Information Systems Security Officer (ISSO)

Credence Management Solutions, LLC
Arlington, VA, United States
3 days ago
Apply on www.clearancejobs.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$95,000.0 - $132,000.0
Working hours
Regular working hours

Tech stack

Cloud Computing Security CompTIA Security+ Cyber Security Information Systems Computer Engineering Internet Information Services (IIS) Information Technology Plan of Action and Milestones

Job description

Credence has an immediate need for an Information Systems Security Officer (ISSO) to support federal cybersecurity compliance, risk management, and authorization activities within a complex government environment. The ISSO will serve as a key security and compliance resource, supporting Authority to Operate (ATO) efforts, continuous monitoring activities, security documentation, risk assessments, and implementation validation of NIST security controls.

The successful candidate will work closely with government stakeholders, technical teams, and compliance personnel to ensure systems remain secure, compliant, and operationally effective.

Responsibilities include, but are not limited to the duties listed below

  • Serve as the primary point of contact (POC) to Lead Security Impact Analysis (SIA) and NOC packages
  • Serve as the primary point of contact (POC) for compliance-related questions by client, RPC, and other stakeholders (except RSCs)
  • Serve as the primary point of contact (POC) for ATO efforts for RPC systems:

  • Privacy Impact Assessment (PIA);Perform risk analysis and risk assessments on proposed changes
  • Information System Contingency Plan (ISCP) - will maintain and coordinate updates annually
  • Contingency Plan Testing - conducted and documented annually
  • SSP updates
  • Cyber Table Top/Testing requirements - Support conducting and documenting annually to meet requirements
  • POA&M management

  • Serve as the primary point of contact (POC) for ISSO Checklist (monthly, quarterly, annual)
  • Support compliance-based data call requests where necessary
  • Participate in IRB, CCB, A&A, M21-31, and other policy meetings
  • Ensure security controls are being met (NIST 800-53 control implementation validation)
  • Keep ArchAngel updated with system changes (boundary diagrams, connection table, POCs…)
  • Participate on IIS daily calls (once a week)
  • Support Compliance meetings with client(s): currently bi-weekly Government Sync with ISO and Monthly AODR Check-in
  • Monthly continuous monitoring deliverables (ISSO checklist, and recurring account validation)
  • Customer responsibility matrix maintenance
  • Evaluate security tools and verify that all have obtained required FedRAMP and TRB approvals prior to integration into the environment

Requirements

  • Active Secret security clearance required.
  • Bachelor’s degree in Cybersecurity, Information Assurance, Information Systems, Computer Science, Computer Engineering, Mathematics, or a related field.
  • Three (3) to five (5) years of relevant professional experience supporting information security, cybersecurity compliance, risk management, or related IT security functions.
  • Experience supporting security authorization and compliance activities within federal, government, or highly regulated environments.
  • Knowledge of Risk Management Framework (RMF) principles and NIST SP 800-53 security controls.
  • Experience developing or maintaining security documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), risk assessments, and contingency plans.
  • Experience supporting continuous monitoring and security compliance activities.
  • Strong analytical, organizational, documentation, and communication skills.

Preferred Qualifications

  • Security+, CAP, CISSP, CISM, or other relevant cybersecurity certifications.
  • Experience supporting Assessment and Authorization (A&A) or Authority to Operate (ATO) activities.
  • Familiarity with FedRAMP, cloud security, and federal cybersecurity compliance requirements.
  • Experience supporting government customers and stakeholders.

Benefits & conditions

Salary Range: $95,000 - $132,000 annually. Actual compensation will be determined based on factors such as experience, education, certifications, security clearance status, and internal equity., * Health Care Plan (Medical, Dental & Vision)

  • Retirement Plan (401k, IRA)
  • Life Insurance (Basic, Voluntary & AD&D)
  • Paid Time Off (Vacation, Sick & Public Holidays)
  • Family Leave (Maternity, Paternity)
  • Short Term & Long Term Disability
  • Training & Development
  • Wellness Resources

About the company

Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With 1,700+ team members, 1,500+ AI/data experts, and 100+ prime contracts, we deliver at scale and with purpose.

We’ve been recognized as a Top Workplace by the Washington Post for six straight years and named to the Inc. 5000 Fastest Growing Private Companies 13 of the past 14 years. Credence is a welcoming home for those looking to grow and contribute to positive change. We encourage all employees to expand beyond their boundaries, dive into important world-changing Federal challenges.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.clearancejobs.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

5:03 min

Navigating new cybersecurity compliance frameworks and laws

Kurt Eder · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:28 min

Preventing sensitive information disclosure in RAG systems

Deepu Deepu · World Congress 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all