This job has expired

This job posting is no longer active and is not accepting applications. Explore similar roles below!

Base-2 Solutions
Posted 1w ago

Information System Security Officer

Base-2 Solutions
Washington, District of Columbia, United States
OnsiteFull Time
Responsibilities
  • ensuring compliance
  • updating documentation
  • mitigating findings
Requirements
  • Requires a bachelor's degree or equivalent experience
  • 9+ years of relevant experience
  • Active Top Secret/SCI clearance with CI polygraph, and expertise in security compliance
  • Risk assessment
  • Vulnerability mitigation, and incident response
Technical tools mentioned
XactaSystem Security Plans (SSPs)Security Control Trace Matrices (SCTM)Security Test Plans (STPs)Plans of Action and Milestones (POAMs)STIGACASRisk Management Framework (RMF)

Job description

  • Requisition ID: 3553
  • Standard Title:
  • Required Security Clearance: Top Secret/SCI with CI Polygraph
  • Location: Washington, DC
  • Work Type: On-Site
  • Shift: First
  • Referral Eligibility: Eligible
  • U.S. Citizenship Required? Yes


Position Summary


Base-2 Solutions is seeking an Information System Security Officer to work with application leads, system administrators, database administrators, developers, and testers to ensure assigned systems are security compliant and achieve or maintain Authority to Operate (ATO). The role includes following the Risk Management Framework (RMF) process for full test, partial test, continuous monitoring (CONMON), and no test scenarios, updating Xacta documentation such as System Security Plans (SSPs), Security Control Trace Matrices (SCTM), Security Test Plans (STPs), and Plans of Action and Milestones (POAMs), loading artifacts including STIG checklists and ACAS scans, implementing STIG checklists and mitigating scan findings, supporting security assessment events, and responding to inquiries from the Security Test and Evaluation (PAT) team, Information System Security Managers (ISSMs), and Security Control Assessors (SCAs).


Essential Duties and Responsibilities


  • Work with application leads, system administrators, database administrators, developers, and testers to ensure systems are security compliant and achieve or maintain ATO.

  • Follow the RMF process for full test, partial test, CONMON, and no test.

  • Update Xacta documentation including SSPs, SCTM, STPs, and POAMs.

  • Load artifacts such as STIG checklists and ACAS scans.

  • Help implement STIG checklists and mitigate scan findings.

  • Answer questions to ensure systems are developed with security compliance built in.

  • Support security assessment events and respond to all questions from PAT team, ISSMs, and SCAs.


Required Qualifications


  • Bachelor's degree in computer science, software engineering, or a field applicable to the position required.

  • 9 or more years of relevant experience required with a Bachelor's degree.

  • Additional experience may be considered in lieu of degree.

  • Demonstrated experience in developing, implementing, and enforcing security policies, standards, and procedures to ensure regulatory compliance and protect organizational information assets.

  • Proven track record in conducting risk assessments and identifying vulnerabilities in systems, networks, and applications.

  • Experience in developing and overseeing implementation of mitigation strategies to reduce security risks.

  • Strong background in monitoring systems and networks for security breaches and suspicious activity.

  • Successful history of responding to security incidents, investigating root causes, and implementing corrective actions.


Preferred Qualifications


  • Comprehensive knowledge of relevant laws, regulations, and industry standards.

  • Experience conducting audits and assessments to verify adherence to security requirements.


Required Education and Experience Equivalency


  • High School with 13 years of experience.

  • Associates with 11 years of experience.

  • Bachelor's with 9 years of experience.

  • Master's with 7 years of experience.

  • PhD with 5 years of experience.


Required Certifications


  • None specified.


Required Security Clearance


  • Active Top Secret/SCI with CI Polygraph

Pay & Benefit Highlights

Compensation

  • Competitive fixed salary or hourly pay (based on experience, skills, location, and internal equity).
  • Employee referral bonuses up to $10,000 per hired referral.
  • Additional bonus opportunities for exceptional performance and contributions to business development and company growth (role-dependent).

Health

  • 100% company-paid medical premiums for employees and eligible dependents.
  • Choose from multiple plan options with CareFirst, Kaiser, and UnitedHealthcare, including PPO, POS, HMO, and HSA-compatible plans.
  • 100% company-paid dental premiums for employees and eligible dependents.
  • 100% company-paid vision premiums for employees and eligible dependents.

Income Protection

  • 100% company-paid premiums for short-term disability.
  • 100% company-paid premiums for long-term disability.
  • 100% company-paid premiums for accidental death & dismemberment (AD&D).
  • 100% company-paid premiums for life insurance up to $200,000.

Retirement

  • 401(k) with immediate vesting: 4% company match plus a 4% non-elective company contribution (8% total).
  • 401(k) pre-tax and Roth options.

Leave

  • Up to 20 days of flexible paid time off (PTO).
  • 11 paid floating holidays.

Work-Life Balance

  • Flexible work schedules, including flex time and compressed work periods (contract and project-dependent).

About Base-2 Solutions

Delivers engineering and technology services for national security.

Year founded
2016
Employees
60
Organization type
Private
Headquarters
US

Similar jobs

Information System Security Officer roles near Washington, District of Columbia
1d
Save
Mark Applied
Hide
Information System Security Officer
Washington or Virginia
HybridFull Time
SAIC
SAICNASDAQ: SAIC: Provides government and defense clients with technology and engineering services.
Bachelor's degree and 9 years' experience, including 5 years in cybersecurity and FISMA. Requires one listed security certification, U.S. citizenship, and ability to obtain DHS Public Trust.
NIST Special Publication (SP) 800, FedRAMP, FISMA, Federal Information Processing Standards (FIPS), LAN, WAN
3d
Save
Mark Applied
Hide
Information System Security Officer (ISSO)
Annapolis Junction or Alexandria or Chantilly or Washington or Reston or McLean or Herndon or Bethesda or Catonsville or Frederick or Ashburn
$116k-$216k/yr OnsiteFull Time
IBM
IBMNew York Stock Exchange: IBM: Global technology providing enterprise software, cloud, and consulting.
2+ YOEBachelor's degree, Security+ certification, TS/SCI CI Poly clearance, RMF and NIST expertise, security control implementation, vulnerability management, continuous monitoring, and authorization experience.
NIST RMF, NIST SP 800-53 Rev. 5, AWS GovCloud, Azure Government
1w
Save
Mark Applied
Hide
Information System Security Officer
Stafford or Quantico
$104k-$173k/yr OnsiteFull Time
ManTech
ManTech: Provides technology solutions for defense and intelligence agencies.
6+ YOEBachelor's degree and 6 years of related experience, or 8 years without a degree; active Secret clearance; DoD 8140 intermediate certification; RMF, eMASS, NIST, and cybersecurity compliance experience.
Enterprise Mission Assurance Support Service (eMASS), NIST SP 800-53, CNSSI 1253, FIPS 199, FIPS 200, ECSM 018, Security Technical Implementation Guide (STIG), Authorization to Operate (ATO), Risk Management Framework (RMF), Information Assurance Vulnerability Management (IAVM)
1w
Save
Mark Applied
Hide
STIP Information System Security Officer
Stafford or Washington
$101k-$164k/yr RemoteFull Time
JRAD
JRAD: Provides technical research and defense support to federal agencies.
10+ YOEBachelor's degree in a technology or science field with 10 years of cybersecurity experience, or master's degree with 7 years. Requires CISSM, Security+, RMF/ATO expertise, DHS TSA suitability, and strong communication skills.
NIST 800-53, FISMA, Risk Management Framework (RMF), Cyber Security Assessment and Management (CSAM), Tenable Nessus, Zero Trust
1w
Save
Mark Applied
Hide
Information System Security Officer
Washington, District of Columbia, United States
$101k-$152k/yr OnsiteFull Time
Applied Information Sciences
Applied Information Sciences: Delivers cloud transformation and software engineering services to organizations.
9+ YOERequires 9+ years in computer science or cybersecurity, 7+ years as an ISSO or ISS engineer in a cleared environment, bachelor's degree or equivalent experience, DoD 8570/IAT III certification, and active Top Secret clearance.
Tenable Nessus, Security Center, Splunk, IBM Guardium, HP WebInspect, NMAP
1w
Save
Mark Applied
Hide
Information System Security Officer
Washington, D.C., District of Columbia, United States
$101k-$152k/yr OnsiteFull Time
Applied Information Sciences
Applied Information Sciences: Provides cloud transformation and software engineering services for enterprises.
9+ YOERequires 9+ years in computer science or cybersecurity, 7+ years as an ISSO or ISS Engineer in a cleared environment, a bachelor's degree or equivalent experience, IAT Level III certification, and an active Top Secret clearance.
Tenable Nessus, Security Center, Splunk, IBM Guardium, HP WebInspect, NMAP, Risk Management Framework (RMF), NIST 800-53
1w
Save
Mark Applied
Hide
Senior Information System Security Officer
Springfield, Virginia, United States
$121k-$266k/yr HybridFull Time
CACI
CACINYSE: CACI: Provides information technology and professional services to government clients.
10+ YOEU.S. citizenship, active Top Secret clearance, bachelor's degree, 10+ years in information security, and expertise in RMF, FISMA, NIST, DHS 4300 Series, and classified systems.
Risk Management Framework (RMF), FISMA, NIST, CSAM, RegScale, eMASS, Supply Chain Risk Management, Configuration Management Plans, System Security Plans (SSPs), Authority to Operate (ATO)
1w
Save
Mark Applied
Hide
Senior Information System Security Officer
Springfield, Virginia, United States
$121k-$266k/yr HybridFull Time
CACI International
CACI InternationalNYSE: CACI: Provides information technology and engineering services for government agencies.
10+ YOEBS/BA and 15 years applicable information security experience, including 10+ years required. Requires U.S. citizenship, active Top Secret clearance, classified systems and SCIF experience, and RMF expertise.
Risk Management Framework (RMF), FISMA, NIST, CSAM, RegScale, eMASS, GRC, Configuration Management Plans, System Security Plans (SSPs), FISMA Scorecard Analysis
This job has expired