Job Requirements
Bethesda, MD
Top Secret/SCI Polygraph Unspecified
Mid Level Career (5+ yrs experience)
Salary not specified
Join Premium to unlock estimated salaries
Job Description
Job Description
Position Summary
Base-2 Solutions is seeking a Senior Security Engineer to serve as the technical lead for day-to-day security activities supporting enterprise and isolated environments. This hands-on technical lead will provide technical leadership and oversight for security operations, vulnerability management, RMF/ATO support, continuous monitoring, and security engineering activities. The position is 100% on-site, with all work performed at the customer site in Bethesda, MD.
Essential Duties and Responsibilities
Required Qualifications
Preferred Qualifications
Required Education and Experience Equivalency
Required Certifications
Required Security Clearance
Pay & Benefit Highlights
Compensation
Health
Income Protection
Retirement
Leave
Work-Life Balance
NT
Position Summary
Base-2 Solutions is seeking a Senior Security Engineer to serve as the technical lead for day-to-day security activities supporting enterprise and isolated environments. This hands-on technical lead will provide technical leadership and oversight for security operations, vulnerability management, RMF/ATO support, continuous monitoring, and security engineering activities. The position is 100% on-site, with all work performed at the customer site in Bethesda, MD.
Essential Duties and Responsibilities
- Lead and coordinate day-to-day security operations, establish priorities, and assign and track activities across the security team.
- Provide technical leadership and guidance to security personnel, system administrators, engineers, and other technical teams.
- Lead vulnerability management from identification through closure, including analysis, prioritization, remediation, validation, and documentation.
- Coordinate vulnerability remediation across Windows, Linux, network, desktop support, and other engineering teams, and provide hands-on support for complex or high-priority issues as needed.
- Oversee and perform vulnerability scanning and analysis using ACAS, Tenable/Nessus, or equivalent technologies.
- Oversee implementation and validation of DISA STIGs and approved security configuration baselines across infrastructure systems.
- Ensure recurring security activities are performed, including audit log and account reviews, vulnerability reviews, security control validation, and continuous monitoring.
- Support and oversee RMF/ATO activities, including security documentation, control evidence, Body of Evidence (BoE), POA&Ms, and compliance with NIST SP 800-53, ICD 503, and applicable security directives.
- Work with the ISSM to translate security and compliance requirements into technical and operational activities and evaluate system or configuration changes for potential security impact.
- Provide security oversight and technical support for isolated or restricted environments, including vulnerability scanning, logging, patching, hardening, and security monitoring.
- Review security logs and events using Splunk or equivalent SIEM/log-management technologies and ensure identified issues are appropriately addressed.
- Develop and maintain repeatable security processes and procedures for vulnerability management, compliance monitoring, evidence collection, and security operations.
- Track security risks, deficiencies, remediation activities, and compliance status, and communicate status, risks, and recommendations to customer and program leadership.
- Participate in Technical Exchange Meetings (TEMs), security reviews, engineering meetings, and customer discussions related to system security and accreditation.
- Manage, supervise, and mentor security and technical staff as assigned.
Required Qualifications
- Education and relevant experience meeting an applicable pathway in the Required Education and Experience Equivalency section.
- Experience with application performance and latency problems related to security requirements from front, middle, and back end.
- Working experience with Windows Server 2016/2019, Active Directory, IIS, DNS, DHCP, Exchange, and DFS.
- Experience implementing security controls on common network services such as file, email, and Active Directory across multiple geographically dispersed sites.
- Experience with networking technologies and security assessment, including but not limited to STIGs.
- Experience implementing and supporting enterprise system security and malware monitoring and prevention tools such as Splunk, McAfee HBSS, and ACAS.
- Solid network and systems troubleshooting experience with TCP/IP, Internet security, and encryption, including data at rest and data in transit.
- Ability to produce clear and concise documents and diagrams capturing networking and operational procedures and LAN/WAN topology using MS Visio, MS Project, MS Excel, and MS Word.
- Candidate must, at a minimum, meet DoD 8570.11- IAT Level II certification requirements, currently Security+ CE, CCNA-Security, GSEC, or SSCP along with an appropriate computing environment (CE) certification.
- US Citizenship is required due to the nature of the government contracts we support.
Preferred Qualifications
- Experience managing and/or supervising a team of technical professionals.
- CISSP or CASP Certification.
Required Education and Experience Equivalency
- Bachelor's degree in Computer Science, Information Technology, or a related field with at least 8 years of relevant experience.
- Additional years of experience may be considered in lieu of degree.
Required Certifications
- Candidate must, at a minimum, meet DoD 8570.11- IAT Level II certification requirements (currently Security+ CE, CCNA-Security, GSEC, or SSCP along with an appropriate computing environment (CE) certification).
Required Security Clearance
- Active Top Secret/SCI
Pay & Benefit Highlights
Compensation
- Competitive fixed salary or hourly pay (based on experience, skills, location, and internal equity).
- Employee referral bonuses up to $10,000 per hired referral.
- Additional bonus opportunities for exceptional performance and contributions to business development and company growth (role-dependent).
Health
- 100% company-paid medical premiums for employees and eligible dependents.
- Choose from multiple plan options with CareFirst, Kaiser, and UnitedHealthcare, including PPO, POS, HMO, and HSA-compatible plans.
- 100% company-paid dental premiums for employees and eligible dependents.
- 100% company-paid vision premiums for employees and eligible dependents.
Income Protection
- 100% company-paid premiums for short-term disability.
- 100% company-paid premiums for long-term disability.
- 100% company-paid premiums for accidental death & dismemberment (AD&D).
- 100% company-paid premiums for life insurance up to $200,000.
Retirement
- 401(k) with immediate vesting: 4% company match plus a 4% non-elective company contribution (8% total).
- 401(k) pre-tax and Roth options.
Leave
- Up to 20 days of flexible paid time off (PTO).
- 11 paid floating holidays.
Work-Life Balance
- Flexible work schedules, including flex time and compressed work periods (contract and project-dependent).
NT
group id: 90984897