SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 115,000 - 145,000 / annual
Quantum Space is seeking an Information Systems Security Officer (ISSO) or GRC Analyst to support governance, risk, and compliance activities across the organization. This role ensures systems, policies, and processes align with cybersecurity frameworks including NIST SP 800-53/800-171, NIST RMF, and CMMC.
Key responsibilities include:
- Develop, maintain, and implement cybersecurity governance, policies, and procedures
- Manage compliance activities aligned with CMMC and NIST Risk Management Framework (RMF)
- Maintain security documentation including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), risk registers, and security processes
- Support internal and external assessments, audits, and readiness activities
- Coordinate with technical teams to ensure security controls are implemented and functioning correctly
- Track remediation of vulnerabilities, audit findings, and compliance gaps to closure
- Support incident response activities including documentation, tracking, and lessons learned
- Facilitate collaboration across IT, cybersecurity, engineering, and external stakeholders
- Provide guidance on cybersecurity best practices, policy interpretation, and secure configuration requirements
- Assist with continuous monitoring activities and ongoing authorization considerations
Required qualifications:
- 2–4 years of cybersecurity, GRC, systems security, or compliance experience
- Knowledge of NIST SP 800-171 security controls and CMMC framework, or NIST RMF and NIST SP 800-53 controls
- Experience supporting SSPs, POA&Ms, security policies, risk assessments, or other GRC deliverables
- Understanding of common cybersecurity technologies (IAM/MFA, endpoint security, SIEM logging, vulnerability management)
- Ability to interpret security requirements and work with technical staff to validate control implementation
- Strong organizational skills and attention to detail
- Excellent communication skills, including ability to translate technical controls into clear documentation
- Experience supporting internal audits, external assessments, or compliance readiness activities
- Familiarity with cloud security concepts (Azure, AWS) and modern enterprise IT environments
- Ability to hold and maintain a security clearance
- CompTIA Security+, CySA+, CISA, or similar certifications desired; RMF or CMMC experience highly valued
U.S. citizenship or lawful permanent resident status required due to ITAR compliance.