Information Systems Security Officer (ISSO)

Credence

$95K — $132K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Active Secret security clearance required.
  • Bachelor's degree in Cybersecurity, Information Assurance, or related field.
  • 3-5 years of experience in information security or compliance.
  • Experience in federal government security authorization and compliance activities.
  • Knowledge of NIST SP 800-53 security controls and RMF principles.
  • Experience in developing security documentation like SSPs and POA&Ms.
  • Strong analytical and communication skills.

Responsibilities

  • Lead Security Impact Analysis (SIA) and NOC packages as point of contact.
  • Address compliance queries from clients and stakeholders.
  • Oversee ATO efforts for RPC systems, including risk assessments.
  • Maintain and update Information System Contingency Plans (ISCPs).
  • Conduct annual contingency plan testing and document results.
  • Manage ISSO Checklist compliance on a monthly and quarterly basis.
  • Evaluate security tools for FedRAMP and TRB approvals before integration.

Benefits

  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Family Leave (Maternity, Paternity)
  • Short Term & Long Term Disability
  • Training & Development
  • Wellness Resources
Full Job Description
Position Summary

Credence has an immediate need for an Information Systems Security Officer (ISSO) to support federal cybersecurity compliance, risk management, and authorization activities within a complex government environment. The ISSO will serve as a key security and compliance resource, supporting Authority to Operate (ATO) efforts, continuous monitoring activities, security documentation, risk assessments, and implementation validation of NIST security controls.

The successful candidate will work closely with government stakeholders, technical teams, and compliance personnel to ensure systems remain secure, compliant, and operationally effective.

Responsibilities include, but are not limited to the duties listed below
    • Serve as the primary point of contact (POC) to Lead Security Impact Analysis (SIA) and NOC packages
    • Serve as the primary point of contact (POC) for compliance-related questions by client, RPC, and other stakeholders (except RSCs)
    • Serve as the primary point of contact (POC) for ATO efforts for RPC systems:
      • Privacy Impact Assessment (PIA);Perform risk analysis and risk assessments on proposed changes
      • Information System Contingency Plan (ISCP) - will maintain and coordinate updates annually
      • Contingency Plan Testing - conducted and documented annually
      • SSP updates
      • Cyber Table Top/Testing requirements - Support conducting and documenting annually to meet requirements
      • POA&M management
    • Serve as the primary point of contact (POC) for ISSO Checklist (monthly, quarterly, annual)
    • Support compliance-based data call requests where necessary
    • Participate in IRB, CCB, A&A, M21-31, and other policy meetings
    • Ensure security controls are being met (NIST 800-53 control implementation validation)
    • Keep ArchAngel updated with system changes (boundary diagrams, connection table, POCs...)
    • Participate on IIS daily calls (once a week)
    • Support Compliance meetings with client(s): currently bi-weekly Government Sync with ISO and Monthly AODR Check-in
    • Monthly continuous monitoring deliverables (ISSO checklist, and recurring account validation)
    • Customer responsibility matrix maintenance
    • Evaluate security tools and verify that all have obtained required FedRAMP and TRB approvals prior to integration into the environment

Requirements

  • Active Secret security clearance required.
  • Bachelor's degree in Cybersecurity, Information Assurance, Information Systems, Computer Science, Computer Engineering, Mathematics, or a related field.
  • Three (3) to five (5) years of relevant professional experience supporting information security, cybersecurity compliance, risk management, or related IT security functions.
  • Experience supporting security authorization and compliance activities within federal, government, or highly regulated environments.
  • Knowledge of Risk Management Framework (RMF) principles and NIST SP 800-53 security controls.
  • Experience developing or maintaining security documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), risk assessments, and contingency plans.
  • Experience supporting continuous monitoring and security compliance activities.
  • Strong analytical, organizational, documentation, and communication skills.


Preferred Qualifications
  • Security+, CAP, CISSP, CISM, or other relevant cybersecurity certifications.
  • Experience supporting Assessment and Authorization (A&A) or Authority to Operate (ATO) activities.
  • Familiarity with FedRAMP, cloud security, and federal cybersecurity compliance requirements.
  • Experience supporting government customers and stakeholders.


Salary Range: $95,000 - $132,000 annually. Actual compensation will be determined based on factors such as experience, education, certifications, security clearance status, and internal equity.

Benefits
  • Health Care Plan (Medical, Dental & Vision)
  • Retirement Plan (401k, IRA)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Family Leave (Maternity, Paternity)
  • Short Term & Long Term Disability
  • Training & Development
  • Wellness Resources

Similar Jobs

More Jobs at Credence

More Information Technology Jobs

Find similar Information Systems Security Officer (ISSO) jobs: