1

Isso Issm Jobs in Tennessee (NOW HIRING)

Isso Issm information

What are the main challenges faced by an Information Systems Security Officer (ISSO) or Information Systems Security Manager (ISSM) when working with cross-functional teams?

ISSO/ISSMs often collaborate with IT, compliance, and business units to ensure security policies align with organizational goals. A common challenge is bridging the communication gap between technical and non-technical stakeholders to ensure security requirements are understood and implemented effectively. Additionally, balancing strict security controls with operational needs requires negotiation and adaptability. Building strong relationships and maintaining clear documentation are key to overcoming these challenges and ensuring a secure and compliant environment.

What are the key skills and qualifications needed to thrive as an Information System Security Officer (ISSO) or Information Systems Security Manager (ISSM), and why are they important?

To thrive as an ISSO/ISSM, you need a solid understanding of cybersecurity principles, risk management frameworks (such as NIST RMF), and compliance requirements, usually supported by a degree in information security or a related field. Familiarity with security tools like SIEM systems, vulnerability scanners, and certifications such as CISSP or Security+ are typically required. Strong analytical thinking, attention to detail, and the ability to communicate complex security concepts to diverse audiences are essential soft skills. These skills ensure the effective protection of organizational assets, compliance with regulations, and the ability to respond proactively to evolving security threats.

What does isso issm mean?

In the context of a job, 'ISSO' stands for Information System Security Officer, a role responsible for managing and implementing security policies for information systems. 'ISSM' refers to Information System Security Manager, who oversees security programs and ensures compliance with security standards. Both positions typically require knowledge of cybersecurity frameworks and security tools.

Which is higher, isso or issm?

In the context of job titles, 'ISSO' (Information System Security Officer) is typically a higher or more senior role than 'ISSM' (Information System Security Manager), though the specific hierarchy can vary by organization. Both roles involve cybersecurity responsibilities, with ISSO often focusing on security compliance and ISSM on managing security programs and teams. Certifications like CISSP are common for both positions, and experience levels can influence seniority.

What is the difference between Isso Issm vs Project Manager?

AspectIsso IssmProject Manager
CertificationsTypically requires ISSM certification, security clearancesOften requires PMP or CAPM certifications
Work EnvironmentPrimarily in cybersecurity, information systems securityIn various industries managing projects across departments
Industry UsageCommon in defense, government, IT security sectorsWidely used across construction, IT, healthcare, and more

While both roles involve managing technical aspects, Isso Issm focuses on information security management within cybersecurity environments, often requiring specific security certifications. Project Managers oversee a broad range of projects across industries, emphasizing planning, execution, and delivery. Understanding these differences helps clarify career paths and employer expectations in respective fields.

How much money does an isso make?

An Isso Issm typically earns a salary that varies based on experience, location, and industry, but the average salary ranges from $50,000 to $80,000 annually. They often require technical skills and certifications related to infrastructure management and systems administration.

Can you make $500,000 a year in cyber security?

In cybersecurity, reaching a $500,000 annual salary is possible for senior roles such as security executives or specialists with extensive experience, advanced certifications, and leadership responsibilities. Most cybersecurity professionals earn lower salaries, but high-level positions in large organizations or consulting firms can offer compensation at this level.

What are ISSOs and ISSMs?

Information System Security Officers (ISSOs) and Information System Security Managers (ISSMs) are cybersecurity professionals responsible for the protection and oversight of information systems within an organization, particularly in compliance-driven environments like government or defense. ISSOs focus on the day-to-day security operations, monitoring, and implementation of security controls, while ISSMs are typically responsible for the overall security program management and ensuring compliance with relevant regulations and policies. Both roles are crucial for maintaining the confidentiality, integrity, and availability of sensitive data.
What job categories do people searching Isso Issm jobs in Tennessee look for? The top searched job categories for Isso Issm jobs in Tennessee are:
What cities in Tennessee are hiring for Isso Issm jobs? Cities in Tennessee with the most Isso Issm job openings:
Information Systems Security Officer ISSO

Information Systems Security Officer ISSO

Cadre5

Knoxville, TN • On-site

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 28 days ago


Job description

Information Systems Security Officer (ISSO)
Founded in 1999 in the beautiful Smoky Mountains of East Tennessee, Cadre5 provides innovative technical solutions to our customers locally and nationally. Our Cadre5 Lab Partners division has partnered with the Information Technology Services Directorate (ITSD) at Oak Ridge National Laboratory (ORNL) to recruit a Information System Security Officer. The successful candidate should have a basic understanding of all aspects of cybersecurity. The candidate will collaborate with other teams across the lab, to include Information Technology, Physical Security, Classification Office, Cybersecurity, Lab Enterprise Risk, Lab Internal Audit in support of the American Science Cloud (AmSC) initiative.
AmSC is a first-of-its-kind, federally funded cloud infrastructure and API platform designed to accelerate AI model development, data sharing, and large-scale computational science across the U.S. Department of Energy (DOE). ORNL is a premier research institution delivering breakthroughs in energy, national security, and advanced computing.
Located near Knoxville, TN, the lab provides world-class resources to solve some of the nation’s most complex scientific challenges. This is a rare opportunity to be part of a groundbreaking project that will help shape the future of U.S. scientific computing.
Why Cadre5?
  • Working with highly talented team members
  • Paid over-time
  • 3 weeks’ vacation
  • Excellent medical insurance, up to 100% paid by employer
Duties and Responsibilities:
The ISSO is a primary stakeholder and facilitator of the continuous monitoring efforts that promote RMF compliance throughout the organization. The ISSO provides direction to IT and infrastructure support personnel on the application of security patches and secure configurations. Routine collaboration and consultation with the ISSM regarding the design, development, integration, and analysis of unclassified information systems. Under general supervision, the candidate is responsible for performing a full range of Information Assurance functions in support of the security needs of the ISSM.
Primary Responsibilities:
  • Provide assistance to the ISSM and CISO in the certification and accreditation (C amp;A) of systems/networks and implementation of cybersecurity requirements and procedures across the client site.
  • Ensure systems are operated, maintained, and disposed of in accordance with security policies and procedures and as outlined in applicable System Security Plans (SSPs).
  • Perform documented procedures for authorizing users to access information systems.
  • Develop and maintain SSPs for system C amp;A.
  • Manage Plans of Action and Milestones to closure for information systems under accreditation.
  • Provide guidance on policies and controls to support appropriate levels of risk, facilitate risk tolerance discussions and decisions, and recommend controls based on industry standards and practices. Escalate questions/concerns/issues to more senior-level staff as required.
  • Participate in internal/external compliance audits, reviews, self-assessments, assessments, and data calls.
  • Identify, promote, and make recommendations for process improvements.
  • Assist with annual self-inspections, system certification testing, periodic security testing, and functional testing on systems/networks.
  • Ensure compliance of all network equipment with applicable DOE and ORNL requirements
  • Other duties as assigned for support within the program.
Basic Qualifications:
  • Bachelor’s degree with 3-5 years of relevant experience (ex. cybersecurity assessments, risk management, cybersecurity policy, and compliance, etc.). An equivalent combination of education and experience may be considered.
  • Strong analytical and organizational skills as well as problem solving capabilities to understand Cybersecurity risk and exposure (legal, regulatory violations, etc.) to ORNL.
  • Demonstrated experience implementing compliance frameworks (NIST, etc)
  • Excellent interpersonal, verbal, written, and presentation communication skills.
  • Thorough understanding of industry standards and regulations including NIST 800-53, NIST Risk Management Framework, and NIST Cybersecurity Framework (CSF).
  • Working knowledge of privacy regulations and impacts.
  • Ability to work independently, meet deadlines, and uphold high ethical standards.
  • This position requires and an active Department of Energy "Q" or “L” clearance. A “Top Secret (TS)” or “Secret” Department of Defense clearance will also suffice. This requires US Citizenship.
Preferred Qualifications:
  • Active DOE Q or TS security clearance or equivalent.
  • Master’s degree in information assurance or related field with 4-6 years of relevant experience working in an information security, information technology or information risk management related field.
  • Cybersecurity certifications (CISSP, CISA, CISM, CRISC, CCSP, SSCP) and Incident Response Certification
  • Privacy management, cybersecurity, evaluating security controls, identifying control gaps, and mitigating measures along with a strong understanding of business practices and technology concepts.
  • Highly motivated individual with an enthusiasm for governance, risk and compliance who can communicate benefits and drive success.
  • Demonstrated background in governance, risk, and compliance.
  • Experience in obtaining Authority to Operate (ATO) for DOE government systems.
Benefits
Cadre5 offers excellent pay and benefits, to include full medical, dental, and vision coverage coupled with 401K match, 15 days PTO, and 10 holidays.
Cadre5 is an equal opportunity employer. All qualified applicants, including individuals with disabilities and protected veterans, are encouraged to apply. Cadre5 is an E-Verify Employer.

Cadre5 logo

About Cadre5

Sourced by ZipRecruiter

Industry

Software development

Company size

11 - 50 Employees

Headquarters location

Knoxville, TN, US

Year founded

1999