Senior Information System Security Officer
Position Summary
Base-2 Solutions is seeking a Senior Information System Security Officer to work with application leads, system administrators, database administrators, developers, and testers to ensure assigned systems are security compliant and achieve or maintain Authority to Operate (ATO). The role includes following the Risk Management Framework (RMF) process for full test, partial test, continuous monitoring (CONMON), and no test scenarios, updating Xacta documentation including System Security Plans (SSPs), Security Control Trace Matrices (SCTM), Security Test Plans (STPs), and Plans of Action and Milestones (POAMs).
The specialist will load artifacts such as Security Technical Implementation Guide (STIG) checklists and ACAS scans, help implement STIG checklists, mitigate scan findings, support security assessment events, and respond to questions from the Security Test and Evaluation (ST&E) team, Information System Security Managers (ISSMs), and Security Control Assessors (SCAs).
- Work with application leads, system administrators, database administrators, developers, and testers to ensure systems are security compliant and achieve or maintain ATO.
- Follow the RMF process for full test, partial test, continuous monitoring (CONMON), and no test.
- Update Xacta documentation including SSPs, SCTM, STPs, and POAMs.
- Load artifacts such as STIG checklists and ACAS scans.
- Help implement STIG checklists and mitigate scan findings.
- Answer questions to ensure systems are developed with security compliance built in.
- Support security assessment events and respond to all questions from the PAT team, ISSMs, and SCAs.
- Bachelor's degree in computer science, software engineering, or a field applicable to the position required.
- 19 or more years of relevant experience required with a Bachelor's degree.
- Additional experience may be considered in lieu of degree.
- Demonstrated experience in developing, implementing, and enforcing security policies, standards, and procedures to ensure regulatory compliance and protect organizational information assets.
- Proven track record in conducting risk assessments and identifying vulnerabilities in systems, networks, and applications.
- Experience in developing and overseeing implementation of mitigation strategies to reduce security risks.
- Strong background in monitoring systems and networks for security breaches and suspicious activity.
- Successful history of responding to security incidents, investigating root causes, and implementing corrective actions.
- Comprehensive knowledge of relevant laws, regulations, and industry standards.
- Experience conducting audits and assessments to verify adherence to security requirements.
Education and Experience Equivalency
- High School with 23 years of experience.
- Associate’s with 21 years of experience.
- Bachelor’s with 19 years of experience.
- Master’s with 17 years of experience.
- PhD with 15 years of experience.
- None specified.
- Active Top Secret/SCI with CI Polygraph
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).