Review system documentation and technical evidence against NIST, FISMA, RMF, FedRAMP, and Zero Trust requirements.
Perform control-gap analyses, maturity assessments, and compliance reviews; identify risks and recommend corrective actions.
Support authorization activities by preparing security plans, control implementation statements, and remediation documentation.
9th Way Insignia is a service-disabled, veteran-owned small business providing transformative technology solutions including cybersecurity, cloud modernization, software development, and data analytics to government customers. As a small business, it empowers its people to fearlessly drive change and offers a comprehensive benefits package.
Serve as the assigned security officer (vCISO) for a portfolio of client engagements, leading recurring meetings and providing strategic security guidance.
Lead CMMC Level 1 and 2 readiness engagements, including NIST SP 800-171 assessments, SSP development, and POA&M management.
Deliver compliance engagements across frameworks such as HIPAA, SOC 2, PCI DSS, ISO 27001, and more, while conducting risk assessments and coordinating remediation.
Intelligent Technical Solutions is a managed IT and cybersecurity services provider delivering compliance and security practice management to client organizations. The company employs a team of security professionals and fosters a culture of continuous improvement and knowledge sharing.
Conduct cybersecurity risk assessments and compliance reviews to identify gaps and remediation needs.
Support internal and external audits against Federal requirements and organizational policies.
Develop and maintain cybersecurity policies, procedures, and compliance documentation.
PingWind is a Service-Disabled Veteran-Owned Small Business that delivers cybersecurity, IT infrastructure, supply chain management, and professional services to the federal government. As a small business with offices in Northern Virginia and Huntsville, AL, PingWind fosters a dynamic team environment focused on supporting large government clients.
Monitor, investigate, and respond to cybersecurity alerts, incidents, vulnerabilities, and threats across enterprise, endpoint, cloud, network, and application environments.
Support compliance with NIST SP 800-171, CMMC, and applicable federal/DoD cybersecurity requirements, including protection of CUI and FCI.
Conduct cybersecurity risk assessments, vulnerability assessments, and security reviews; prioritize findings and coordinate remediation efforts.
Tlingit Haida Tribal Business Corporation (THTBC) delivers mission-critical services to federal clients globally, including logistics, IT, cybersecurity, and facilities operations. For over 35 years, the company has been committed to generating economic opportunity for the Tlingit & Haida Tribes of Alaska, fostering a purpose-driven culture.
Lead enterprise and division risk assessments to identify strategic, operational, compliance, technology, and cybersecurity risks.
Maintain the enterprise risk register, develop KRIs/KPIs, and produce executive-level risk reports and dashboards.
Evaluate policies and controls to address weaknesses, drive corrective actions, and improve ERM processes.
SkyePoint Decisions is a cybersecurity architecture and engineering IT service provider headquartered in Dulles, Virginia, serving federal government clients. It is a certified small business with a collaborative culture focused on innovation and mission success.
Own risk identification, analysis, and prioritization across third-party risk and security risk assessments using established frameworks.
Translate technical vulnerabilities and risk findings into clear, quantified risk statements for non-security stakeholders and leadership.
Drive remediation of findings and risk exceptions to closure, partnering with Engineering, IT, Product, and Legal.
GitLab is an intelligent orchestration platform for DevSecOps, helping organizations increase developer productivity and improve security. With over 50 million users, GitLab is trusted by more than 50% of the Fortune 100 and fosters a high-performance culture driven by values and continuous knowledge exchange.
Provide technical expertise on security controls and system architecture for FedRAMP compliance.
Perform detailed architecture reviews of Cloud Service Providers (CSPs) and author package briefings.
Lead architecture interviews and reviews, ensuring alignment with NIST, FISMA, and FedRAMP standards.
Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies, it has been recognized as a Best Place to Work in the D.C. area for 12 consecutive years, fostering a culture of trust, growth, and work-life balance.
Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.
Develop and implement cybersecurity strategies and architectures aligned with organizational objectives and regulatory requirements.
Lead RMF activities for large distributed systems to obtain and maintain Authority to Operate.
Collaborate with government stakeholders and cross-functional teams to integrate security across systems and networks.
The company specializes in cybersecurity architecture and Zero Trust solutions for U.S. Department of Defense clients. It offers a fully remote work environment with a focus on work-life balance and professional development opportunities.
Own the overall security posture, including policy, standards, and risk framework.
Manage ISO 27001, SOC 2, FedRAMP, and CMMC compliance programs.
Lead incident response, vulnerability management, and customer security assurance.
RapidFort is a cybersecurity company that helps organizations secure and optimize their software supply chain and containerized environments. As a fast-growing startup, we foster a culture of ownership and direct communication, where every team member contributes to our mission of securing cloud-native applications for regulated industries.
Lead compliance assessments and build-out of IL4/IL5 authorizations for DoD Cloud Computing Security Requirements Guide.
Maintain and evolve compliance posture for FedRAMP High, NIST SP 800-53, and other federal frameworks.
Serve as GRC liaison to engineering teams, translating complex federal compliance requirements into technical specifications for AWS environments.
Horizon3 is a fast-growing, remote cybersecurity company that provides autonomous pentesting through its NodeZero platform. The company is a fusion of former Special Operations cyber operators and engineers, fostering a culture of respect, collaboration, ownership, and results.
Lead and mature enterprise and technology risk management, including AI governance for machine learning and generative AI.
Translate regulatory and control expectations into actionable policies, risk frameworks, and processes.
Collaborate with technology, security, privacy, compliance, and business teams to strengthen the control environment.
The company is a growing technology organization operating in the financial-services sector. It fosters a diverse and inclusive workplace and supports professional development and continuous learning.
Design and implement an end-to-end Enterprise Cybersecurity Risk Register.
Lead governance lifecycle, establish risk ownership, and drive cross-functional stakeholder alignment.
Deliver audit-ready documentation and ensure post-contract sustainability through structured knowledge transfer.
ASSYST is a technology consulting firm that provides staffing and solutions. The company seeks to place experienced professionals in client engagements, though size and culture are not specified.
Design and implement cybersecurity controls for satellite software, ground systems, and mission infrastructure.
Develop secure software practices including threat modeling, code reviews, and vulnerability management.
Monitor networks for cyber threats, lead incident response, and support compliance with NIST 800-171 and CMMC.
Muon Space is an end-to-end Space Systems Provider that designs, builds, and operates LEO satellite constellations delivering mission-critical data. Founded in 2021, the company is based in Silicon Valley and offers a comprehensive benefits package including equity, medical, dental, vision, 401k, paid vacation, and parental leave.
Deliver third-party security and supplier assurance, assessing risks and translating findings into actionable recommendations.
Lead security assurance activities, including control testing, PCI DSS assessments, and audits, driving remediation to completion.
Strengthen governance by improving security policies and procedures, and support teams with security risk guidance and innovative solutions.
Monzo is a digital bank on a mission to make money work for everyone, offering personal and business accounts, savings, investments, and credit cards. With a team of over 3,000 Monzonauts, we foster an inclusive and diverse culture where everyone can grow and do their best work.
Perform cybersecurity and technology risk assessments across systems, vendors, and business processes.
Support compliance with SOC 2, HIPAA, HITRUST, and PCI DSS frameworks.
Manage third-party risk assessments and track remediation of security findings.
Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. They partner with companies to manage applications and hiring processes, offering remote roles and streamlined recruitment.
Lead development of security architecture guidance, standards, and reference diagrams for on-premise and cloud platforms.
Support design and assessment of enterprise security architectures using commercial and government frameworks like NIST and OWASP.
Collaborate with stakeholders, assess security postures, and contribute to risk management and compliance activities.
Valiant Solutions is a security-focused IT solutions provider serving public clients nationwide. Named one of the fastest growing privately held companies by Inc. 5000, the company prides itself on an employee-centric culture and offers great benefits and career development opportunities.
Lead complex incident response investigations end-to-end with minimal supervision.
Perform alert triage, phishing investigations, endpoint forensics, and data exfiltration analysis.
Mentor junior analysts and drive improvements to security processes.
Version 1 is a technology and transformation solutions provider trusted by global brands. With over 3,300 employees and €350m revenue, it has been recognized as a Great Place to Work for over a decade.
Establish and enforce a unified security posture across GCP and OCI, including guardrails, IAM policies, and centralized monitoring.
Validate cloud deployments meet FedRAMP High, FISMA, and NIST 800-53 requirements, working with governance and audit teams.
Identify vulnerabilities, policy deviations, and architectural risks, and drive remediation.
Latitude is a growing Service-Disabled Veteran Owned company within the Federal Sector, working with various federal clients across multiple agencies. They foster a remote work-from-home culture, invest in employee growth, and strive for innovation to break through technology and government barriers.
Lead cybersecurity governance, assessment, and audit activities supporting a federal customer.
Coordinate evidence, control assessments, and remediation across NIST, RMF, and federal compliance requirements.
Maintain quality control, configuration traceability, and readiness for IV&V, QA, and government surveillance.
SkyePoint Decisions is a cybersecurity architecture, engineering, and IT services provider supporting federal government clients. Headquartered in Dulles, Virginia, it is an ISO-certified small business with a collaborative culture focused on mission assurance.