We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Security ISSO

Quadrant, Inc.
United States, Virginia, Fairfax
Dec 02, 2025
Security ISSO

Washington, DC (remote)

Pay From: $130,000 per year


MUST:

Experienced Security ISSO with PaaS experience

Eligible for T3 Public Trust

8+ years of progressive IA experience

2+ years of experience working in an ISSO capacity supporting the Federal Government

Strong experience reviewing and analyzing security documentation for PaaS products

Experience with ISO, NIST and US Government standards and cybersecurity frameworks (e.g. FISMA, FIPS, etc..)

Strong understanding of FedRamp policies/procedures, proper Authorization practice in a cloud environment with CSPs

IT security management, engineering, and analysis experience

ServiceNow GRC experience is a must

Experience working with MuleSoft is a plus

Excellent communication skills both written and verbal

Strong documentation skills

High attention to detail and strong problem-solving skills

Active security certification: CISM, CRISC, CNDA strongly desired

Bachelor's Degree in a related field ideally Cyber Security, IT Management or similar

DUTIES:

The ideal candidate will act as the primary cybersecurity analyst for an assigned portfolio of PaaS products at various stages of preparation, authorization, and sustainment within the client's ecosystem

Provide expertise regarding FedRAMP and VA cloud policies/processes/requirements

Conduct meetings with Cloud Service Providers (CSPs) preparing for authorization of their PaaS products for the client

Perform Risk Management Framework (RMF) implementation within the VA GRC tool to obtain and maintain authorization for PaaS products

Provide technical assistance in the designing and implementation of solutions for protecting the confidentiality, integrity and availability of sensitive information

Provide technical support for overall IT systems including: Security improvements, vulnerability assessments, risk assessments, network security and more

Review and analyze security documentation for PaaS products (e.g. SSPs, CIS/CRM, etc.) to ensure alignment with FedRAMP and VA policy and system readiness for assessment/authorization

Use SOPs and checklists to verify all documentation requirements are met

Perform in-depth review of CRM to confirm customer responsibilities are well-defined by CSP and that the client will be capable of performing those functions

When required, obtain access to CSP FedRAMP documentation repositories to retrieve documentation needed for Client's authorization efforts

Maintain PaaS authorization packages within VA GRC tool after ATO and participate in Continuous Monitoring activities

Monitor FedRAMP repository for updated CSP documentation (e.g. SSP, SAR, POA&Ms, scan results, etc.) and upload to eMASS promptly

As applicable based on CSP changes, update control information, inheritance status, etc and archive outdated artifacts within eMASS when appropriate

Create, update, and resolve POA&Ms

Participate in the management of accreditation of the Federal Client's systems evaluating and certifying the implementation FISMA, the NIST security guidelines, and the Departments plans, policies and guidelines


Quadrant is an affirmative action/equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, status as a protected veteran, or status as an individual with a disability. "Healthcare benefits are offered to all eligible employees according to compliance mandated by the Affordable Care Act".
Applied = 0

(web-df9ddb7dc-rwcm4)