Lead Atmosera's internal GRC program and managed GRC service delivery.
Manage federal System Security Plans, POA&Ms, and audit responses.
Serve as a senior GRC advisor bridging executive and technical teams.
Atmosera empowers businesses to redefine what's possible with modern technology and human expertise across Applications, Data & AI, DevOps, Security, and Microsoft Azure. As a Microsoft Partner with seven specializations, the company values humility, hunger, and mindfulness in a collaborative team environment.
Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.
Own the compliance function as its sole occupant, reporting to the Head of Engineering and partnering with the Security Lead on policies, audits, and evidence.
Manage the Q&A library, customer security reviews, audit calendar, and third-party risk to keep Duvo reviewable for buyers and auditors.
Deliver precise, evidenced answers that stand up to hostile reviewers and keep the trust center and subprocessor list current.
Duvo builds an AI operations platform for large enterprises, enabling customers to create AI agents that automate business-critical processes across systems like SAP, spreadsheets, and supplier portals. The company is growing fast and values velocity, direct feedback, autonomy, and heavy use of AI tools.
Lead end-to-end service delivery for cybersecurity professional services, ensuring quality, timelines, and compliance for a portfolio of customers.
Drive operational strategy, governance frameworks, and KPIs for predictable delivery across FedRAMP advisory, implementation, and continuous monitoring programs.
Mentor and grow high-performing technical teams including project managers, cloud architects, security engineers, and analysts.
Quantum Sky engineers cybersecurity and cloud solutions for U.S. Federal agencies, focusing on FedRAMP, RMF, and post-quantum mission needs. The company fosters a collaborative, innovative, mission-driven culture with a high-performing team of technical professionals.
Own end-to-end audit evidence collection and validation across multiple compliance frameworks including FedRAMP, ISO 27001, and SOC 2.
Maintain and continuously verify technical controls across GCP, GitHub, and Microsoft 365 environments.
Serve as the primary liaison between GRC and technical teams to reduce audit burden and ensure continuous audit readiness.
A-LIGN is a leading provider of cybersecurity compliance programs, offering services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. They are the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor, operating in a high-growth, PE-backed environment.
Monarch is an all-in-one personal finance platform that simplifies finances. Since 2021, they have become the top-recommended app, with a fully remote, AI-driven team focused on building a product people love.
Build and maintain compliance frameworks in the Secfix platform, including ISO 27001, TISAX, SOC 2, GDPR, and more.
Own internal audits end-to-end for customers, ensuring they are prepared for external audits.
Collaborate with product and engineering to translate compliance gaps into structured product work and enhance platform quality.
Secfix automates security compliance for European companies, helping them achieve ISO 27001, GDPR, TISAX, and SOC 2 efficiently. They are a 100% remote team with hubs in Munich, Berlin, and London, recently raised a $12M Series A, and are backed by top VCs.
Lead cybersecurity governance, assessment, and audit activities supporting a federal customer.
Coordinate evidence, control assessments, and remediation across NIST, RMF, and federal compliance requirements.
Maintain quality control, configuration traceability, and readiness for IV&V, QA, and government surveillance.
SkyePoint Decisions is a cybersecurity architecture, engineering, and IT services provider supporting federal government clients. Headquartered in Dulles, Virginia, it is an ISO-certified small business with a collaborative culture focused on mission assurance.
Lead projects from client acquisition to final delivery and oversee client service teams on multiple engagements.
Perform technical security assessments, audits, and risk evaluations across applications and infrastructure.
Mentor and develop staff while cultivating client relationships and cross-selling firm services.
The Bonadio Group is a leading accounting, advisory, and consulting firm providing next-level solutions to clients across industries. The firm values diversity, innovation, and professional growth, offering mentoring and training programs with a path to partnership.
Own global certification programs like ISO 27001 and SOC 2, and advise engineering teams on secure development.
Collaborate directly with engineers to audit cloud infrastructure, CI/CD pipelines, and AI-driven security controls.
Assess risks of emerging technologies and drive continuous compliance improvements across the organization.
Picus Security is an exposure validation company that proves what attackers can exploit and what defenses stop, turning exposures into defensible decisions. As a fast-growing global remote team, it values continuous security validation and has a 95% recommendation rate.
Own risk identification, analysis, and prioritization across third-party risk and security risk assessments using established frameworks.
Translate technical vulnerabilities and risk findings into clear, quantified risk statements for non-security stakeholders and leadership.
Drive remediation of findings and risk exceptions to closure, partnering with Engineering, IT, Product, and Legal.
GitLab is an intelligent orchestration platform for DevSecOps, helping organizations increase developer productivity and improve security. With over 50 million users, GitLab is trusted by more than 50% of the Fortune 100 and fosters a high-performance culture driven by values and continuous knowledge exchange.
Lead compliance assessments and build-out of IL4/IL5 authorizations for DoD Cloud Computing Security Requirements Guide.
Maintain and evolve compliance posture for FedRAMP High, NIST SP 800-53, and other federal frameworks.
Serve as GRC liaison to engineering teams, translating complex federal compliance requirements into technical specifications for AWS environments.
Horizon3 is a fast-growing, remote cybersecurity company that provides autonomous pentesting through its NodeZero platform. The company is a fusion of former Special Operations cyber operators and engineers, fostering a culture of respect, collaboration, ownership, and results.
Define Sprinto's Professional Services portfolio and build a scalable delivery function.
Lead audit delivery partnerships and ensure independence and quality standards.
Work closely with Product to convert customer and auditor feedback into product improvements.
Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers. Backed by top-tier investors such as Accel, Elevation, and Blume Ventures, we have raised $31.8M in funding and are trusted by over 4,000 organizations across 75 countries.
Act as part vCISO and account manager, guiding clients through security and compliance programs.
Assess security posture, provide recommendations, and design programs using NIST, SOC 2, and ISO 27001.
Liaise with auditors and internal teams to translate programs into policies, procedures, and configurations.
Oneleet provides a platform for companies to build, manage, and monitor cybersecurity programs and achieve SOC 2 and ISO 27001. It raised a $33M Series A and is a fast-growing, remote-first team with an opinionated culture.
Lead and mature enterprise and technology risk management, including AI governance for machine learning and generative AI.
Translate regulatory and control expectations into actionable policies, risk frameworks, and processes.
Collaborate with technology, security, privacy, compliance, and business teams to strengthen the control environment.
The company is a growing technology organization operating in the financial-services sector. It fosters a diverse and inclusive workplace and supports professional development and continuous learning.
Own the overall security posture, including policy, standards, and risk framework.
Manage ISO 27001, SOC 2, FedRAMP, and CMMC compliance programs.
Lead incident response, vulnerability management, and customer security assurance.
RapidFort is a cybersecurity company that helps organizations secure and optimize their software supply chain and containerized environments. As a fast-growing startup, we foster a culture of ownership and direct communication, where every team member contributes to our mission of securing cloud-native applications for regulated industries.
Lead ISO 27001 and SOC 2 audit cycles end-to-end, owning compliance and audit.
Own customer trust by responding to security questionnaires and representing InfoSec to enterprise clients.
Drive risk management, vendor security, and incident response while building AI-assisted workflows.
We are the first AI-native Employee Experience Platform, helping organizations unlock inspirational communication. Our diverse team of 550+ employees supports over 1,500 customers, and we are a unicorn company valued at over $1 billion.
Lead security risk assessments across engineering, IT, operations, and business functions.
Maintain a risk register and provide leadership with a clear view of the company's risk posture.
Partner with teams to drive remediation of risks and map controls to compliance frameworks like NIST 800-171.
Muon Space is an end-to-end Space Systems Provider that designs, builds, and operates LEO satellite constellations delivering mission-critical data. Founded in 2021, the company operates a state-of-the-art facility in Silicon Valley and is committed to fostering a diverse and dynamic workforce.
Drive SOC 2, ISO 27001, and PCI 4.0 compliance audit cycles: gather evidence, design controls, and coordinate with auditors.
Own the compliance automation platform Vanta: monitor control status, chase failing checks, and update risk register.
Run vendor and third-party risk reviews, security assessments, and respond to customer security questionnaires.
AssemblyAI builds the best-in-class Voice AI models powering the next generation of voice applications. With under 100 people, it is a capital-efficient AI company generating roughly $500K ARR per employee and operating as a true meritocracy with no bureaucracy.