Information Systems Security Officer (ISSO)
At Credence, we support our clients’ mission-critical needs, powered by technology. We provide cutting-edge solutions, including AI/ML, enterprise modernization, and advanced intelligence capabilities, to the largest defense and health federal organizations. Through partnership and trust, we increase mission success for war-fighters and secure our nation for a better future.
We are privately held, are repeatedly recognized as a top place to work, and have been on the Inc. 5000 Fastest Growing Private Companies list for the last 12 years. We practice servant leadership and believe that by focusing on the success of our clients, team members, and partners, we all achieve greater success.
Credence is seeking an Information System Security Officer (ISSO) to provide IT professional support for Information System Security Officer (ISSO) and Security Control Assessment (SCA) activities, working with United States Marshals Service (USMS) system owners and other operations and maintenance (O&M) staff to ensure compliance with DOJ security requirements and standards for the USMS P30 system.
Responsibilities include, but are not limited to ...
The ISSO support will include developing and maintaining an IT System Security Compliance Schedule covering 12-month intervals that capture POA&M Action Items, required ITSS reports/updates, Change Control Board Meetings, Scheduled Vulnerability Scans, and Updates to System IT Security Documentation. Support includes the following:
- Advise the systems owner on the security posture of their systems.
- Perform assessment and authorization (A&A) activities on classified and unclassified networks in accordance with the DOJ/NIST Risk Management Framework (RMF).
- Develop and update artifacts for all control families (Security Categorization, SSP, Contingency Planning, Incident Response, Configuration Management, etc.).
- Perform compliance assessment reviews, tracking, and continuous monitoring of multiple networks, systems, and applications.
- Advise stakeholders throughout the entire lifecycle of the A&A process to include the development of Systems Security Plans (SSP).
- Perform System Categorization in accordance with FIPS-199 and CNSS 1253.
- Perform security control assessments in accordance with NIST 800-53A.
- Develop/edit/review Security Assessment Plans using CSAM.
- Perform risk analysis and prepare reports on networks, facilities and systems.
- Review, create and validate Security Assessment Reports.
- Develop and maintain the Plan of Action and Milestones (POA&M) statements, and support remediation activities through their lifecycle.
- Support Incident Response and Contingency activities.
- Perform security impact analysis on all configuration change requests.
- Review information in support of DOJ OCIO review for FISMA inventory
Requirements
- Secret clearance is required
- Bachelor’s Degree (or significant equivalent experience)
- Minimum 8 years of experience
- Must possess certification(s) in CISSP, CISA, or CISM
- Must be able to function resourcefully and independently and work with a diverse team of IA/cybersecurity practitioners
- Strong written and verbal communication skills required
- Experience working within DOJ Offices, Boards, and Divisions (OBDs), with an understanding of unique organizational security policies and security controls implementations within specific IT environments is desired.
Salary Range: $120,000.00 to $170,000.00 annually. Actual compensation will be determined based on the selected candidate's experience, education, skills, and overall qualifications.