Lead technical roadmap for FedRAMP Continuous Monitoring, transitioning manual reporting to automated telemetry and validation.
Design compliance-as-code frameworks and automated evidence generation to reduce manual effort during assessments and audits.
Partner with cross-functional teams to define compliance verification requirements and mentor on FedRAMP practices.
Our partner is a technology company specializing in security and compliance for public sector cloud environments. They foster a collaborative, fast-moving culture with significant autonomy and cross-functional exposure.
Lead the technical roadmap for FedRAMP Continuous Monitoring, moving from manual reporting to automated, real-time telemetry.
Architect compliance outcomes by translating NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering solutions.
Engineer evidence generation frameworks to reduce manual effort for 3PAO assessments and automate compliance validation.
Wiz provides an AI-powered platform to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. It is one of the fastest-growing startups, trusted by over 65% of the Fortune 100, with a global team and a culture that values world-class talent.
Review system documentation and technical evidence against NIST, FISMA, RMF, FedRAMP, and Zero Trust requirements.
Perform control-gap analyses, maturity assessments, and compliance reviews; identify risks and recommend corrective actions.
Support authorization activities by preparing security plans, control implementation statements, and remediation documentation.
9th Way Insignia is a service-disabled, veteran-owned small business providing transformative technology solutions including cybersecurity, cloud modernization, software development, and data analytics to government customers. As a small business, it empowers its people to fearlessly drive change and offers a comprehensive benefits package.
Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.
Lead compliance assessments and build-out of IL4/IL5 authorizations for DoD Cloud Computing Security Requirements Guide.
Maintain and evolve compliance posture for FedRAMP High, NIST SP 800-53, and other federal frameworks.
Serve as GRC liaison to engineering teams, translating complex federal compliance requirements into technical specifications for AWS environments.
Horizon3 is a fast-growing, remote cybersecurity company that provides autonomous pentesting through its NodeZero platform. The company is a fusion of former Special Operations cyber operators and engineers, fostering a culture of respect, collaboration, ownership, and results.
Support day-to-day information security operations and maintain strong operational security posture across the platform.
Develop and maintain the System Security Plan and other cybersecurity documentation for security authorization and compliance.
Support FedRAMP High and DoD IL5 compliance activities including continuous monitoring, audits, assessments, and remediation.
The partner company operates a secure, mission-focused technology platform supporting government and commercial teams. It is an equal opportunity workplace committed to considering qualified candidates from all backgrounds.
Spearhead FedRAMP authorization and international sovereign cloud strategy.
Bridge federal security controls with scalable engineering execution.
Transform customer requirements into technical solutions meeting regulatory mandates.
Vultr makes high-performance cloud infrastructure easy, affordable, and locally accessible for enterprises and AI innovators. As the world's largest privately-held cloud infrastructure company with a $3.5 billion valuation, it serves hundreds of thousands of customers across 185 countries.
Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, and remediation.
Drive recurring continuous monitoring and evidence workflows across multiple teams.
Support vulnerability detection and response, including reconciling findings from tools like Wiz, Nessus, and Burp.
Abnormal protects the humans behind the world's most critical organizations from AI-powered cybercrime. 4,500+ enterprises trust their behavioral AI platform.
Build, deploy, and maintain cloud-based IAM systems using DevSecOps practices and cloud-native architecture.
Ensure rapid and reliable delivery of code changes through CI/CD, automated testing, and deployment into production.
Lead evergreening activities, environment support, and compliance with federal requirements.
PingWind delivers services to the federal government in cybersecurity, development, IT infrastructure, and supply chain management. They are an SBA certified Service-Disabled Veteran-Owned Small Business with offices in Northern Virginia and Huntsville AL.
Lead end-to-end service delivery for cybersecurity professional services, ensuring quality, timelines, and compliance for a portfolio of customers.
Drive operational strategy, governance frameworks, and KPIs for predictable delivery across FedRAMP advisory, implementation, and continuous monitoring programs.
Mentor and grow high-performing technical teams including project managers, cloud architects, security engineers, and analysts.
Quantum Sky engineers cybersecurity and cloud solutions for U.S. Federal agencies, focusing on FedRAMP, RMF, and post-quantum mission needs. The company fosters a collaborative, innovative, mission-driven culture with a high-performing team of technical professionals.
Own and evolve Orca’s FedRAMP environment across AWS GovCloud, Azure Government, and GCP, including infrastructure code, production health, and incident response.
Design automation to make compliance a byproduct of system operation, covering continuous validation, drift detection, and evidence collection.
Serve as the technical interface to federal customers, agency security teams, and assessors, leading authorization efforts and security reviews.
Orca Security is a cloud security innovation leader that invented agentless technology for comprehensive cloud security. The company is a unicorn with a $1.8 billion valuation, backed by top investors, and fosters a respectful and transparent culture.
Support security and compliance initiatives across cloud-based environments.
Conduct web application penetration testing and vulnerability assessments.
Implement and maintain security controls aligned with compliance frameworks.
Epsilon ASI is a technology company focused on providing secure and compliant environments for its clients. The company is looking for early-career security professionals to join its highly technical team in a remote setting.
Monitor, investigate, and respond to cybersecurity alerts, incidents, vulnerabilities, and threats across enterprise, endpoint, cloud, network, and application environments.
Support compliance with NIST SP 800-171, CMMC, and applicable federal/DoD cybersecurity requirements, including protection of CUI and FCI.
Conduct cybersecurity risk assessments, vulnerability assessments, and security reviews; prioritize findings and coordinate remediation efforts.
Tlingit Haida Tribal Business Corporation (THTBC) delivers mission-critical services to federal clients globally, including logistics, IT, cybersecurity, and facilities operations. For over 35 years, the company has been committed to generating economic opportunity for the Tlingit & Haida Tribes of Alaska, fostering a purpose-driven culture.
Conduct and manage regular security vulnerability scans of IAM systems using industry-standard tools, analyzing results and developing remediation plans.
Support federal compliance assessments including FISMA, A-123, BOD, and Safeguards reviews, developing corrective action plans and tracking remediation efforts.
Maintain and update Plans of Action and Milestones (POA&M) in CSAM, monitor CDM scan results, and ensure adherence to NIST guidance and federal cybersecurity standards.
PingWind is an SBA certified Service-Disabled Veteran-Owned Small Business (SDVOSB) delivering cybersecurity, development, IT infrastructure, and professional services to the federal government. The company has offices in Northern Virginia and Huntsville, AL, with a focus on mission-critical programs.
Lead the design and execution of cybersecurity architecture and engineering to ensure compliance with internal and external policies.
Partner with business leaders to identify risks, develop solutions, and embed security into enterprise strategy.
Oversee deployment, integration, and optimization of security tools while driving cloud-native security improvements.
U.S. Financial Technology builds and operates the world's largest mortgage securitization platform, supporting the Uniform Mortgage-Backed Security of Fannie Mae and Freddie Mac. It handles 70% of mortgage-backed securities and fosters a collaborative, remote-first culture.
Develop and implement cybersecurity strategies and architectures aligned with organizational objectives and regulatory requirements.
Lead RMF activities for large distributed systems to obtain and maintain Authority to Operate.
Collaborate with government stakeholders and cross-functional teams to integrate security across systems and networks.
The company specializes in cybersecurity architecture and Zero Trust solutions for U.S. Department of Defense clients. It offers a fully remote work environment with a focus on work-life balance and professional development opportunities.
Lead the development and implementation of security strategies, policies, and procedures.
Architect secure systems and collaborate with engineering teams to integrate security throughout the software development lifecycle.
Conduct risk assessments, incident response, and mentor junior engineers to promote security awareness.
Gemini is a global crypto and Web3 platform founded in 2014, offering secure crypto products and services to individuals and institutions in over 70 countries. The company is publicly traded with a mission to bridge traditional finance with the emerging cryptoeconomy, fostering a diverse team that prioritizes trust and security.
Provide overall program and contract management leadership for cybersecurity architecture and engineering activities.
Serve as primary interface with government stakeholders and translate requirements into actionable work plans.
Manage program schedules, risks, deliverables, and ensure alignment with Federal security standards.
9th Way Insignia is a service-disabled, veteran-owned small business bringing transformative technology to government customers. We specialize in cybersecurity, cloud modernization, and artificial intelligence.
Lead and oversee cybersecurity assessment and authorization activities for a major federal program.
Serve as the primary interface with government leadership and stakeholders.
Manage task order execution, staffing, schedules, and contractual performance.
This company supports federal cybersecurity programs and manages contracts for government clients. It offers a remote work environment and emphasizes employee empowerment and accountability.
Design and implement robust security monitoring, logging, and incident response for FSA IAM systems.
Ensure compliance with FISMA, NIST RMF, and FedRAMP through advanced logging (EL3) and SIEM processes.
Manage security remediation, POA&M tracking, and vulnerability management to maintain Authority to Operate.
PingWind delivers outstanding services to the federal government in cybersecurity, development, IT infrastructure, and supply chain management. It is an SBA-certified Service-Disabled Veteran-Owned Small Business with offices in Northern Virginia and Huntsville, AL.