Own FedRAMP and GovRAMP certifications and roadmaps, including package management and compliance timelines.
Manage 3PAO relationships and assessments, coordinating scoping, evidence, and results validation.
Lead continuous monitoring, POA&M processes, and drive compliance automation and efficiency.
Smartsheet empowers teams to manage work seamlessly and scale solutions smarter, now uniting human teams with AI agents. It is an equal opportunity employer committed to fostering an inclusive environment with the best employees.
Lead FedRAMP Moderate and CMMC readiness assessments, including system boundary validation and control gap analysis.
Design and implement cloud security architectures aligned to NIST 800-53 and NIST 800-171 requirements.
Develop and own System Security Plans (SSPs), control narratives, and compliance documentation.
Riveron helps organizations implement leading governance, risk and compliance practices with a hands-on approach. The company fosters an entrepreneurial culture with collaboration and diverse perspectives, offering flexible work and progressive benefits.
Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.
USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.
Partner with application development teams to integrate security requirements into design, development, and deployment workflows.
Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation.
Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards.
Oddball builds quality software for the federal space, focusing on improving the daily lives of millions of people. They are a small company that values learning, growth, and making a big impact.
Design and implement security controls across AWS GovCloud environments.
Integrate security into CI/CD pipelines using Terraform and GitLab.
Ensure compliance with FedRAMP and DoD IL-4/5 standards.
Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. We are a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, ownership, and results.
Consult onsite and remotely with customers to collect and analyze data related to policies, infrastructure, and compliance requirements.
Perform gap analyses of current environments and recommend remediation steps.
Assist with sales and marketing activities as a subject matter expert and prepare industry presentations.
CampusGuard provides information security and privacy consulting and compliance services for campus-based organizations. It is a full-service firm leveraging industry standards to deliver world-class security and compliance services.
Own Filevine's FedRAMP 20x strategy and execution, including evidence automation, continuous monitoring, and certification readiness.
Drive the security compliance and trust program across FedRAMP, SOC 2, ISO, HIPAA, and PCI-DSS, converting obligations into engineering work.
Lead cross-functional alignment and executive reporting to ensure compliance, privacy, and security priorities are shipped on time.
Filevine is a Legal AI company delivering Legal Operating Intelligence for the future of legal work. Fueled by a team of exceptional collaborators and innovators, Filevine’s rapid growth has earned AI awards and recognition from Deloitte and Inc. as one of the most innovative and fastest-growing technology companies in the country.
Manage and maintain version control of all documentation related to compliance for each standard and track implementation status of security controls.
Oversee preparation and execution of external compliance audits, including facilitating security assessments.
Support mapping of compliance requirements to security control implementation using agile development processes.
Hypori is a high-growth cybersecurity SaaS company providing a virtual workspace platform for secure mobile access. Backed by $55M in funding, the company is expanding into commercial and regulated markets with a focus on innovation and security.
Lead GRC activities including risk management framework, security assessments, and continuous monitoring for assigned systems.
Collaborate with engineering and security teams to integrate GRC principles into system lifecycles and DevSecOps practices.
Develop and maintain security documentation, support ATO processes, and provide risk briefings to leadership.
The partner company helps organizations strengthen cybersecurity programs through modern GRC practices and engineering expertise. It is a fully remote organization with a collaborative culture focused on technical excellence and professional growth.
Manage and implement complex controls frameworks for large systems consisting of Cloud infrastructure and SaaS services.
Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
Conduct risk assessments across business units and processes, identifying risk findings and recommending remediation strategies.
Virtru is a data protection platform that enables secure sharing without sacrificing security or privacy. Backed by top venture capital firms, the company helps Fortune 500 companies and government agencies achieve true data security with freedom to share.
Own IRAP and ISMAP program strategy and execution across Australia and Japan.
Coordinate with regional assessors and government agencies to maintain compliance.
Design and maintain compliance documentation and manage continuous monitoring.
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. They are now uniting human teams with AI agents to automate tasks and uncover insights.
Lead compliance initiatives across commercial and federal lines, driving FedRAMP, CMMC, ISO 27001, SOC 2, and HITRUST programs.
Coordinate internal and external audits, ensuring stakeholder readiness and timely remediation of findings.
Manage program roadmaps, risk registers, and cross-functional execution to translate regulatory requirements into actionable plans.
We provide an AI-infused scenario planning and analysis platform to optimize business decision-making. We serve over 2,400 global customers including Fortune 50 companies and foster a Winning Culture focused on innovation, diversity, and leadership.
Identify products or programs through the FedRAMP (Joint Authorization Board or Agency) authorization process.
Collaborate with the Program Manager Public Sector Compliance to define strategic roadmaps and support full product lifecycle.
Provide product architectural guidance for Vultr's public sector cloud product roadmap.
Vultr makes high-performance cloud infrastructure easy to use, affordable, and locally accessible for enterprises and AI innovators worldwide. We are the world's largest privately-held cloud infrastructure company, trusted by hundreds of thousands of active customers across 185 countries.
Lead ISSO activities to ensure confidentiality, integrity, availability, and compliance of enterprise applications and information systems.
Manage RMF processes including ATO packages, continuous monitoring, risk assessments, and accreditation documentation within eMASS.
Implement and maintain compliance with DISA STIGs, NIST 800-53 controls, and federal cybersecurity requirements.
Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. The company facilitates the hiring process by sharing top-fitting candidate shortlists with partner companies, focusing on efficiency and objectivity.
Act as a trusted consultant guiding clients through complex security and compliance challenges.
Develop security strategies aligned with frameworks like CMMC, NIST 800-171, and NIST 800-53.
Design and implement AWS and/or GCP security tools with deep expertise in cloud security.
Aprio is a Top 20 CPA and advisory firm that provides compliance and advisory services to fast-growing industries. With over 3,200 team members across 40 US and international offices, they foster a top-rated culture and collaborative environment.
Lead end-to-end service delivery operations for cybersecurity and cloud security professional services engagements.
Own the delivery lifecycle for FedRAMP advisory, implementation, continuous monitoring, and related security programs.
Develop operational strategies and governance models ensuring compliance with NIST 800-53, FedRAMP, and DoD frameworks.
This company specializes in cybersecurity and cloud service delivery for federal agencies, managing mission-critical environments with strict compliance requirements. They are a mid-sized organization focused on scalable operations and measurable outcomes.
Own and drive the compliance roadmap across multiple frameworks like ISO 27001, TISAX, and SOC 2.
Implement ISO 27001 end-to-end for customers and mentor junior compliance specialists.
Act as the senior compliance voice for customers, auditors, and product, partnering with CS and founders.
Secfix automates security compliance in Europe, helping companies achieve ISO 27001, GDPR, TISAX, and SOC 2 quickly and easily. We are a 100% remote team with hubs in Munich, Berlin, and London, backed by top VCs with a high-performing, ownership-driven culture.
Provide RMF security artifacts for ARTRANS programs to inherit NIST 800-53 controls.
Maintain STIG/SRG checklists and monthly status reports.
Evaluate risk assessments and develop plans for full inheritance from DevSecOps pipeline.
DecisionPoint Corporation provides IT and cloud services, specializing in DevSecOps platforms and security compliance. They are a mid-sized company with a focus on supporting government programs through robust security practices.
Lead RMF activities including control selection, POA&M management, and ATO support for the depot.
Design supply chain security controls such as SBOM generation, artifact signing, and vulnerability scanning.
Integrate security tooling into CI/CD pipelines and interface with government assessors and authorizing officials.
OpenTeams builds AI that empowers, focusing on energy-efficient, cost-effective models that give users full ownership of their data. As a small company, they value freedom, teamwork, accountability, and reinvest 3% of profits into the open-source community.
Serves as a cybersecurity SME for Assessment and Authorization (A&A) of information systems, applying NIST 800-53 security controls and the Risk Management Framework (RMF) process.
Possesses five years of relevant RMF, NIST, and A&A experience, including assessing security controls for large, complex organizations like DLA.
Briefs senior management on authorization progress and understands cybersecurity in emerging technology areas such as Cloud and Industrial Control Systems.
Horizon Industries Limited is a dynamic IT and Management Consulting firm based in the Washington, DC area, providing full-cycle IT consulting and management support to both private and public sectors. Founded in 1996, the company prides itself on a diverse, employee- and family-centric culture with a focus on professional growth.