JobRaahGet matched free

Jobs

Information Systems Security Officer (ISSO) / GRC Analyst

Quantum Space · Rockville, MD · United States · On-site

Pay: USD 115,000 – 145,000 a year

Posted Sep 8, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

Quantum Space is redefining mobility and maneuverability in space. Our high-mobility spacecraft platforms support national security, civil, and commercial missions with unmatched flexibility and propulsion capability. We build fast and iterate quickly. Who We’re Looking For A knowledgeable and detail‑oriented Information Systems Security Officer (ISSO) or GRC Analyst to support governance, risk, and compliance activities across the organization. This role helps ensure our systems, policies, and processes align with cybersecurity frameworks such as NIST SP 800‑53/800-171, NIST RMF, and CMMC. You will work closely with engineering, IT, and external partners to maintain compliance, reduce risk, and strengthen our cybersecurity posture. Where You’ll Make an Impact Support the development, maintenance, and implementation of cybersecurity governance, policies, and procedures. Manage compliance activities aligned with the CMMC and the NIST Risk Management Framework (RMF). Assist in maintaining security documentation, including SSPs, POA&Ms, risk registers, and security processes. Support internal and external assessments, audits, and readiness activities. Coordinate with technical teams to ensure security controls are implemented and functioning as intended. Track remediation of vulnerabilities, audit findings, and compliance gaps to closure. Support incident response activities, including documentation, tracking, and lessons learned. Facilitate collaboration across IT, cybersecurity, engineering, and external stakeholders. Provide guidance on cybersecurity best practices, policy interpretation, and secure configuration requirements. Assist with continuous monitoring activities and ongoing authorization considerations. What It Takes Knowledge of the NIST SP 800‑171 security controls and CMMC framework, or the NIST RMF and NIST SP 800‑53 security controls. Experience supporting SSPs, POA&Ms, security policies, risk assessments, or other GRC deliverables. Understanding of common cybersecurity technologies, including IAM/MFA, endpoint security, SIEM logging, and vulnerability management. Ability to interpret security requirements and work with technical staff to validate control implementation. Strong organizational skills and attention to detail for handling security documentation and compliance artifacts. Excellent communication skills, including the ability to translate technical controls into clear documentation. Experience supporting internal audits, external assessments, or compliance readiness activities. Familiarity with cloud security concepts (Azure, AWS) and modern enterprise IT environments. 2–4 years of cybersecurity, GRC, systems security, or compliance experience. CompTIA Security+, CySA+, CISA, or similar certifications desired; RMF or CMMC experience highly valued. Ability to hold and maintain a security clearance. What You’ll Get Ownership – Play a pivotal role in shaping…