Security Documentation, Audit, and Quality Analyst
Washington, DC
Contracted
Experienced


We are a growing information technology company that offers its employees a culture of success, the chance to work on revolutionary federal IT infrastructure, and the opportunity to grow alongside cutting-edge technology that is reshaping the industry. We are seeking forward-thinking candidates that have strong experience in operational support and can help take to the next level in a proactive stance.
Chameleon Integrated Services has expertise in operations management, quality systems, data operations and cybersecurity. We secure some of the most sensitive data for the Department of Defense and for other U.S. federal government agencies. We are known for the great care we take with clients and employees, and we believe in promoting from within.
We offer a Full Benefits package including:
Security Documentation, Audit, and Quality Analyst
Control the quality, traceability, currency, and acceptance readiness of cybersecurity deliverables. Maintain the evidence repository and deliverable register; conduct independent reviews of SSPs, POA&Ms, assessment packages, dashboards, situation reports, RCAs, audit responses, and recurring program reports; identify inconsistent or unsupported statements; and track corrections through closure. The position will also support FISMA, IG, GAO, OMB, CISA, independent assessor, penetration-test, and FedRAMP-related evidence requests. DFC requires audit-ready SSPs, SARs, POA&M records, control evidence, assessment artifacts, and Splunk-derived logging records that can be produced without a special evidence-collection surge.
The position will also support FISMA, IG, GAO, OMB, CISA, independent assessor, penetration-test, and FedRAMP-related evidence requests. DFC requires audit-ready SSPs, SARs, POA&M records, control evidence, assessment artifacts, and Splunk-derived logging records that can be produced without a special evidence-collection surge.
Minimum Requirements:

We are a growing information technology company that offers its employees a culture of success, the chance to work on revolutionary federal IT infrastructure, and the opportunity to grow alongside cutting-edge technology that is reshaping the industry. We are seeking forward-thinking candidates that have strong experience in operational support and can help take to the next level in a proactive stance.
Chameleon Integrated Services has expertise in operations management, quality systems, data operations and cybersecurity. We secure some of the most sensitive data for the Department of Defense and for other U.S. federal government agencies. We are known for the great care we take with clients and employees, and we believe in promoting from within.
We offer a Full Benefits package including:
- Competitive Employee Health Insurance options including dental
- 100% company paid vision plan
- 401K plan with generous company match and no vesting period
- 100% company paid life insurance
- 100% company paid long and short-term disability insurance
- Training allowance
- PTO and more
Security Documentation, Audit, and Quality Analyst
- Must be a United States citizen.
- Must be eligible for a Tier 4 High-Risk Public Trust investigation.
- Strong preference for a current or recently favorably adjudicated Tier 4 or Tier 5 investigation.
Control the quality, traceability, currency, and acceptance readiness of cybersecurity deliverables. Maintain the evidence repository and deliverable register; conduct independent reviews of SSPs, POA&Ms, assessment packages, dashboards, situation reports, RCAs, audit responses, and recurring program reports; identify inconsistent or unsupported statements; and track corrections through closure. The position will also support FISMA, IG, GAO, OMB, CISA, independent assessor, penetration-test, and FedRAMP-related evidence requests. DFC requires audit-ready SSPs, SARs, POA&M records, control evidence, assessment artifacts, and Splunk-derived logging records that can be produced without a special evidence-collection surge.
The position will also support FISMA, IG, GAO, OMB, CISA, independent assessor, penetration-test, and FedRAMP-related evidence requests. DFC requires audit-ready SSPs, SARs, POA&M records, control evidence, assessment artifacts, and Splunk-derived logging records that can be produced without a special evidence-collection surge.
Minimum Requirements:
- At least 5 years of cybersecurity compliance, RMF documentation, audit support, quality control, or federal technical writing
- At least 3 years supporting federal cybersecurity documentation
- Demonstrated ability to independently review:
- SSPs
- SARs
- POA&Ms
- Control evidence
- Risk assessments
- Continuous-monitoring reports
- Audit responses
- Incident reports and RCAs
- Experience maintaining version control, comment resolution, document traceability, and evidence indexes
- Experience supporting at least one federal audit, FISMA review, IG review, independent assessment, or comparable inspection
- Strong Microsoft Word, Excel, PowerPoint, and SharePoint skills
- Familiarity with a GRC platform and ServiceNow
- Security+ or CGRC preferred
- CSAM reporting or data-quality experience
- Experience building deliverable acceptance registers or quality dashboards
- FISMA, IG, GAO, OMB CyberStat, CISA data-call, or FedRAMP experience
- Ability to review technical evidence from Splunk, Tenable, Qualys, Microsoft Defender, Azure, and identity platforms
- Experience measuring first-time acceptance, defect rates, finding closure, and SLA/KPI performance
- Federal cybersecurity technical-writing background
- Current Tier 4 or Tier 5 suitability
- Types and volume of deliverables reviewed
- Audits and assessments supported
- Evidence repositories or document-control systems maintained
- Quality-control responsibilities
- Defects, rework, acceptance, timeliness, or audit-response metrics
- GRC, SharePoint, ServiceNow, and reporting tools used
- Examples of correcting inconsistent or unsupported cybersecurity documentation
“We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability or protected veteran status”
Texting Privacy Policy
- Message type: Informational; you will receive text messages regarding your application and potentially regarding interview scheduling.
- No mobile information will be shared with third parties/affiliates for marketing/promotional purposes.
- Message frequency will vary depending on the application process.Msg & data rates may apply.
- OPT out at any time by texting "Stop".
Apply for this position
Required*