-compatible plans.
  • 100% company-paid dental premiums for employees and eligible dependents.
  • 100% company-paid vision premiums for employees and eligible dependents.

  • 100% company-paid premiums for short-term disability.
  • 100% company-paid premiums for long-term disability.
  • 100% company-paid premiums for accidental death & dismemberment (AD&D).
  • 100% company-paid premiums for life insurance up to $200,000.

  • 401(k) with immediate vesting: 4% company match plus a 4% non-elective company contribution (8% total).
  • 401(k) pre-tax and Roth options.

  • Up to 20 days of flexible paid time off (PTO).
  • 11 paid floating holidays.

  • Flexible work schedules, including flex time and compressed work periods (contract and project-dependent).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:13 min

Structuring a comprehensive corporate security organization

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

39 sec

Introducing Monoscope for intelligent post-deployment system monitoring

Anthony Alaribe Anthony Alaribe · World Congress 2025

1:22 min

Understanding software engineering as more than just coding

Lilia Gargouri Lilia Gargouri · World Congress 2026 Europe

2:59 min

Applying secure coding practices and proactive system monitoring

Mihaela-Roxana Ghidersa · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:29 min

Undervaluing product design by treating software engineers as generic programmers

Marlene Roth Marlene Roth +1 · World Congress 2025

Videos

See all

Related articles

See all