> Markdown version of [/jobs/ext/1356964-senior-information-system-security-officer](https://www.wearedevelopers.com/jobs/ext/1356964-senior-information-system-security-officer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Information System Security Officer - **Company:** Base-2 Solutions, LLC - **Location:** Reston, VA, United States - **Experience:** Expert - **Salary:** $10,000.0 - **Contract:** Permanent contract - **Skills:** Xacta, Software System Penetration Testing, Cyber Security, Computer Networks, Data Security, Information Security Management, Network Planning and Design, Software Security, Patch Management - **Published:** July 20, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9041117/senior-information-system-security-officer ## About the Role * Experience helping to implement STIG checklists and mitigate scan findings. * Experience supporting security assessment events and responding to questions from PAT team, ISSMs, and SCA. * Experience working with application leads, sysadmins, DBAs, developers, and testers to ensure systems are security compliant and achieve/maintain ATO. * Experience working with Xacta. * Bachelor's degree with 14+ years of experience. * Master's degree with 12+ years of experience. * PhD with 10+ years of experience. ## Description Base-2 Solutions is seeking a Senior Information Systems Security Officer responsible for safeguarding computer networks and systems to ensure data security, integrity, and confidentiality at the highest standards. * Designs, develops, implements and/or integrates IA and security systems and system components including those for networking, computing, and enclave environments with multiple enclaves and differing data protection/classification requirements. * Analyzes architecture and system functionality for multiple technologies. * Contributes to the development and evaluation of attack scenarios. * Prepares and delivers technical reports and briefings. * Has a complete understanding of Risk Management Framework and implements the process on program systems/networks. * Performs or reviews technical security assessments of computing environments to identify vulnerabilities, non-compliance with IA standards and regulations, and recommends mitigation strategies. * Validates and verifies system security requirements definitions and analysis and establishes system security designs. * Assists architects and systems developers in identifying and implementing appropriate information security functionality to ensure uniform application security policy and enterprise solutions. * Supports building security architectures and enforces trusted relations among external systems and architectures. * Assesses and mitigates system security threats/risks throughout the program life cycle. * Contributes to security planning, assessment, risk analysis, risk management, certification, and awareness activities for system and networking operations. * Reviews certification and accreditation (C&A) documentation, providing feedback on completeness and compliance. * Performs system installation, configuration, maintenance, account maintenance, signature maintenance, patch management, and troubleshooting of operational IA and CND systems. * Performs limited penetration testing and routine exploit analysis. * Performs system or network designs encompassing multiple enclaves with differing data protection/classification requirements. * Recommends system-level solutions to resolve security requirements. * Supports enforcement of design and implementation of trusted relationships among external systems and architectures. * Works with application leads, sysadmins, DBAs, developers, and testers to ensure assigned systems are security compliant and achieve/maintain ATO. * Loads artifacts such as STIG checklists and ACAS scans. * Helps implement STIG checklists and mitigate scan findings. * Supports security assessment events and responds to questions from PAT team, ISSMs, and SCA. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Web-based Information Visualization](https://www.wearedevelopers.com/videos/84-web-based-information-visualization) ## Related Articles - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)