Source Job

US

  • Execute formal SCA/R duties and lead security assessment efforts.
  • Establish reusable security playbooks and assessment frameworks for rapid AI deployment.
  • Evaluate technical control effectiveness across AWS cloud, DevSecOps pipelines, and AI/LLM stacks.

AWS RMF NIST SP 800-53 DevSecOps

20 jobs similar to Security Control Assessor/Representative

Jobs ranked by similarity.

US

  • Maintain Risk Management Framework artifacts for DevSecOps pipeline inheritance of NIST SP 800-53 controls.
  • Complete and validate STIG/SRG checklists quarterly and provide monthly application STIG status reports.
  • Evaluate program risks, document mitigation strategies, and recommend courses of action to ensure continuous ATO compliance.

DecisionPoint is a company providing cloud services and DevSecOps solutions, supporting ARTRANS AWS environments. It is a regular full-time employer fostering a culture of security and compliance, with an active Secret clearance required for this role.

$111,427–$200,000/yr
US

  • Lead Risk Management Framework activities for a federal AI platform deployment in AWS GovCloud.
  • Own authorization artifacts and coordinate with ISSOs and Authorizing Officials for ATO.
  • Partner with platform engineers on cloud and container security, vulnerability management, and hardening.

LMI is a digital solutions provider dedicated to accelerating government impact with innovation and speed, bringing commercial-grade platforms and mission-ready AI to federal agencies. Headquartered in Tysons, Virginia, it serves the defense, space, healthcare, and energy sectors, with a culture more startup than traditional government contractor.

Canada

  • Lead a specialized team of security engineers focused on application, cloud, and AI system security.
  • Champion shift-left security practices including threat modeling, secure code review, and developer training.
  • Define cloud security standards and enforce security for AI systems including LLM-based agents.

Acquia empowers ambitious brands to create digital customer experiences using open source Drupal. Headquartered in Boston, MA, it is a Great Place to Work-Certified company and among the world's top software companies.

US

  • Design and implement security controls across AWS GovCloud environments.
  • Integrate security into CI/CD pipelines using Terraform and GitLab.
  • Ensure compliance with FedRAMP and DoD IL-4/5 standards.

Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. We are a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, ownership, and results.

$195,000–$200,000/yr
US

  • Lead cloud architecture assessments for IaaS, PaaS, SaaS, and CDaaS environments, and develop architecture diagrams and documentation.
  • Perform systems engineering activities throughout the system lifecycle and support Agile and traditional engineering efforts.
  • Collaborate with stakeholders to evaluate technical risks, devise migration strategies, and integrate DevSecOps into workflows.

A-TEK operates at the intersection of mission and innovation, providing digital transformation, enterprise IT, and scientific services to federal clients. The company emphasizes a creative, mission-driven work environment and actively cultivates talent to drive its success.

India

  • Partner with engineering, product, and DevOps teams to integrate security practices throughout the SDLC, focusing on cloud-native environments and automated pipelines.
  • Design, implement, and maintain security tooling and gates within CI/CD pipelines covering SAST, DAST, SCA, secrets detection, and container scanning.
  • Lead threat modeling, conduct application security assessments including code review and manual penetration testing, and triage bug bounty reports.

Hyland is the pioneer of the Content Innovation Cloud, delivering ubiquitous enterprise intelligence to organizations. With a team of nearly 4,000 employees, the company fosters an employee-centric culture focused on community impact and innovation.

$230,000–$250,000/yr
United States Unlimited PTO 12w maternity 12w paternity

  • Own our approach to AI and agentic security: guardrails for agentic access to cloud and data, and the security of AI/ML workloads.
  • Own our detection platform (Panther): detection strategy and coverage across cloud, container, and SaaS log sources.
  • Act as the senior security resource across cloud security and security reviews, mentoring teammates.

SmarterDx is a clinical AI platform that helps health systems capture revenue and improve quality metrics using clinically-validated EHR data. The company is a remote-first team with a small, collaborative engineering culture focused on making healthcare more accurate and effective.

US

  • Design and implement security best practices for application modernization and cloud migration initiatives.
  • Secure ASP.NET Core applications using modern authentication and authorization frameworks.
  • Configure and manage AWS security services including IAM, Secrets Manager, KMS, WAF, GuardDuty, and CloudTrail.

Fastwater Staffing is a staffing firm connecting talent with contract opportunities. They focus on matching skilled professionals with government and enterprise clients.

US

  • Lead the evolution of the software delivery lifecycle by embedding security into every stage of the CI/CD pipeline.
  • Integrate existing automation frameworks with AI-based solutions to improve coverage, reliability, and efficiency.
  • Collaborate with software developers and IT staff to oversee code releases and deployments.

Tier One Technologies provides technology solutions for government clients, focusing on security and compliance. The company sizes are not specified, but the culture emphasizes collaboration and security.

US

  • Provide RMF security artifacts for ARTRANS programs to inherit NIST 800-53 controls.
  • Maintain STIG/SRG checklists and monthly status reports.
  • Evaluate risk assessments and develop plans for full inheritance from DevSecOps pipeline.

DecisionPoint Corporation provides IT and cloud services, specializing in DevSecOps platforms and security compliance. They are a mid-sized company with a focus on supporting government programs through robust security practices.

US 18w maternity 16w paternity

  • Contribute to secure-by-design practices and advance the S-SDLC program.
  • Mentor engineers on secure coding and career growth.
  • Evaluate and recommend AI-assisted security tooling.

Spring Health is a global mental health company eliminating every barrier to mental health. They reach more than 170 million people worldwide and are an AI-native company focused on expanding the reach, quality, and humanity of care.

US

  • Act as a trusted consultant guiding clients through complex security and compliance challenges.
  • Develop security strategies aligned with frameworks like CMMC, NIST 800-171, and NIST 800-53.
  • Design and implement AWS and/or GCP security tools with deep expertise in cloud security.

Aprio is a Top 20 CPA and advisory firm that provides compliance and advisory services to fast-growing industries. With over 3,200 team members across 40 US and international offices, they foster a top-rated culture and collaborative environment.

$100,000–$150,000/yr
US

  • Design and implement security controls and governance frameworks for AI and machine learning systems.
  • Develop threat models and security architectures tailored to LLMs, AI applications, and training data pipelines.
  • Identify and mitigate AI-specific risks like prompt injection, model abuse, and data exfiltration.

Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. They operate as a technology-focused company with a remote team, emphasizing fair and efficient hiring processes.

$125,000–$152,000/yr
US

  • Bridge the gap between traditional infrastructure security and modern DevSecOps, defining secure-by-design frameworks and implementing high-impact DevSecOps pipelines across multi-cloud environments.
  • Lead critical security reviews for emerging technologies, including artificial intelligence, and act as a collaborative partner to internal teams fostering proactive security and cyber vigilance.
  • Manage security lifecycles within multi-cloud environments, own the end-to-end vulnerability management program, and leverage SIEM platforms for real-time threat intelligence.

NPR is a thriving, mission-driven multimedia organization that produces award-winning news, information, and music programming in partnership with hundreds of independent public radio stations across the nation. They are innovators and leaders in diverse fields, from journalism and digital media to IT and development, committed to building an inclusive workplace where collaboration is essential and diverse voices are heard.

Mexico

  • Drive security engineering initiatives and embed security across engineering teams.
  • Manage threats and respond to incidents with advanced automation and AI agents.
  • Architect secure solutions for AI/ML workloads and mentor team members.

EarnIn is a pioneer of earned wage access, building products that deliver real-time financial flexibility for those living paycheck to paycheck. They have an experienced leadership team and world-class funding partners, and are growing fast with a healthy core business.

India

  • Monitor enterprise AI usage end to end to detect unauthorized AI tools and rogue agent activity.
  • Investigate alerts related to autonomous agents and AI-powered workflows, including data exfiltration and credential misuse.
  • Partner with security, legal, and engineering teams to align findings with incident response processes and support ISO 42001 audits.

AlphaSense provides AI-driven market intelligence and search to help companies make informed decisions. With over 2,000 employees across the globe, the company fosters a collaborative and innovative culture.

$135,000–$160,000/yr
US

  • Build tools, automation, and infrastructure for scalable adversarial testing of AI systems.
  • Build and maintain realistic security test environments using cloud infrastructure and automation tools like Terraform.
  • Collaborate with red teamers and engineers to reproduce, investigate, and remediate vulnerabilities.

10a Labs is the safety and threat-intelligence layer trusted by frontier AI labs, AI unicorns, Fortune 10 companies, and leading global technology platforms. They operate in a fast-paced, high-growth startup environment with a collaborative and builder-oriented culture.

Europe

  • Serve as the premier technical specialist for complex enterprise architectures, acting as the ultimate authority on modern cloud infrastructure.
  • Guide prospects on embedding Sonatype solutions into modern CI/CD pipelines, container registries, and cloud infrastructure using Terraform and Helm.
  • Establish credibility with enterprise CTOs, Chief Architects, and DevSecOps leaders, positioning Sonatype as an indispensable layer of their cloud-native strategy.

Sonatype is the software supply chain security company, accelerating the future of agentic software development. With over 1 trillion downloads annually and over 70% of the Fortune 100 as customers, Sonatype has a scrappy, entrepreneurial culture.

US

  • Design and enforce least-privilege IAM architectures, network segmentation, and cloud security controls across multiple AWS accounts.
  • Build automated detection and response pipelines using AI tools for fast, actionable remediation.
  • Own vulnerability management, HIPAA compliance, and lead cross-functional security initiatives.

Chamber Cardio is rebuilding the cardiology system to focus on outcomes, partnering with independent cardiologists with technology, data, and operational tools. They are a mission-driven team combining clinical expertise, design, and a modern operating platform, with a culture of low ego, empathy, courage, ownership, and grit.

United States

  • Design and implement security controls for autonomous and multi-agent AI systems, including RAG pipelines and vector databases.
  • Perform AI threat modeling to assess risks like prompt injection, data poisoning, and adversarial inputs, and develop mitigation strategies.
  • Build guardrails and monitoring for responsible AI governance, ensuring explainability, auditability, and compliance with federal standards.

LTS builds an AI-native engineering platform to modernize mission-critical healthcare systems for federal agencies, serving millions of Veterans. Their culture emphasizes innovation, collaboration, and secure, transparent AI development.