Senior Information System Security Officer

Base-2 Solutions, LLC
Norfolk, VA, United States
about 1 month ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
10 years minimum
Compensation
$10,000.0
Working hours
Regular working hours

Tech stack

Xacta Software System Penetration Testing Cyber Security Computer Networks Data Security Information Security Management Network Planning and Design Software Security Patch Management

Job description

Base-2 Solutions is seeking a Senior Information Systems Security Officer responsible for safeguarding computer networks and systems to the highest standards, ensuring data security, integrity, and confidentiality.

  • Designs, develops, implements and/or integrates IA and security systems and system components including those for networking, computing, and enclave environments with multiple enclaves and differing data protection/classification requirements.
  • Analyzes architecture and system functionality for multiple technologies.
  • Contributes to the development and evaluation of attack scenarios.
  • Prepares and delivers technical reports and briefings.
  • Has a complete understanding of Risk Management Framework and implements the process on program systems/networks.
  • Performs or reviews technical security assessments of computing environments to identify vulnerabilities, non-compliance with IA standards and regulations, and recommends mitigation strategies.
  • Validates and verifies system security requirements definitions and analysis and establishes system security designs.
  • Assists architects and systems developers in identifying and implementing appropriate information security functionality to ensure uniform application security policy and enterprise solutions.
  • Supports building security architectures and enforces trusted relations among external systems and architectures.
  • Assesses and mitigates system security threats/risks throughout the program life cycle.
  • Contributes to security planning, assessment, risk analysis, risk management, certification, and awareness activities for system and networking operations.
  • Reviews certification and accreditation (C&A) documentation, providing feedback on completeness and compliance.
  • Performs system installation, configuration, maintenance, account maintenance, signature maintenance, patch management, and troubleshooting of operational IA and CND systems.
  • Performs limited penetration testing and routine exploit analysis.
  • Performs system or network designs encompassing multiple enclaves with differing data protection/classification requirements.
  • Recommends system-level solutions to resolve security requirements.
  • Supports enforcement of design and implementation of trusted relationships among external systems and architectures.
  • Works with application leads, sysadmins, DBAs, developers, and testers to ensure assigned systems are security compliant and achieve/maintain ATO.
  • Loads artifacts such as STIG checklists and ACAS scans.
  • Helps implement STIG checklists and mitigate scan findings.
  • Supports security assessment events and responds to questions from PAT team, ISSMs, and SCA.

Requirements

  • Experience helping to implement STIG checklists and mitigate scan findings.
  • Experience supporting security assessment events and responding to questions from PAT team, ISSMs, and SCA.
  • Experience working with application leads, sysadmins, DBAs, developers, and testers to ensure systems are security compliant and achieve/maintain ATO.

  • Experience working with Xacta.

  • Bachelor’s degree with 14+ years of experience.
  • Master’s degree with 12+ years of experience.
  • PhD with 10+ years of experience.

Benefits & conditions

  • Competitive fixed salary or hourly pay (based on experience, skills, location, and internal equity).
  • Employee referral bonuses up to $10,000 per hired referral.
  • Additional bonus opportunities for exceptional performance and contributions to business development and company growth (role-dependent).

  • 100% company-paid medical premiums for employees and eligible dependents.
  • Choose from multiple plan options with CareFirst, Kaiser, and UnitedHealthcare, including PPO, POS, HMO, and HSA-compatible plans.
  • 100% company-paid dental premiums for employees and eligible dependents.
  • 100% company-paid vision premiums for employees and eligible dependents.

  • 100% company-paid premiums for short-term disability.
  • 100% company-paid premiums for long-term disability.
  • 100% company-paid premiums for accidental death & dismemberment (AD&D).
  • 100% company-paid premiums for life insurance up to $200,000.

  • 401(k) with immediate vesting: 4% company match plus a 4% non-elective company contribution (8% total).
  • 401(k) pre-tax and Roth options.

  • Up to 20 days of flexible paid time off (PTO).
  • 11 paid floating holidays.

  • Flexible work schedules, including flex time and compressed work periods (contract and project-dependent).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

10:35 min

Teaching and coaching security concepts for lasting impact

Tanya Janca · World Congress 2021

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:04 min

Embedding data security and applied ethics into developer education

Daniel Tao +3 · World Congress 2024

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

Videos

See all

Related articles

See all