Likeremote

Subscribe to the latest remote jobs:

  • Likeremote jobs on https://LinkedIn.com/
  • Likeremote jobs on https://telegram.org/
  • Likeremote jobs on Reddit.com

Senior Security Engineer

Base-2 Solutions, LLC
๐Ÿ‡บ๐Ÿ‡ธ United States
Senior
11 hours ago
  • Vulnerability Management
  • RMF
  • Windows
  • Linux
  • Tenable
  • Nessus
  • STIGs
  • Splunk
  • SIEM
  • Windows Server
  • Active Directory
  • IIS
  • DNS
  • DHCP
  • TCP/IP
  • Visio
  • MS Project
  • Excel
  • CCNA
  • GSEC
  • CISSP
Not scoredNo CV on file. Upload one and this job gets a score out of 100.Upload CV

Position Summary

Base-2 Solutions is seeking a Senior Security Engineer to serve as the technical lead for day-to-day security activities supporting enterprise and isolated environments. This hands-on technical lead will provide technical leadership and oversight for security operations, vulnerability management, RMF/ATO support, continuous monitoring, and security engineering activities. The position is 100% on-site, with all work performed at the customer site in Bethesda, MD.

Essential Duties and Responsibilities

  • Lead and coordinate day-to-day security operations, establish priorities, and assign and track activities across the security team.
  • Provide technical leadership and guidance to security personnel, system administrators, engineers, and other technical teams.
  • Lead vulnerability management from identification through closure, including analysis, prioritization, remediation, validation, and documentation.
  • Coordinate vulnerability remediation across Windows, Linux, network, desktop support, and other engineering teams, and provide hands-on support for complex or high-priority issues as needed.
  • Oversee and perform vulnerability scanning and analysis using ACAS, Tenable/Nessus, or equivalent technologies.
  • Oversee implementation and validation of DISA STIGs and approved security configuration baselines across infrastructure systems.
  • Ensure recurring security activities are performed, including audit log and account reviews, vulnerability reviews, security control validation, and continuous monitoring.
  • Support and oversee RMF/ATO activities, including security documentation, control evidence, Body of Evidence (BoE), POA&Ms, and compliance with NIST SP 800-53, ICD 503, and applicable security directives.
  • Work with the ISSM to translate security and compliance requirements into technical and operational activities and evaluate system or configuration changes for potential security impact.
  • Provide security oversight and technical support for isolated or restricted environments, including vulnerability scanning, logging, patching, hardening, and security monitoring.
  • Review security logs and events using Splunk or equivalent SIEM/log-management technologies and ensure identified issues are appropriately addressed.
  • Develop and maintain repeatable security processes and procedures for vulnerability management, compliance monitoring, evidence collection, and security operations.
  • Track security risks, deficiencies, remediation activities, and compliance status, and communicate status, risks, and recommendations to customer and program leadership.
  • Participate in Technical Exchange Meetings (TEMs), security reviews, engineering meetings, and customer discussions related to system security and accreditation.
  • Manage, supervise, and mentor security and technical staff as assigned.

Required Qualifications

  • Education and relevant experience meeting an applicable pathway in the Required Education and Experience Equivalency section.
  • Experience with application performance and latency problems related to security requirements from front, middle, and back end.
  • Working experience with Windows Server 2016/2019, Active Directory, IIS, DNS, DHCP, Exchange, and DFS.
  • Experience implementing security controls on common network services such as file, email, and Active Directory across multiple geographically dispersed sites.
  • Experience with networking technologies and security assessment, including but not limited to STIGs.
  • Experience implementing and supporting enterprise system security and malware monitoring and prevention tools such as Splunk, McAfee HBSS, and ACAS.
  • Solid network and systems troubleshooting experience with TCP/IP, Internet security, and encryption, including data at rest and data in transit.
  • Ability to produce clear and concise documents and diagrams capturing networking and operational procedures and LAN/WAN topology using MS Visio, MS Project, MS Excel, and MS Word.
  • Candidate must, at a minimum, meet DoD 8570.11- IAT Level II certification requirements, currently Security+ CE, CCNA-Security, GSEC, or SSCP along with an appropriate computing environment (CE) certification.
  • US Citizenship is required due to the nature of the government contracts we support.

Preferred Qualifications

  • Experience managing and/or supervising a team of technical professionals.
  • CISSP or CASP Certification.

Required Education and Experience Equivalency

  • Bachelor's degree in Computer Science, Information Technology, or a related field with at least 8 years of relevant experience.
  • Additional years of experience may be considered in lieu of degree.

Required Certifications

  • Candidate must, at a minimum, meet DoD 8570.11- IAT Level II certification requirements (currently Security+ CE, CCNA-Security, GSEC, or SSCP along with an appropriate computing environment (CE) certification).

Required Security Clearance

  • Active Top Secret/SCI

Senior Security Engineer ยท Base-2 Solutions, LLC

Auto apply with Likeremote