About this opportunity
RPMGlobal lists this Senior Security Engineer opportunity in bethesda, Maryland. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Position Summary
Base-2 Solutions is seeking a Senior Security Engineer to serve as the technical lead for day-to-day security activities supporting enterprise and isolated environments. This hands‑on technical lead will provide technical leadership and oversight for security operations, vulnerability management, RMF/ATO support, continuous monitoring, and security engineering activities. The position is 100% on‑site, with all work performed at the customer site in Bethesda, MD.
Essential Duties and Responsibilities
Lead and coordinate day‑to‑day security operations, establish priorities, and assign and track activities across the security team.
Provide technical leadership and guidance to security personnel, system administrators, engineers, and other technical teams.
Lead vulnerability management from identification through closure, including analysis, prioritization, remediation, validation, and documentation.
Coordinate vulnerability remediation across Windows, Linux, network, desktop support, and other engineering teams, and provide hands‑on support for complex or high‑priority issues as needed.
Oversee and perform vulnerability scanning and analysis using ACAS, Tenable/Nessus, or equivalent technologies.
Oversee implementation and validation of DISA STIGs and approved security configuration baselines across infrastructure systems.
Ensure recurring security activities are performed, including audit log and account reviews, vulnerability reviews, security control validation, and continuous monitoring.
Support and oversee RMF/ATO activities, including security documentation, control evidence, Body of Evidence (BoE), POA&Ms, and compliance with NIST SP 800‑53, ICD 503, and applicable security directives.
Work with the ISSM to translate security and compliance requirements into technical and operational activities and evaluate system or configuration changes for potential security impact.
Provide security oversight and technical support for isolated or restricted environments, including vulnerability scanning, logging, patching, hardening, and security monitoring.
Review security logs and events using Splunk or equivalent SIEM/log‑management technologies and ensure identified issues are appropriately addressed.
Develop and maintain repeatable security processes and procedures for vulnerability management, compliance monitoring, evidence collection, and security operations.
Track security risks, deficiencies, remediation activities, and compliance status, and communicate status, risks, and recommendations to customer and program leadership.
Participate in Technical Exchange Meetings (TEMs), security reviews, engineering meetings, and customer discussions related to system security and accreditation.
Manage, supervise, and mentor security and technical staff as assigned.
Required Qualifications
Education and relevant experience meeting an applicable pathway in the Required Education and Experience Equivalency section.
Experience with application performance and latency problems related to security requirements from front, middle, and back end.
Working experience with Windows Server 2016/2019, Active Directory, IIS, DNS, DHCP, Exchange, and DFS.
Experience implementing security controls on common network services such as file, email, and Active Directory across multiple geographically dispersed sites.
Experience with networking technologies and security assessment, including but not limited to STIGs.
Experience implementing and supporting enterprise system security and malware monitoring and prevention tools such as Splunk, McAfee HBSS, and ACAS.
Solid network and systems troubleshooting experience with TCP/IP, Internet security, and encryption, including data at rest and data in transit.
Ability to produce clear and concise documents and diagrams capturing networking and operational procedures and LAN/WAN topology using MS Visio, MS Project, MS Excel, and MS Word.
Candidate must, at a minimum, meet DoD ‑ IAT Level II certification requirements, currently Security+ CE, CCNA‑Security, GSEC, or SSCP along with an appropriate computing environment (CE) certification.
US Citizenship is required due to the nature of the government contracts we support.
Preferred Qualifications
Experience managing and/or supervising a team of technical professionals.
CISSP or CASP Certification.
Required Education and Experience Equivalency
Bachelor's degree in Computer Science, Information Technology, or a related field with at least 8 years of relevant experience.
Additional years of experience may be considered in lieu of degree.
Required Certifications
Candidate must, at a minimum, meet DoD ‑ IAT Level II certification requirements (currently Security+ CE, CCNA‑Security, GSEC, or SSCP along with an appropriate computing environment (CE) certification).
Required Security Clearance
Active Top Secret/SCI
#J-18808-Ljbffr
Worksite address
bethesda, MD, 20811, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.