Erik Schroeder, CISSP

Chief Information Officer at U.S. Department of Energy (DOE)

United States

About

Chief Information Officer with over 25 years of experience in information system engineering, administration, and cybersecurity risk management to include policy development, compliance, and Assessment and Authorization (A&A) in NIST, DIARMF, and other government agency specific environments.

Experience

  • U.S. Department of Energy (DOE) (7 yrs 1 mo)
    • Chief Information Officer
      Apr 2023 - Present · 3 yrs 4 mos

    • Chief Information Security Officer
      Mar 2020 - Apr 2023 · 3 yrs 2 mos

    • Director of Information Assurance
      Jul 2019 - Mar 2020 · 9 mos

      Department of Energy's Cyber Directorate, Director of Information Assurance. Responsible for all aspects of Assessment and Authorization (A&A) and Compliance of information systems.

  • Enterprise Information System Security Manager at ClearFocus Technologies
    Mar 2016 - Jul 2019 · 3 yrs 5 mos

    Contractor for the Department of Energy's Cyber Directorate, Enterprise Information Systems Security Manager (ISSM) • Manage all aspects of information security risk for a Wide Area Network (WAN) with the Department of Energy’s National Laboratories located throughout the continental United States. I work directly with the Chief Information Security Officer (CISO) managing risk in accordance with NIST Risk Management Framework 800-37.

  • Information Systems Security Manager (ISSM) / Director of Information Technology at BAI Inc
    Aug 2006 - Mar 2016 · 9 yrs 8 mos

    • As the company’s Information Systems Security Manager (ISSM), I’m responsible for the risk management of information systems to include writing and developing System Security Plans (SSPs), implementation of network system security policies and procedures for the Assessment & Authorization (A&A) of classified systems in accordance with the National Industrial Security Program Operating Manual (NISPOM) chapter 8, DIARMF, and the Director Central Intelligence Directive (DCID) 6/3 - ICD 503. • Designed, configured, and certified classified systems located in Sensitive Compartmented Information Facilities (SCIF) in accordance with DoD Security Technical Implementation Guides (STIG) and NIST SP 800-53. Implement enhanced security controls for servers and CISCO IOS equipment including routers, firewalls, IPS, and switches. Configured and managed network Security Information and Event Management (SIEM) utilizing SPLUNK and increased server efficiency utilizing VMware. • Conducted vulnerability scans on systems using Tenable’s Security Center and Nessus vulnerability scanners. Implemented and maintained reporting requirements via DISA’s Vulnerability Management System (VMS) and updating our Plan of Action & Milestones (POA&M) to keep track and mitigate any unresolved risks to the systems. • Managed and oversees projects, initiatives, and daily operations of information systems for the company headquarters and multiple client sites. • Managed the migration, training, and implementation of the corporate email system to Office 365. • Maintained IT budget and planning to include lifecycle management of information systems and other communications systems such as financial, VOIP, and VTC systems. • Completed extensive client stakeholder interviews and provided Information Assurance subject matter expertise while part of a team developing an Enterprise Architecture (EA) roadmap for large government agency.

  • Information Systems Security Officer (ISSO) / Communications Officer at Strategic Systems Program
    Jan 2003 - Jun 2006 · 3 yrs 6 mos

    • Responsible for implementing and securing the Defense Messaging Systems (DMS) for all incoming and outgoing naval message traffic for the Director of Strategic Systems Programs and nine subordinate commands throughout the United States and the United Kingdom. • Managed nine commands information assurance as the ISSO. Directed the implementation of security and managed C&A processes in accordance with DoD Information Technology Security Certification Accreditation Process (DITSCAP) on multiple DMS systems. • Communication Security (COMSEC) Material System (CMS) manager for echelon II command responsible for inspecting and evaluating subordinate commands CMS accounts and general communication policies and procedures. • Top Secret Control Officer responsible for safeguarding and tracking all of the commands Top Secret material. Conducted training and implemented procedures as the commands Operational Security (OPSEC) officer. Annually audited and reviewed SSP’s OPSEC plans and procedures as well as eight other subordinate commands as part of the commands Inspector General (IG) team.

  • Information Systems Security Officer (ISSO) / Leading Chief Petty Officer Electronics Technician at USS West Virginia SSBN 736
    Jan 1998 - Dec 2002 · 5 yrs

    Information Systems Security Officer (ISSO), Communications Leading Chief Petty Officer, Sailor of the Year (2001), COMSEC Manager, 8 Strategic Deterrent Patrols • Managed Information Assurance (IA) and DITSCAP C&A lifecycle process for the ship’s classified information system as the commands ISSO. • Managed a division of 12 electronic technicians as the Leading Chief Petty Officer (LCPO) for the communications division during an extensive refurbishment period and patrol cycle. • Electronic Key Material System (EKMS) manager for COMSEC Material System (CMS) maintaining and controlling keying material for cryptographic equipment for the commands communications suite. • Ship’s senior duty section leader in charge of scheduling and managing over 40 duty section personnel.