Cyber Security Engineer 2
Job Description
Base-2 Solutions supports mission-focused teams building secure systems for on-premises infrastructure through the DOMEX Technology Platform contract supporting NMEC. This onsite role in Bethesda, MD combines security engineering work across the system lifecycle with opportunities to strengthen your impact through RMF-aligned practices, compliance validation, and security automation.
You will support multiple task orders by designing, developing, and implementing secure systems in accordance with applicable DoD and NIST guidance, while integrating security activities into the SDLC. Work includes RMF integration, SSP/SAR and related documentation, STIG compliance validation, vulnerability scanning, and support for system authorization, incident response, forensics analysis, and automation.
Responsibilities
- Support secure architecture, design, and implementation of DoD systems in alignment with DoDI 8510.01, NIST SP 800-53, and other DoD security guidance.
- Lead integration of RMF activities into the SDLC, including selection, implementation, and validation of security controls.
- Develop and maintain SSPs, SARs, risk assessments, and POA&Ms.
- Apply STIGs and validate compliance using SCAP, STIG Viewer, and ACAS.
- Maintain scanning infrastructure and analyze vulnerabilities to support mitigation or risk acceptance decisions.
- Support system authorization, incident response, forensics analysis, and security automation efforts.
Requirements
- Active TS/SCI with ability to obtain a CI Polygraph.
- Bachelor's degree with a minimum of 3 years of experience in the category field. Two additional years of experience may be substituted for the bachelor's degree.
- At least one DoD 8570.01-M IASAE Level II certification: CISSP, CISSP-ISSAP, CISSP-ISSEP, CSSLP, or CASP+ CE.
- Preferred developer experience in at least one scripting or programming language.
- Experience reviewing cybersecurity vulnerabilities for risk and relevance, and building mitigation or remediation plans across systems, network, application, and database vulnerabilities.
- Ability to architect, design, troubleshoot, maintain, and deploy vulnerability scanning solutions such as OWASP, Fortify, SonarQube, and Tenable.
- Experience with XACTA, eMASS, or similar tools.
- Strong understanding of Microsoft Windows and Linux/UNIX operating systems.
- Experience with middleware/web technologies, databases, TCP/IP networking, and CI/CD platforms.
- Familiarity with NIST 800-171, NIST 800-172, NIST SSDF, CMMC, and CNSSI 1253.
- Experience supporting DoD/IC systems through the RMF+ process.
Technologies
Python, Java, React, OWASP, Fortify, SonarQube, Tenable, XACTA, eMASS, SCAP, STIG Viewer, ACAS, CISSP, CISSP-ISSAP, CISSP-ISSEP, CSSLP, CASP+ CE, NIST SP 800-53, DoDI 8510.01, DoD 8570.01-M IASAE, NIST 800-171, NIST 800-172, NIST SSDF, CMMC, CNSSI 1253, RMF, SDLC, RMF+, TCP/IP, CI/CD, Kubernetes, Rancher, Strimzi, Cloudera, Active Directory, Bash, PowerShell, GitLab, Jira, Confluence, OIDC, OAuth2
Benefits
- Competitive fixed salary or hourly pay (based on experience, skills, location, and internal equity).
- Employee referral bonuses up to $10,000 per hired referral.
- Additional bonus opportunities for exceptional performance and contributions to business development and company growth (role-dependent).
- 100% company-paid medical premiums for employees and eligible dependents. Multiple plan options with CareFirst, Kaiser, and UnitedHealthcare, including PPO, POS, HMO, and HSA-compatible plans.
- 100% company-paid dental premiums for employees and eligible dependents.
- 100% company-paid vision premiums for employees and eligible dependents.
- 100% company-paid premiums for short-term disability, long-term disability, AD&D, and life insurance up to $200,000.
- 401(k) with immediate vesting: 4% company match plus a 4% non-elective company contribution (8% total). Pre-tax and Roth options.
- Up to 20 days of flexible paid time off (PTO) plus 11 paid floating holidays.
- Flexible work schedules including flex time and compressed work periods (contract and project-dependent).