
Cyber Security Engineer 4
Base-2 Solutions, LLC
🇺🇸 United States
4 days ago
- RMF
- STIGs
- Incident Response
- CISSP
- CSSLP
- OWASP
- SonarQube
- Tenable
- Microsoft Windows
- Linux
- Unix
- TCP/IP
- CI/CD
- NIST
- CMMC
- Python
- Java
- React.js
- GitLab
- Jira
- Confluence
- Agile
- OIDC
- OAuth2
- Kubernetes
- Active Directory
- Bash
- PowerShell
4 days ago
Position Summary
Support multiple task orders under the DOMEX Technology Platform contract supporting NMEC by designing, developing, and implementing secure systems in on-premises infrastructure and integrating security across the system lifecycle.
Essential Duties and Responsibilities
- Support the secure architecture, design, and implementation of DoD systems in accordance with DoDI 8510.01, NIST SP 800-53, and other DoD security guidance.Â
- Lead integration of RMF activities into the SDLC, including selection, implementation, and validation of security controls.Â
- Develop and maintain SSPs, SARs, risk assessments, and POA&Ms.Â
- Apply STIGs and validate compliance using SCAP, STIG Viewer, and ACAS.Â
- Maintain scanning infrastructure and analyze vulnerabilities for mitigation or risk acceptance.Â
- Support system authorization, incident response, forensics analysis, and security automation efforts.
Required Qualifications
- Active TS/SCI with ability to obtain a CI Polygraph.
- Bachelor's degree with a minimum of ten years of experience in the category field.
- At least one DoD 8570.01-M IASAE Level II certification: CISSP, CISSP-ISSAP, CISSP-ISSEP, CSSLP, or CASP+ CE.Â
- Developer experience preferred in at least one scripting or programming language.Â
- Experience reviewing cybersecurity vulnerabilities for risk and relevance and building mitigation/remediation plans across systems, network, application, and database vulnerabilities.Â
- Ability to architect, design, troubleshoot, maintain, and deploy vulnerability scanning solutions such as OWASP, Fortify, SonarQube, and Tenable.Â
- Experience with XACTA, eMASS, or similar tools.Â
- Strong understanding of Microsoft Windows and Linux/UNIX operating systems.Â
- Experience with middleware/web technologies, databases, TCP/IP networking, and CI/CD platforms.Â
- Familiarity with NIST 800-171, 800-172, NIST SSDF, CMMC, and CNSSI 1253.Â
- Experience supporting DoD/IC systems through the RMF+ process.
Preferred Qualifications
- Software development experience with Python, Java, or React.
- Experience successfully achieving ATO under RMF+.Â
- Experience with big data applications.Â
- Experience with GitLab, Jira, and Confluence.Â
- Experience in Agile environments.Â
- Experience with OIDC or OAuth2.Â
- Experience with Kubernetes, Rancher, Strimzi, Cloudera, Active Directory, and scripting languages such as Bash, Python, or PowerShell.
Required Education and Experience Equivalency
- Bachelors' Degree with 10 years of experience.
- Masters' Degree with 10 years of experience.
- PhD with 10 years of experience.
Required Certifications
- One DoD 8570.01-M IASAE Level II certification: CISSP, CISSP-ISSAP, CISSP-ISSEP, CSSLP, or CASP+ CE.
Required Security Clearance
- Active TS/SCI with ability to obtain a CI Polygraph.
Cyber Security Engineer 4 · Base-2 Solutions, LLC