Security Documentation, Audit, and Quality Analyst

Chameleon Integrated Services

$90K — $120K *
Education, Government & Non-Profit
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • U.S. citizenship required
  • Eligibility for Tier 4 High-Risk Public Trust investigation
  • 5+ years in cybersecurity compliance and federal technical writing
  • 3+ years supporting federal cybersecurity documentation
  • Experience with independent reviews of compliance documents
  • Strong proficiency in MS Word, Excel, PowerPoint, and SharePoint
  • Familiarity with GRC platforms and ServiceNow; Security+ or CGRC preferred

Responsibilities

  • Ensure quality and traceability of cybersecurity deliverables
  • Maintain evidence repository and deliverable register
  • Conduct independent reviews of SSPs, POA&Ms, and assessment packages
  • Identify inconsistencies in documentation and track corrections
  • Support FISMA, IG, GAO, OMB, and FedRAMP-related evidence requests
  • Produce audit-ready SSPs and control evidence without evidence collection surges
  • Collaborate with multiple teams for compliance and reporting tasks

Benefits

  • Comprehensive health insurance including dental
  • 100% company paid vision insurance
  • 403B plan with generous company match and no vesting
  • 100% company paid life insurance
  • 100% company paid short and long-term disability insurance
  • Training allowance for professional development
  • Paid time off and additional perks
Full Job Description
We offer a Full Benefits package including:
  • Competitive Employee Health Insurance options including dental
  • 100% company paid vision plan
  • 401K plan with generous company match and no vesting period
  • 100% company paid life insurance
  • 100% company paid long and short-term disability insurance
  • Training allowance
  • PTO and more

Security Documentation, Audit, and Quality Analyst
  • Must be a United States citizen.
  • Must be eligible for a Tier 4 High-Risk Public Trust investigation.
  • Strong preference for a current or recently favorably adjudicated Tier 4 or Tier 5 investigation.
Role:
Control the quality, traceability, currency, and acceptance readiness of cybersecurity deliverables. Maintain the evidence repository and deliverable register; conduct independent reviews of SSPs, POA&Ms, assessment packages, dashboards, situation reports, RCAs, audit responses, and recurring program reports; identify inconsistent or unsupported statements; and track corrections through closure. The position will also support FISMA, IG, GAO, OMB, CISA, independent assessor, penetration-test, and FedRAMP-related evidence requests. DFC requires audit-ready SSPs, SARs, POA&M records, control evidence, assessment artifacts, and Splunk-derived logging records that can be produced without a special evidence-collection surge.

The position will also support FISMA, IG, GAO, OMB, CISA, independent assessor, penetration-test, and FedRAMP-related evidence requests. DFC requires audit-ready SSPs, SARs, POA&M records, control evidence, assessment artifacts, and Splunk-derived logging records that can be produced without a special evidence-collection surge.

Minimum Requirements:
  • At least 5 years of cybersecurity compliance, RMF documentation, audit support, quality control, or federal technical writing
  • At least 3 years supporting federal cybersecurity documentation
  • Demonstrated ability to independently review:
    • SSPs
    • SARs
    • POA&Ms
    • Control evidence
    • Risk assessments
    • Continuous-monitoring reports
    • Audit responses
    • Incident reports and RCAs
  • Experience maintaining version control, comment resolution, document traceability, and evidence indexes
  • Experience supporting at least one federal audit, FISMA review, IG review, independent assessment, or comparable inspection
  • Strong Microsoft Word, Excel, PowerPoint, and SharePoint skills
  • Familiarity with a GRC platform and ServiceNow
  • Security+ or CGRC preferred
Competitive Differentiators:
  • CSAM reporting or data-quality experience
  • Experience building deliverable acceptance registers or quality dashboards
  • FISMA, IG, GAO, OMB CyberStat, CISA data-call, or FedRAMP experience
  • Ability to review technical evidence from Splunk, Tenable, Qualys, Microsoft Defender, Azure, and identity platforms
  • Experience measuring first-time acceptance, defect rates, finding closure, and SLA/KPI performance
  • Federal cybersecurity technical-writing background
  • Current Tier 4 or Tier 5 suitability
The resume must clearly identify:
  • Types and volume of deliverables reviewed
  • Audits and assessments supported
  • Evidence repositories or document-control systems maintained
  • Quality-control responsibilities
  • Defects, rework, acceptance, timeliness, or audit-response metrics
  • GRC, SharePoint, ServiceNow, and reporting tools used
  • Examples of correcting inconsistent or unsupported cybersecurity documentation


Similar Jobs

More Education, Government & Non-Profit Jobs

Find similar Security Documentation, Audit, and Quality Analyst jobs: