Position
Summary Base-2 Solutions is seeking an Information System Security Officer to work with application leads, system administrators, database administrators, developers, and testers to ensure assigned systems are security compliant and achieve or maintain Authority to Operate (ATO). The role includes following the Risk Management Framework (RMF) process for full test, partial test, continuous monitoring (CONMON), and no test scenarios, updating Xacta documentation such as System Security Plans (SSPs), Security Control Trace Matrices (SCTM), Security Test Plans (STPs), and Plans of Action and Milestones (POAMs), loading artifacts including STIG checklists and ACAS scans, implementing STIG checklists and mitigating scan findings, supporting security assessment events, and responding to inquiries from the Security Test and Evaluation (PAT) team, Information System Security Managers (ISSMs), and Security Control Assessors (SCAs). Essential
Duties and
- Work with application leads, system administrators, database administrators, developers, and testers to ensure systems are security compliant and achieve or maintain ATO.
- Follow the RMF process for full test, partial test, CONMON, and no test.
- Update Xacta documentation including SSPs, SCTM, STPs, and POAMs.
- Load artifacts such as STIG checklists and ACAS scans.
- Help implement STIG checklists and mitigate scan findings.
- Answer questions to ensure systems are developed with security compliance built in.
- Support security assessment events and respond to all questions from PAT team, ISSMs, and SCAs. Required
- Bachelor's degree in computer science, software engineering, or a field applicable to the position required.
- 9 or more years of relevant
experience required with a Bachelor's degree.
experience may be considered in lieu of degree.
experience in developing, implementing, and enforcing security policies, standards, and procedures to ensure regulatory compliance and protect organizational information assets.
- Proven track record in conducting risk assessments and identifying vulnerabilities in systems, networks, and applications.
•
- Strong background in monitoring systems and networks for security breaches and suspicious activity.
- Successful history of responding to security incidents, investigating root causes, and implementing corrective actions.
Preferred
Qualifications
- Comprehensive knowledge of relevant laws, regulations, and industry standards.
- Experience conducting audits and assessments to verify adherence to security
requirements. Required
Education and
Experience Equivalency
- High School with 13 years of
experience.
- Associates with 11 years of
experience.
- Bachelor's with 9 years of
experience.
experience.
experience. Required Certifications
- None specified. Required Security
Clearance
- Active Top Secret/SCI with CI Polygraph