> Markdown version of [/jobs/ext/1932174-information-systems-security-officer-isso](https://www.wearedevelopers.com/jobs/ext/1932174-information-systems-security-officer-isso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Systems Security Officer (ISSO) - **Company:** Credence Management Solutions, LLC - **Location:** Arlington, VA, United States - **Experience:** Expert - **Salary:** $120,000.0 - $170,000.0 - **Contract:** Permanent contract - **Skills:** Configuration Management, Cyber Security, Federal Information Processing Standards (FIPS), Information Security Management, SC Clearance, Information Technology, Plan of Action and Milestones, Vulnerability Analysis - **Published:** August 5, 2026 - **Apply:** https://www.clearancejobs.com/jobs/9076564/information-systems-security-officer-isso ## About the Role * Secret clearance is required * Bachelor's Degree (or significant equivalent experience) * Minimum 8 years of experience * Must possess certification(s) in CISSP, CISA, or CISM * Must be able to function resourcefully and independently and work with a diverse team of IA/cybersecurity practitioners * Strong written and verbal communication skills required * Experience working within DOJ Offices, Boards, and Divisions (OBDs), with an understanding of unique organizational security policies and security controls implementations within specific IT environments is desired. ## Description Credence is seeking an Information System Security Officer (ISSO) to provide IT professional support for Information System Security Officer (ISSO) and Security Control Assessment (SCA) activities, working with United States Marshals Service (USMS) system owners and other operations and maintenance (O&M) staff to ensure compliance with DOJ security requirements and standards for the USMS P30 system., The ISSO support will include developing and maintaining an IT System Security Compliance Schedule covering 12-month intervals that capture POA&M Action Items, required ITSS reports/updates, Change Control Board Meetings, Scheduled Vulnerability Scans, and Updates to System IT Security Documentation. Support includes the following: * Advise the systems owner on the security posture of their systems. * Perform assessment and authorization (A&A) activities on classified and unclassified networks in accordance with the DOJ/NIST Risk Management Framework (RMF). * Develop and update artifacts for all control families (Security Categorization, SSP, Contingency Planning, Incident Response, Configuration Management, etc.). * Perform compliance assessment reviews, tracking, and continuous monitoring of multiple networks, systems, and applications. * Advise stakeholders throughout the entire lifecycle of the A&A process to include the development of Systems Security Plans (SSP). * Perform System Categorization in accordance with FIPS-199 and CNSS 1253. * Perform security control assessments in accordance with NIST 800-53A. * Develop/edit/review Security Assessment Plans using CSAM. * Perform risk analysis and prepare reports on networks, facilities and systems. * Review, create and validate Security Assessment Reports. * Develop and maintain the Plan of Action and Milestones (POA&M) statements, and support remediation activities through their lifecycle. * Support Incident Response and Contingency activities. * Perform security impact analysis on all configuration change requests. * Review information in support of DOJ OCIO review for FISMA inventory ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 216: CyberSec + Mythos, Stack Overflow for Agents & DOOM in TTF](https://www.wearedevelopers.com/magazine/728-dev-digest-216-cybersec-mythos-stack-overflow-for-agents-doom-in-ttf) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)