Information Systems Security Officer (ISSO)
Overview
Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With 1,700+ team members, 1,500+ AI/data experts, and 100+ prime contracts, we deliver at scale and with purpose.
We’ve been recognized as a Top Workplace by the Washington Post for six straight years and named to the Inc. 5000 Fastest Growing Private Companies 13 of the past 14 years. Credence is a welcoming home for those looking to grow and contribute to positive change. We encourage all employees to expand beyond their boundaries, dive into important world-changing Federal challenges.
Position Summary
Credence has an immediate need for an Information Systems Security Officer (ISSO) to support federal cybersecurity compliance, risk management, and authorization activities within a complex government environment. The ISSO will serve as a key security and compliance resource, supporting Authority to Operate (ATO) efforts, continuous monitoring activities, security documentation, risk assessments, and implementation validation of NIST security controls.
The successful candidate will work closely with government stakeholders, technical teams, and compliance personnel to ensure systems remain secure, compliant, and operationally effective.
Responsibilities include, but are not limited to the duties listed below
- Serve as the primary point of contact (POC) to Lead Security Impact Analysis (SIA) and NOC packages
- Serve as the primary point of contact (POC) for compliance-related questions by client, RPC, and other stakeholders (except RSCs)
- Serve as the primary point of contact (POC) for ATO efforts for RPC systems:
- Privacy Impact Assessment (PIA);Perform risk analysis and risk assessments on proposed changes
- Information System Contingency Plan (ISCP) - will maintain and coordinate updates annually
- Contingency Plan Testing – conducted and documented annually
- SSP updates
- Cyber Table Top/Testing requirements – Support conducting and documenting annually to meet requirements
- POA&M management
- Serve as the primary point of contact (POC) for ISSO Checklist (monthly, quarterly, annual)
- Support compliance-based data call requests where necessary
- Participate in IRB, CCB, A&A, M21-31, and other policy meetings
- Ensure security controls are being met (NIST 800-53 control implementation validation)
- Keep ArchAngel updated with system changes (boundary diagrams, connection table, POCs...)
- Participate on IIS daily calls (once a week)
- Support Compliance meetings with client(s): currently bi-weekly Government Sync with ISO and Monthly AODR Check-in
- Monthly continuous monitoring deliverables (ISSO checklist, and recurring account validation)
- Customer responsibility matrix maintenance
- Evaluate security tools and verify that all have obtained required FedRAMP and TRB approvals prior to integration into the environment
Requirements
- Active Secret security clearance required.
- Bachelor's degree in Cybersecurity, Information Assurance, Information Systems, Computer Science, Computer Engineering, Mathematics, or a related field.
- Three (3) to five (5) years of relevant professional experience supporting information security, cybersecurity compliance, risk management, or related IT security functions.
- Experience supporting security authorization and compliance activities within federal, government, or highly regulated environments.
- Knowledge of Risk Management Framework (RMF) principles and NIST SP 800-53 security controls.
- Experience developing or maintaining security documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), risk assessments, and contingency plans.
- Experience supporting continuous monitoring and security compliance activities.
- Strong analytical, organizational, documentation, and communication skills.
Preferred Qualifications
- Security+, CAP, CISSP, CISM, or other relevant cybersecurity certifications.
- Experience supporting Assessment and Authorization (A&A) or Authority to Operate (ATO) activities.
- Familiarity with FedRAMP, cloud security, and federal cybersecurity compliance requirements.
- Experience supporting government customers and stakeholders.
Salary Range: $95,000 - $132,000 annually. Actual compensation will be determined based on factors such as experience, education, certifications, security clearance status, and internal equity.
Benefits
- Health Care Plan (Medical, Dental & Vision)
- Retirement Plan (401k, IRA)
- Life Insurance (Basic, Voluntary & AD&D)
- Paid Time Off (Vacation, Sick & Public Holidays)
- Family Leave (Maternity, Paternity)
- Short Term & Long Term Disability
- Training & Development
- Wellness Resources
As published by workable
First name, Last name, Email, Headline, Please list your full legal first and last name (e.g., John L. Smith II), Please provide your preferred first name, Phone, By providing a phone number and submitting this form you consent to receive SMS text messages from Credence LLC in accordance with our SMS Privacy Policy (https://credence-llc.com/careers/sms-privacy/) Message and data rates may apply. Message frequency may vary. Reply No, to STOP and opt out., Address, Photo, Education, Experience, List any work related certifications or licenses you currently possess, Please comment on how your prior education and experiences qualify you for the type of employment you are seeking., Summary, Resume, Please indicate which active clearances you have, If you have a security clearance not listed, please fill in., Cover letter, Type of work desired, What is your annual salary expectation? (Ranges are welcomed- non-answers may delay your consideration), What date are you available to join Credence as a new hire?, Are you legally authorized to work in the U.S. as a U.S. citizen or Fully Naturalized U.S. Citizen? , Do you currently or will you in the future, require an immigration sponsorship and/or a host for a work visa authorization (e.g., F1 or H-1B)? (if hired, verification will be required consistent with federal law.) , Are you at least 18 years old? (if no, you may be required to provide authorization to work) , How did you hear about us? Was it a job board or an employee? Do tell...., Have you ever worked for Credence before? If yes, what year and in what role?, Credence honors our Service Members and wonder if you are a Veteran or have Veteran status?, Credence honors our Service Members and their spouses, have you ever been a Military Spouse?, Do you have any relatives employed by this organization?, I have disclosed all information that is relevant and should be considered applicable to my candidacy for employment. I understand, where permissible under applicable state and local law, I may be subject to a pre-employment drug test after receiving a conditional offer of employment, and must receive a negative result for illegal drug use before being permitted to commence work with Company. I understand, where permissible under applicable state and local law, I may be subject to a pre-employment medical examination after receiving a conditional offer of employment, and must meet the qualifications for the position, with or without reasonable accommodation, before being permitted to commence work with Company. I understand, where permissible under applicable state and local law, I may be subject to a pre-employment background check after receiving a conditional offer of employment to investigate my criminal background and other matters related to my suitability for employment. Initial to agree., I hereby certify that the information given by me is true in all respects. I authorize Company and its representatives to contact my prior employers and all others (with the exception of my current employer, only if I have marked "May we contact your present employer" on this application as "No") for the purpose of verification of the information I have supplied and release same from any liability resulting from the information released. I authorize employers, schools and other persons named on this application to provide any information or transcripts requested. Initials to agree, I understand employment with Company is also contingent on my providing sufficient documentation necessary to establish my identity and eligibility to work in the United States. If employed, I understand that as a condition of employment that I may be required to agree to and sign a non-solicitation, non-disclosure, and/or other similar agreements. I also agree to notify the organization during the pre-employment process of any non-solicitation, non-disclosure, and/or other similar agreements that I may have already signed with current and former employers. I expressly understand and agree that, if employed, my employment, having no specified term, is based upon mutual consent and may be terminated at-will, with or without cause, by either party (Company or me) without prior notice to the other, unless otherwise prohibited by law. I understand that no representation, whether oral or written, by any representative or agent of Company, at any time, can constitute an implied or express contract of employment. I further understand no representative or agent of Company has the authority to enter into an agreement for employment for any specified period of time or to make any change in any policy, procedure, benefit or other terms or condition of employment other than in a document signed by an authorized representative. I understand that the technical processing and transmission of the application, including my personal information, may involve (a) transmissions over various networks, including the transfer of this information to the United States and/or other countries for storage, processing and use by Company, its affiliates, and their agents; and (b) changes to conform and adapt to technical requirements of connecting networks and devices. Accordingly, I agree to permit such parties to make such transmissions and changes, and hereby provide the necessary consent for the same. Initial to agree., Do you currently meet the worksite location requirements for being On-site or Hybrid as defined in the job description?, If “No”, are you willing to relocate to meet this requirement? Please note that candidates who are unable to work onsite or relocate will not meet the position requirements.
- Do you have an Active Secret security clearance? yes / no
- Are you legally authorized to work in the United States? yes / no
- What are your annual salary expectations in USD?
- Do you have Bachelor's degree in Cybersecurity, Information Assurance, Information Systems, Computer Science, Computer Engineering, Mathematics, or a related field? yes / no
- Do you have atleast three (3) to five (5) years of relevant professional experience supporting information security, cybersecurity compliance, risk management, or related IT security functions? yes / no
- Do you have knowledge of Risk Management Framework (RMF) principles and NIST SP 800-53 security controls? yes / no
- Do you have experience developing or maintaining security documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), risk assessments, and contingency plans? yes / no
- Do you have experience supporting continuous monitoring and security compliance activities? yes / no
- Do you have Security+, CAP, CISSP, CISM, or other relevant cybersecurity certifications? yes / no