Position
Summary Base-2 Solutions is seeking a dedicated and detail-oriented Information Systems Security Officer (ISSO) to join our team. Our ISSOs are responsible for ensuring the security posture of mission-critical systems by supporting compliance efforts, managing risk, and enforcing security policies. We're looking for individuals who excel at navigating complex cybersecurity environments, maintaining meticulous documentation, and fostering collaboration between technical teams and government stakeholders. The ideal candidate will have strong knowledge of security regulations, be adaptable, and possess excellent communication
skills to drive information security initiatives forward. Essential
Duties and
- Ensure system compliance with federal, DoD, and IC cybersecurity regulations and standards, including NIST, ICD 503, CNSS, and RMF.
- Maintain and update security documentation, including System Security Plans (SSPs), Security Assessment Reports (SARs), Plan of Action and Milestones (POA&Ms), and Continuous Monitoring Plans.
- Coordinate and support security assessments, audits, and inspections by internal and external stakeholders.
- Conduct risk assessments and vulnerability analysis, providing recommendations for mitigating identified risks.
- Facilitate and oversee system authorization activities in accordance with the Risk Management Framework (RMF) process.
- Monitor and report on system security posture, incident response, and remediation efforts.
- Collaborate with Information Systems Security Engineers (ISSEs), system administrators, and program managers to integrate security
- Provide security awareness training to system users and enforce proper security practices.
- Act as a liaison between the organization and government customers, ensuring timely communication of security updates and issues. Required
Qualifications
- Experience with security frameworks and policies: NIST SP 800-53, RMF, ICD 503, CNSS, DoD STIGs, FISMA, FedRAMP.
- Experience managing security documentation: SSPs, POA&Ms, Security Controls Assessment (SCA) artifacts, SARs, SCTM.
- Experience with security tools such as ACAS, Nessus, Splunk, HBSS, eMASS, Xacta.
- Knowledge of security technologies: Firewalls, SIEMs, VPNs, IDS/IPS, DLP, PKI, Multi-Factor Authentication.
- Experience with operating systems: Windows, Linux, Unix, macOS.
- Experience with Cloud environments (AWS, Azure, Google Cloud) and cloud security controls.
- Familiarity with vulnerability scanning, security testing, and incident response processes.
•
- Strong knowledge of system authorization process, audit support, and compliance reporting.
- Security certifications such as CISSP, CAP, Security+, CISM, CEH, AWS Security Specialty.
Preferred
Qualifications
Education and
- None specified. Required Certifications
- CISSP
- CAP
- Security+
- CISM
- CEH
- AWS Security Specialty Required Security
Clearance
- Active Top Secret/SCI with Full Scope Polygraph