
Senior Security Engineer
Base-2 Solutions, LLC
๐บ๐ธ United States
Senior
11 hours ago
- Vulnerability Management
- RMF
- Windows
- Linux
- Tenable
- Nessus
- STIGs
- Splunk
- SIEM
- Windows Server
- Active Directory
- IIS
- DNS
- DHCP
- TCP/IP
- Visio
- MS Project
- Excel
- CCNA
- GSEC
- CISSP
11 hours ago
Position Summary
Base-2 Solutions is seeking a Senior Security Engineer to serve as the technical lead for day-to-day security activities supporting enterprise and isolated environments. This hands-on technical lead will provide technical leadership and oversight for security operations, vulnerability management, RMF/ATO support, continuous monitoring, and security engineering activities. The position is 100% on-site, with all work performed at the customer site in Bethesda, MD.
Essential Duties and Responsibilities
- Lead and coordinate day-to-day security operations, establish priorities, and assign and track activities across the security team.
- Provide technical leadership and guidance to security personnel, system administrators, engineers, and other technical teams.
- Lead vulnerability management from identification through closure, including analysis, prioritization, remediation, validation, and documentation.
- Coordinate vulnerability remediation across Windows, Linux, network, desktop support, and other engineering teams, and provide hands-on support for complex or high-priority issues as needed.
- Oversee and perform vulnerability scanning and analysis using ACAS, Tenable/Nessus, or equivalent technologies.
- Oversee implementation and validation of DISA STIGs and approved security configuration baselines across infrastructure systems.
- Ensure recurring security activities are performed, including audit log and account reviews, vulnerability reviews, security control validation, and continuous monitoring.
- Support and oversee RMF/ATO activities, including security documentation, control evidence, Body of Evidence (BoE), POA&Ms, and compliance with NIST SP 800-53, ICD 503, and applicable security directives.
- Work with the ISSM to translate security and compliance requirements into technical and operational activities and evaluate system or configuration changes for potential security impact.
- Provide security oversight and technical support for isolated or restricted environments, including vulnerability scanning, logging, patching, hardening, and security monitoring.
- Review security logs and events using Splunk or equivalent SIEM/log-management technologies and ensure identified issues are appropriately addressed.
- Develop and maintain repeatable security processes and procedures for vulnerability management, compliance monitoring, evidence collection, and security operations.
- Track security risks, deficiencies, remediation activities, and compliance status, and communicate status, risks, and recommendations to customer and program leadership.
- Participate in Technical Exchange Meetings (TEMs), security reviews, engineering meetings, and customer discussions related to system security and accreditation.
- Manage, supervise, and mentor security and technical staff as assigned.
Required Qualifications
- Education and relevant experience meeting an applicable pathway in the Required Education and Experience Equivalency section.
- Experience with application performance and latency problems related to security requirements from front, middle, and back end.
- Working experience with Windows Server 2016/2019, Active Directory, IIS, DNS, DHCP, Exchange, and DFS.
- Experience implementing security controls on common network services such as file, email, and Active Directory across multiple geographically dispersed sites.
- Experience with networking technologies and security assessment, including but not limited to STIGs.
- Experience implementing and supporting enterprise system security and malware monitoring and prevention tools such as Splunk, McAfee HBSS, and ACAS.
- Solid network and systems troubleshooting experience with TCP/IP, Internet security, and encryption, including data at rest and data in transit.
- Ability to produce clear and concise documents and diagrams capturing networking and operational procedures and LAN/WAN topology using MS Visio, MS Project, MS Excel, and MS Word.
- Candidate must, at a minimum, meet DoD 8570.11- IAT Level II certification requirements, currently Security+ CE, CCNA-Security, GSEC, or SSCP along with an appropriate computing environment (CE) certification.
- US Citizenship is required due to the nature of the government contracts we support.
Preferred Qualifications
- Experience managing and/or supervising a team of technical professionals.
- CISSP or CASP Certification.
Required Education and Experience Equivalency
- Bachelor's degree in Computer Science, Information Technology, or a related field with at least 8 years of relevant experience.
- Additional years of experience may be considered in lieu of degree.
Required Certifications
- Candidate must, at a minimum, meet DoD 8570.11- IAT Level II certification requirements (currently Security+ CE, CCNA-Security, GSEC, or SSCP along with an appropriate computing environment (CE) certification).
Required Security Clearance
- Active Top Secret/SCI
Senior Security Engineer ยท Base-2 Solutions, LLC