Information System Security Officer
Base-2 Solutions · Reston, VA · 3 days ago
Information TechnologyFull-time
Location: Reston, VA | Work Type: On-Site | Shift: First | U.S. Citizenship Required
About the Role
Base-2 Solutions is seeking an Information System Security Officer to work with application leads, system administrators, database administrators, developers, and testers to ensure assigned systems are security compliant and achieve or maintain Authority to Operate (ATO). The role includes following the Risk Management Framework (RMF) process, updating Xacta documentation, loading artifacts, implementing STIG checklists, mitigating scan findings, supporting security assessment events, and responding to inquiries from security teams.
Responsibilities
- Work with application leads, system administrators, database administrators, developers, and testers to ensure systems are security compliant and achieve or maintain ATO.
- Follow the RMF process for full test, partial test, continuous monitoring (CONMON), and no test scenarios.
- Update Xacta documentation including System Security Plans (SSPs), Security Control Trace Matrices (SCTM), Security Test Plans (STPs), and Plans of Action and Milestones (POAMs).
- Load artifacts such as STIG checklists and ACAS scans.
- Implement STIG checklists and mitigate scan findings.
- Support security assessment events and respond to inquiries from the Security Test and Evaluation (PAT) team, Information System Security Managers (ISSMs), and Security Control Assessors (SCAs).
Requirements
- Bachelor's degree in computer science, software engineering, or a related field (or equivalent experience).
- 9 or more years of relevant experience with a Bachelor's degree; additional experience may substitute for a degree.
- Demonstrated experience in developing, implementing, and enforcing security policies, standards, and procedures to ensure regulatory compliance and protect organizational information assets.
- Proven track record in conducting risk assessments and identifying vulnerabilities in systems, networks, and applications.
- Experience in developing and overseeing implementation of mitigation strategies to reduce security risks.
- Strong background in monitoring systems and networks for security breaches and suspicious activity.
- Successful history of responding to security incidents, investigating root causes, and implementing corrective actions.
- Active Top Secret/SCI with CI Polygraph clearance.
Qualifications
Equivalent combinations of education and experience:
- High School with 13 years of experience.
- Associate's degree with 11 years of experience.
- Bachelor's degree with 9 years of experience.
- Master's degree with 7 years of experience.
- PhD with 5 years of experience.
Preferred Qualifications
- Comprehensive knowledge of relevant laws, regulations, and industry standards.
- Experience conducting audits and assessments to verify adherence to security requirements.
Benefits
Health
- 100% company-paid medical premiums for employees and eligible dependents (multiple plan options available).
- 100% company-paid dental premiums for employees and eligible dependents.
- 100% company-paid vision premiums for employees and eligible dependents.
Income Protection
- 100% company-paid short-term disability premiums.
- 100% company-paid long-term disability premiums.
- 100% company-paid accidental death & dismemberment (AD&D) premiums.
- 100% company-paid life insurance up to $200,000.
Retirement
- 401(k) with immediate vesting: 4% company match plus a 4% non-elective company contribution (8% total).
- 401(k) pre-tax and Roth options.
Leave
- Up to 20 days of flexible paid time off (PTO).
- 11 paid floating holidays.
Work-Life Balance
- Flexible work schedules, including flex time and compressed work periods (contract and project-dependent).
Additional Perks
- Employee referral bonuses up to $10,000 per hired referral.
- Bonus opportunities for exceptional performance and contributions to business development and company growth (role-dependent).