Source Job

US

  • Lead cybersecurity governance, assessment, and audit activities supporting a federal customer.
  • Coordinate evidence, control assessments, and remediation across NIST, RMF, and federal compliance requirements.
  • Maintain quality control, configuration traceability, and readiness for IV&V, QA, and government surveillance.

Cybersecurity NIST Governance

20 jobs similar to Oversight and Governance Lead

Jobs ranked by similarity.

US

  • Lead and oversee cybersecurity assessment and authorization activities for a major federal program.
  • Serve as the primary interface with government leadership and stakeholders.
  • Manage task order execution, staffing, schedules, and contractual performance.

This company supports federal cybersecurity programs and manages contracts for government clients. It offers a remote work environment and emphasizes employee empowerment and accountability.

$77,000–$107,000/yr
US

  • Conduct cybersecurity risk assessments and compliance reviews to identify gaps and remediation needs.
  • Support internal and external audits against Federal requirements and organizational policies.
  • Develop and maintain cybersecurity policies, procedures, and compliance documentation.

PingWind is a Service-Disabled Veteran-Owned Small Business that delivers cybersecurity, IT infrastructure, supply chain management, and professional services to the federal government. As a small business with offices in Northern Virginia and Huntsville, AL, PingWind fosters a dynamic team environment focused on supporting large government clients.

$140,000–$155,000/yr
US

  • Provide technical expertise on security controls and system architecture for FedRAMP compliance.
  • Perform detailed architecture reviews of Cloud Service Providers (CSPs) and author package briefings.
  • Lead architecture interviews and reviews, ensuring alignment with NIST, FISMA, and FedRAMP standards.

Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies, it has been recognized as a Best Place to Work in the D.C. area for 12 consecutive years, fostering a culture of trust, growth, and work-life balance.

US

  • Review system documentation and technical evidence against NIST, FISMA, RMF, FedRAMP, and Zero Trust requirements.
  • Perform control-gap analyses, maturity assessments, and compliance reviews; identify risks and recommend corrective actions.
  • Support authorization activities by preparing security plans, control implementation statements, and remediation documentation.

9th Way Insignia is a service-disabled, veteran-owned small business providing transformative technology solutions including cybersecurity, cloud modernization, software development, and data analytics to government customers. As a small business, it empowers its people to fearlessly drive change and offers a comprehensive benefits package.

$115,000–$186,000/yr
US

  • Lead compliance assessments and build-out of IL4/IL5 authorizations for DoD Cloud Computing Security Requirements Guide.
  • Maintain and evolve compliance posture for FedRAMP High, NIST SP 800-53, and other federal frameworks.
  • Serve as GRC liaison to engineering teams, translating complex federal compliance requirements into technical specifications for AWS environments.

Horizon3 is a fast-growing, remote cybersecurity company that provides autonomous pentesting through its NodeZero platform. The company is a fusion of former Special Operations cyber operators and engineers, fostering a culture of respect, collaboration, ownership, and results.

US Unlimited PTO

  • Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
  • Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
  • Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.

GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.

US

  • Monitor, investigate, and respond to cybersecurity alerts, incidents, vulnerabilities, and threats across enterprise, endpoint, cloud, network, and application environments.
  • Support compliance with NIST SP 800-171, CMMC, and applicable federal/DoD cybersecurity requirements, including protection of CUI and FCI.
  • Conduct cybersecurity risk assessments, vulnerability assessments, and security reviews; prioritize findings and coordinate remediation efforts.

Tlingit Haida Tribal Business Corporation (THTBC) delivers mission-critical services to federal clients globally, including logistics, IT, cybersecurity, and facilities operations. For over 35 years, the company has been committed to generating economic opportunity for the Tlingit & Haida Tribes of Alaska, fostering a purpose-driven culture.

$170,000–$190,000/yr
US

  • Lead end-to-end service delivery for cybersecurity professional services, ensuring quality, timelines, and compliance for a portfolio of customers.
  • Drive operational strategy, governance frameworks, and KPIs for predictable delivery across FedRAMP advisory, implementation, and continuous monitoring programs.
  • Mentor and grow high-performing technical teams including project managers, cloud architects, security engineers, and analysts.

Quantum Sky engineers cybersecurity and cloud solutions for U.S. Federal agencies, focusing on FedRAMP, RMF, and post-quantum mission needs. The company fosters a collaborative, innovative, mission-driven culture with a high-performing team of technical professionals.

$154,000–$207,000/yr
US 3w PTO

  • Lead security risk assessments across engineering, IT, operations, and business functions.
  • Maintain a risk register and provide leadership with a clear view of the company's risk posture.
  • Partner with teams to drive remediation of risks and map controls to compliance frameworks like NIST 800-171.

Muon Space is an end-to-end Space Systems Provider that designs, builds, and operates LEO satellite constellations delivering mission-critical data. Founded in 2021, the company operates a state-of-the-art facility in Silicon Valley and is committed to fostering a diverse and dynamic workforce.

$119,000–$166,000/yr
US

  • Lead a complex cybersecurity and enterprise security engineering program for a large Federal Government client.
  • Manage contract performance, personnel, schedule, deliverables, risks, and technical activities.
  • Oversee IT and cloud security architecture, engineering, development, and implementation.

PingWind delivers outstanding services to the federal government, specializing in cybersecurity, development, IT infrastructure, and supply chain management. It is an SBA certified Service-Disabled Veteran-Owned Small Business (SDVOSB) with offices in Northern Virginia and Huntsville AL, fostering a culture of service and excellence.

US

  • Support information assurance and cybersecurity activities for the Army Contract Writing System (ACWS).
  • Assist with implementation and maintenance of security controls per NIST, RMF, STIG, and DoD requirements.
  • Develop and maintain security documentation including SSPs, POA&Ms, and continuous monitoring artifacts.

LMI is a digital solutions provider dedicated to accelerating government impact with innovation and speed. Headquartered in Tysons, Virginia, the company delivers mission-ready technology and solutions to federal agencies.

US Unlimited PTO 16w maternity 16w paternity

  • Own the V4G partner strategy across Federal and SLED, defining partner archetypes, tiering, and coverage model.
  • Own the V4G partner-sourced pipeline and ARR contribution, and define metrics for partner performance and network coverage.
  • Design programs and mechanisms that let the network scale, including partner tiering, enablement, co-sell motion, and standardized agreements.

Vanta provides a Trust Management Platform that helps businesses automate security monitoring and compliance to earn and prove trust. They have a kind and talented team of hundreds of employees, and they are committed to building an inclusive culture.

$86,896–$130,000/yr
United States

  • Provide overall program and contract management leadership for cybersecurity architecture and engineering activities.
  • Serve as primary interface with government stakeholders and translate requirements into actionable work plans.
  • Manage program schedules, risks, deliverables, and ensure alignment with Federal security standards.

9th Way Insignia is a service-disabled, veteran-owned small business bringing transformative technology to government customers. We specialize in cybersecurity, cloud modernization, and artificial intelligence.

US

  • Lead enterprise and division risk assessments to identify strategic, operational, compliance, technology, and cybersecurity risks.
  • Maintain the enterprise risk register, develop KRIs/KPIs, and produce executive-level risk reports and dashboards.
  • Evaluate policies and controls to address weaknesses, drive corrective actions, and improve ERM processes.

SkyePoint Decisions is a cybersecurity architecture and engineering IT service provider headquartered in Dulles, Virginia, serving federal government clients. It is a certified small business with a collaborative culture focused on innovation and mission success.

$77,245–$95,200/yr
US

  • Support governance, risk, privacy, and compliance programs to ensure alignment with regulatory requirements.
  • Conduct risk assessments for vendors and new technologies, and maintain compliance with GDPR and other regulations.
  • Manage data governance, privacy evaluations, and cybersecurity awareness training.

RMI is an independent nonprofit transforming global energy systems for a zero-carbon future. Founded in 1982, the organization has a global team and a remote-ready culture.

$114,800–$173,250/yr
US

  • Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, and remediation.
  • Drive recurring continuous monitoring and evidence workflows across multiple teams.
  • Support vulnerability detection and response, including reconciling findings from tools like Wiz, Nessus, and Burp.

Abnormal protects the humans behind the world's most critical organizations from AI-powered cybercrime. 4,500+ enterprises trust their behavioral AI platform.

$151,000–$189,000/yr
US Unlimited PTO

  • Lead and mature enterprise and technology risk management, including AI governance for machine learning and generative AI.
  • Translate regulatory and control expectations into actionable policies, risk frameworks, and processes.
  • Collaborate with technology, security, privacy, compliance, and business teams to strengthen the control environment.

The company is a growing technology organization operating in the financial-services sector. It fosters a diverse and inclusive workplace and supports professional development and continuous learning.

US

  • Deliver compelling technical demonstrations of Tenable's platform tailored to public sector needs.
  • Support enterprise software trials and 'Proof of Value' evaluations to align with customer goals.
  • Build strong, trusting relationships with customers, partners, and internal peers across all levels.

Tenable is the Exposure Management company, helping over 40,000 organizations understand and reduce cyber risk. With a global team that supports 65% of the Fortune 500 and 50% of the Global 2000, they foster a culture of belonging, respect, and excellence.

$135,000–$216,000/yr
US

  • Provide executive-level oversight of a multi-agency technology initiative, serving as primary interface between delivery team and government stakeholders.
  • Manage schedule, budget, and risk across all workstreams, ensuring compliance with IT governance frameworks like FITARA and FedRAMP.
  • Coordinate with federal agencies including DOI, FWS, and NOAA to maintain alignment and deliver comprehensive ESA data integration.

Peraton is a next-generation national security company that delivers mission-critical solutions and technologies to protect the nation and allies. It is a large enterprise IT provider serving government agencies, with a culture focused on solving complex challenges.

$230,000–$260,000/yr
US

  • Own and evolve Orca’s FedRAMP environment across AWS GovCloud, Azure Government, and GCP, including infrastructure code, production health, and incident response.
  • Design automation to make compliance a byproduct of system operation, covering continuous validation, drift detection, and evidence collection.
  • Serve as the technical interface to federal customers, agency security teams, and assessors, leading authorization efforts and security reviews.

Orca Security is a cloud security innovation leader that invented agentless technology for comprehensive cloud security. The company is a unicorn with a $1.8 billion valuation, backed by top investors, and fosters a respectful and transparent culture.