Review system documentation and technical evidence against NIST, FISMA, RMF, FedRAMP, and Zero Trust requirements.
Perform control-gap analyses, maturity assessments, and compliance reviews; identify risks and recommend corrective actions.
Support authorization activities by preparing security plans, control implementation statements, and remediation documentation.
9th Way Insignia is a service-disabled, veteran-owned small business providing transformative technology solutions including cybersecurity, cloud modernization, software development, and data analytics to government customers. As a small business, it empowers its people to fearlessly drive change and offers a comprehensive benefits package.
Plan, implement, and upgrade security controls and architecture to safeguard systems and sensitive information.
Conduct risk assessments, penetration testing, and vulnerability assessments, then track mitigation plans.
Support compliance with NIST 800-171, develop governance documentation, and deliver security awareness training.
Insitu, a Boeing Company, provides unmanned air systems and software solutions for collecting, processing, and understanding sensor data to support critical decision-making. With over 1 million operational flight hours, the company values integrity, collaboration, and adaptability in a fast-paced, mission-driven environment.
Provide technical expertise on security controls and system architecture for FedRAMP compliance.
Perform detailed architecture reviews of Cloud Service Providers (CSPs) and author package briefings.
Lead architecture interviews and reviews, ensuring alignment with NIST, FISMA, and FedRAMP standards.
Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies, it has been recognized as a Best Place to Work in the D.C. area for 12 consecutive years, fostering a culture of trust, growth, and work-life balance.
Lead security risk assessments across engineering, IT, operations, and business functions.
Maintain a risk register and provide leadership with a clear view of the company's risk posture.
Partner with teams to drive remediation of risks and map controls to compliance frameworks like NIST 800-171.
Muon Space is an end-to-end Space Systems Provider that designs, builds, and operates LEO satellite constellations delivering mission-critical data. Founded in 2021, the company operates a state-of-the-art facility in Silicon Valley and is committed to fostering a diverse and dynamic workforce.
Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, and remediation.
Drive recurring continuous monitoring and evidence workflows across multiple teams.
Support vulnerability detection and response, including reconciling findings from tools like Wiz, Nessus, and Burp.
Abnormal protects the humans behind the world's most critical organizations from AI-powered cybercrime. 4,500+ enterprises trust their behavioral AI platform.
Monitor, investigate, and respond to cybersecurity alerts, incidents, vulnerabilities, and threats across enterprise, endpoint, cloud, network, and application environments.
Support compliance with NIST SP 800-171, CMMC, and applicable federal/DoD cybersecurity requirements, including protection of CUI and FCI.
Conduct cybersecurity risk assessments, vulnerability assessments, and security reviews; prioritize findings and coordinate remediation efforts.
Tlingit Haida Tribal Business Corporation (THTBC) delivers mission-critical services to federal clients globally, including logistics, IT, cybersecurity, and facilities operations. For over 35 years, the company has been committed to generating economic opportunity for the Tlingit & Haida Tribes of Alaska, fostering a purpose-driven culture.
Support information assurance and cybersecurity activities for the Army Contract Writing System (ACWS).
Assist with implementation and maintenance of security controls per NIST, RMF, STIG, and DoD requirements.
Develop and maintain security documentation including SSPs, POA&Ms, and continuous monitoring artifacts.
LMI is a digital solutions provider dedicated to accelerating government impact with innovation and speed. Headquartered in Tysons, Virginia, the company delivers mission-ready technology and solutions to federal agencies.
Lead development of security architecture guidance, standards, and reference diagrams for on-premise and cloud platforms.
Support design and assessment of enterprise security architectures using commercial and government frameworks like NIST and OWASP.
Collaborate with stakeholders, assess security postures, and contribute to risk management and compliance activities.
Valiant Solutions is a security-focused IT solutions provider serving public clients nationwide. Named one of the fastest growing privately held companies by Inc. 5000, the company prides itself on an employee-centric culture and offers great benefits and career development opportunities.
Participate in assessing client environments against frameworks like NIST CSF 2.0, CIS Controls, and ISO 27001.
Design and implement secure solutions across cybersecurity, networking, and cloud technologies.
Perform configuration, installation, and maintenance of security products and services.
Apollo Information Systems is a cybersecurity services company delivering unified security and compliance programs through a subscription-based platform. Backed by Series A funding, the company is growing rapidly with a collaborative, mission-driven culture and a remote-first team with a hub in Denver.
Conduct cybersecurity risk assessments and compliance reviews to identify gaps and remediation needs.
Support internal and external audits against Federal requirements and organizational policies.
Develop and maintain cybersecurity policies, procedures, and compliance documentation.
PingWind is a Service-Disabled Veteran-Owned Small Business that delivers cybersecurity, IT infrastructure, supply chain management, and professional services to the federal government. As a small business with offices in Northern Virginia and Huntsville, AL, PingWind fosters a dynamic team environment focused on supporting large government clients.
Serve as the assigned security officer (vCISO) for a portfolio of client engagements, leading recurring meetings and providing strategic security guidance.
Lead CMMC Level 1 and 2 readiness engagements, including NIST SP 800-171 assessments, SSP development, and POA&M management.
Deliver compliance engagements across frameworks such as HIPAA, SOC 2, PCI DSS, ISO 27001, and more, while conducting risk assessments and coordinating remediation.
Intelligent Technical Solutions is a managed IT and cybersecurity services provider delivering compliance and security practice management to client organizations. The company employs a team of security professionals and fosters a culture of continuous improvement and knowledge sharing.
Build and maintain technical controls across security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, and other enterprise requirements.
Automate compliance workflows, evidence collection, access reviews, and security checks.
Partner with Engineering and Security to implement controls around access management, infrastructure, data protection, logging, and vulnerability management.
Retell AI is reimagining the call center with cutting-edge voice AI. Backed by Y Combinator, the company has scaled to $60M ARR with a team of 40 people, and is looking for ambitious builders to tackle hard technical problems.
Independently execute endpoint security, identity management, and vulnerability remediation across Windows, macOS, Linux, and cloud platforms.
Monitor and analyze alerts within SIEM and EDR, conduct initial investigations, and escalate complex findings as needed.
Partner with IT, Engineering, DevOps, and IAM teams to maintain security controls and support compliance frameworks like SOC 2, HIPAA, and ISO 27001.
Accela is an industry leader in designing and delivering government software to improve efficiency, increase citizen engagement, and enable the development of thriving communities. The company has been operating for nearly 20 years, fosters a diverse and inclusive culture, and is committed to equity and belonging.
Lead compliance assessments and build-out of IL4/IL5 authorizations for DoD Cloud Computing Security Requirements Guide.
Maintain and evolve compliance posture for FedRAMP High, NIST SP 800-53, and other federal frameworks.
Serve as GRC liaison to engineering teams, translating complex federal compliance requirements into technical specifications for AWS environments.
Horizon3 is a fast-growing, remote cybersecurity company that provides autonomous pentesting through its NodeZero platform. The company is a fusion of former Special Operations cyber operators and engineers, fostering a culture of respect, collaboration, ownership, and results.
Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.
Establish and enforce a unified security posture across GCP and OCI, including guardrails, IAM policies, and centralized monitoring.
Validate cloud deployments meet FedRAMP High, FISMA, and NIST 800-53 requirements, working with governance and audit teams.
Identify vulnerabilities, policy deviations, and architectural risks, and drive remediation.
Latitude is a growing Service-Disabled Veteran Owned company within the Federal Sector, working with various federal clients across multiple agencies. They foster a remote work-from-home culture, invest in employee growth, and strive for innovation to break through technology and government barriers.
Design and implement cybersecurity controls for satellite software, ground systems, and mission infrastructure.
Develop secure software practices including threat modeling, code reviews, and vulnerability management.
Monitor networks for cyber threats, lead incident response, and support compliance with NIST 800-171 and CMMC.
Muon Space is an end-to-end Space Systems Provider that designs, builds, and operates LEO satellite constellations delivering mission-critical data. Founded in 2021, the company is based in Silicon Valley and offers a comprehensive benefits package including equity, medical, dental, vision, 401k, paid vacation, and parental leave.
Deploy and automate CI/CD pipelines and establish IaC using modern DevSecOps techniques including serverless and Zero Trust patterns.
Own the POAM process end to end, develop plans of action with target dates, track progress, and close findings proactively.
Conduct Security Impact Analyses (SIAs) to achieve and maintain ATO, and maintain a live dashboard for all security findings.
Oddball brings quality software to the federal space, aiming to improve the daily lives of millions. It is a small company that values learning, growth, and making a big impact.
Lead and grow a small security team while owning Canary's security and compliance program end-to-end.
Serve as the primary security voice to customers, partners, and auditors, translating security posture for varied audiences.
Set technical direction for security tooling and stay hands-on in architecture and threat-model reviews.
Canary Technologies is a leading agentic AI platform for hotel and guest management, powering digital infrastructure for over 20,000 hotels in 125+ countries. With nearly $200M raised, they are a top-funded hotel tech company, recognized for growth and workplace excellence.
Lead cybersecurity governance, assessment, and audit activities supporting a federal customer.
Coordinate evidence, control assessments, and remediation across NIST, RMF, and federal compliance requirements.
Maintain quality control, configuration traceability, and readiness for IV&V, QA, and government surveillance.
SkyePoint Decisions is a cybersecurity architecture, engineering, and IT services provider supporting federal government clients. Headquartered in Dulles, Virginia, it is an ISO-certified small business with a collaborative culture focused on mission assurance.