Information Systems Security Officer (ISSO) / GRC Analyst

Quantum Space

$115K — $145K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Knowledge of NIST SP 800-171 and CMMC frameworks
  • Experience with SSPs, POA&Ms, and security policies
  • Familiarity with cybersecurity technologies like IAM and SIEM
  • Strong organizational and communication skills
  • 2-4 years in cybersecurity or GRC roles
  • Relevant certifications like CompTIA Security+, CySA+, CISA preferred
  • Ability to maintain a security clearance

Responsibilities

  • Support development and implementation of cybersecurity governance and policies
  • Manage compliance activities for CMMC and NIST RMF
  • Assist in maintaining crucial security documentation
  • Support internal/external assessments and audits
  • Coordinate with technical teams to validate security controls
  • Track and remediate vulnerabilities and compliance gaps
  • Facilitate collaboration between IT and external stakeholders

Benefits

  • Play a pivotal role in shaping cybersecurity compliance
  • Collaborative work environment with cross-functional teams
  • Enhance organization's security posture directly
  • Opportunities for growth in cybersecurity and GRC expertise
  • Comprehensive benefits package including medical and 401(k) matching
Full Job Description
A knowledgeable and detail-oriented Information Systems Security Officer (ISSO) or GRC Analyst to support governance, risk, and compliance activities across the organization. This role helps ensure our systems, policies, and processes align with cybersecurity frameworks such as NIST SP 800-53/800-171, NIST RMF, and CMMC. You will work closely with engineering, IT, and external partners to maintain compliance, reduce risk, and strengthen our cybersecurity posture.

Where You'll Make an Impact
  • Support the development, maintenance, and implementation of cybersecurity governance, policies, and procedures.
  • Manage compliance activities aligned with the CMMC and the NIST Risk Management Framework (RMF).
  • Assist in maintaining security documentation, including SSPs, POA&Ms, risk registers, and security processes.
  • Support internal and external assessments, audits, and readiness activities.
  • Coordinate with technical teams to ensure security controls are implemented and functioning as intended.
  • Track remediation of vulnerabilities, audit findings, and compliance gaps to closure.
  • Support incident response activities, including documentation, tracking, and lessons learned.
  • Facilitate collaboration across IT, cybersecurity, engineering, and external stakeholders.
  • Provide guidance on cybersecurity best practices, policy interpretation, and secure configuration requirements.
  • Assist with continuous monitoring activities and ongoing authorization considerations.

What It Takes
  • Knowledge of the NIST SP 800-171 security controls and CMMC framework, or the NIST RMF and NIST SP 800-53 security controls.
  • Experience supporting SSPs, POA&Ms, security policies, risk assessments, or other GRC deliverables.
  • Understanding of common cybersecurity technologies, including IAM/MFA, endpoint security, SIEM logging, and vulnerability management.
  • Ability to interpret security requirements and work with technical staff to validate control implementation.
  • Strong organizational skills and attention to detail for handling security documentation and compliance artifacts.
  • Excellent communication skills, including the ability to translate technical controls into clear documentation.
  • Experience supporting internal audits, external assessments, or compliance readiness activities.
  • Familiarity with cloud security concepts (Azure, AWS) and modern enterprise IT environments.
  • 2-4 years of cybersecurity, GRC, systems security, or compliance experience.
  • CompTIA Security+, CySA+, CISA, or similar certifications desired; RMF or CMMC experience highly valued.
  • Ability to hold and maintain a security clearance.

What You'll Get
  • Ownership - Play a pivotal role in shaping cybersecurity compliance and risk management efforts across the organization
  • Collaboration - Partner across engineering, IT, and security teams while expanding your technical and GRC expertise
  • Impact - Strengthen the organization's security posture through hands-on involvement in audits, control implementation, assessments, and continuous improvement
  • Growth - Join a fast-moving environment where you can deepen your cybersecurity and GRC expertise while directly contributing to operational resilience
  • Compensation - Competitive salary, equity, and comprehensive benefits including medical, dental, vision, generous leave, HSA, 401(k) matching, and equity sharing

Location: Rockville, MD

Base Salary: $115,000 to $145,000

The salary range for this role is an estimate based on a wide range of compensation factors. Actual salary offer may vary based on (but not limited to) work experience, education and/or training, critical skills, and/or business considerations. Highly competitive equity grants are included in the majority of full time offers; and are considered part of Quantum Space's total compensation package.

Additional Requirements

To comply with U.S. Government space technology export regulations, including ITAR, applicants must be a U.S. citizen, lawful permanent resident, protected individual per 8 U.S.C. 1324b(a)(3), or eligible to obtain the required authorizations from the U.S. Department of State.

Apply now. Join us in building the next generation of spacecraft.

Similar Jobs

More Jobs at Quantum Space

  • Accounting Manager
    $135K — $165K *
    Rockville, MD 20850 (Montgomery County)
    Legal & Accounting
    In-Person
  • Test Conductor
    $75K — $105K *
    Denver, CO 80219 (Denver County)
    Aerospace & Defense
    In-Person
  • Senior FP&A / Program Controller
    $120K — $150K *
    Rockville, MD 20850 (Montgomery County)
    Aerospace & Defense
    In-Person
  • Senior FP&A / Program Controller
    $120K — $150K *
    Hawthorne, CA 90250 (Los Angeles County)
    Aerospace & Defense
    In-Person
  • Reliability Engineer
    $120K — $180K *
    Hawthorne, CA 90250 (Los Angeles County)
    Aerospace & Defense
    In-Person

More Information Technology Jobs

Find similar Information Systems Security Officer (ISSO) / GRC Analyst jobs: