- Company Name
- Credence
- Job Title
- Information Systems Security Manager (ISSM)
- Job Description
-
**Job Title**
Information Systems Security Manager (ISSM)
**Role Summary**
Lead a security operations team to safeguard federal IT environments. Oversee proactive threat hunting, continuous monitoring, vulnerability management, and certification/accreditation (C&A) activities. Ensure compliance with NIST, FISMA, and other governmental security standards while integrating security controls into system development and change management processes.
**Expectations**
- Deliver timely, accurate security assessments and reports to program management and government stakeholders.
- Maintain an up‑to‑date System Security Plan (SSP) and support the RMF Assessment & Authorization process.
- Lead the Plan of Actions and Milestones (POA&M) program, ensuring rapid remediation of identified vulnerabilities.
- Serve as the primary liaison for audits, assessments, and external government agencies.
**Key Responsibilities**
- Manage daily SecOps activities: threat hunting, alert analysis, continuous monitoring, and vulnerability assessment across on‑premises and cloud systems.
- Develop and maintain the SSP, RMF documentation, and all required security artifacts.
- Coordinate with Authorizing Officials, system owners, and stakeholders to gather information, assess risks, and ensure policy compliance.
- Execute change management oversight: evaluate security/ privacy impacts of system changes, provide mitigation recommendations, and coordinate implementation.
- Conduct security impact assessments for system changes, focusing on data sensitivity, access controls, and confidentiality, integrity, availability.
- Collaborate with cross‑functional teams to integrate security controls into system architecture and configuration.
- Facilitate audits and assessments, address findings, and ensure timely resolution.
- Manage POA&M lifecycle: document vulnerabilities, track remediation, prioritize actions, and report status.
- Respond to data calls and queries from internal and external partners (e.g., IRM/A&A, GITR).
- Interpret and communicate interdepartmental and federal security directives to teams, adjusting systems as needed.
- Stay informed on emerging security trends, regulatory changes, and industry best practices.
**Required Skills**
- Deep knowledge of NIST SP 800 series, FISMA, RMF, and C&A processes.
- Experience in SecOps: threat hunting, continuous monitoring, incident response, and vulnerability management.
- Proficiency in change management, security impact assessment, and risk mitigation.
- Strong analytical, problem‑solving, and project management abilities.
- Excellent communication and stakeholder‑management skills.
- Ability to work cross‑functionally with technical, program, and audit teams.
**Required Education & Certifications**
- Bachelor’s degree in Computer Science, Information Security, Cybersecurity, or related field (or equivalent experience).
- Valid certifications: CISSP, CISM, GECSP, or equivalent senior security credentials preferred.
- Project management certification (PMP, CAPM) is a plus.