Design, develop, and maintain automated workflows for RMF, A&A, and continuous monitoring.
Develop integrations between GRC platforms, security tools, and reporting solutions.
Automate evidence collection, control validation, and compliance activities to improve efficiency.
True Zero Technologies is a veteran-owned small business that enables people and technology to deliver top-tier cybersecurity services. With a people-first approach, the company has been recognized as a Best Places to Work honoree and made the Inc. 5000 list, reflecting a culture of driven and passionate individuals.
Design automation and build data-driven security workflows to embed security-by-design principles across the product development lifecycle.
Establish and maintain product security governance processes, ensuring traceability, accountability, and audit readiness.
Develop automated dashboards, KPIs, and security metrics using tools like Power BI, Tableau, or Grafana, and automate security workflows using Python and APIs.
The company is a technology organization focused on security solutions. It fosters a collaborative culture emphasizing innovation, continuous improvement, and professional growth.
Own the design and implementation of Onebrief's GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.
Build and manage the control environment, including policies, procedures, and evidence collection systems.
Design and implement technical security controls in partnership with Product, Engineering, Infrastructure and Corporate IT.
Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination. Founded in 2019 and valued at over $2 billion, the company is a distributed team of builders from military, operational, and technology backgrounds.
Lead GRC activities including risk management framework, security assessments, and continuous monitoring for assigned systems.
Collaborate with engineering and security teams to integrate GRC principles into system lifecycles and DevSecOps practices.
Develop and maintain security documentation, support ATO processes, and provide risk briefings to leadership.
The partner company helps organizations strengthen cybersecurity programs through modern GRC practices and engineering expertise. It is a fully remote organization with a collaborative culture focused on technical excellence and professional growth.
Manage and implement complex controls frameworks for large systems consisting of Cloud infrastructure and SaaS services.
Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
Conduct risk assessments across business units and processes, identifying risk findings and recommending remediation strategies.
Virtru is a data protection platform that enables secure sharing without sacrificing security or privacy. Backed by top venture capital firms, the company helps Fortune 500 companies and government agencies achieve true data security with freedom to share.
Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.
USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.
Own FedRAMP and GovRAMP certifications and roadmaps, including package management and compliance timelines.
Manage 3PAO relationships and assessments, coordinating scoping, evidence, and results validation.
Lead continuous monitoring, POA&M processes, and drive compliance automation and efficiency.
Smartsheet empowers teams to manage work seamlessly and scale solutions smarter, now uniting human teams with AI agents. It is an equal opportunity employer committed to fostering an inclusive environment with the best employees.
Provide comprehensive post-sales onboarding assistance, ensuring customers reach full production readiness and achieve long-term adoption.
Participate in solution workshops with customers to identify key requirements and shape prescriptive technical strategies.
Develop Python scripts to load customer data and integrate RegScale with external commercial tools and platforms.
RegScale is a continuous controls monitoring (CCM) platform that helps organizations automate and scale their security, risk, and compliance programs. We are at an inflection point, transitioning from startup execution to a disciplined, enterprise ready engineering organization, and we are building the team that will take us there.
Lead RMF activities including control selection, POA&M management, and ATO support for the depot.
Design supply chain security controls such as SBOM generation, artifact signing, and vulnerability scanning.
Integrate security tooling into CI/CD pipelines and interface with government assessors and authorizing officials.
OpenTeams builds AI that empowers, focusing on energy-efficient, cost-effective models that give users full ownership of their data. As a small company, they value freedom, teamwork, accountability, and reinvest 3% of profits into the open-source community.
Lead FedRAMP Moderate and CMMC readiness assessments, including system boundary validation and control gap analysis.
Design and implement cloud security architectures aligned to NIST 800-53 and NIST 800-171 requirements.
Develop and own System Security Plans (SSPs), control narratives, and compliance documentation.
Riveron helps organizations implement leading governance, risk and compliance practices with a hands-on approach. The company fosters an entrepreneurial culture with collaboration and diverse perspectives, offering flexible work and progressive benefits.
Perform enterprise risk assessments using NIST CSF, SOC 2, and CIS frameworks.
Develop and execute security awareness programs including training and phishing simulations.
Support governance and control management by maintaining policies and control libraries.
Protective helps protect customers against life's uncertainties by providing insurance and peace of mind. The company offers a collaborative environment with a focus on employee wellbeing and work-life balance.
Design and implement security controls across AWS GovCloud environments.
Integrate security into CI/CD pipelines using Terraform and GitLab.
Ensure compliance with FedRAMP and DoD IL-4/5 standards.
Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. We are a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, ownership, and results.
Assist in developing and maintaining scripts, tools, and automation frameworks to support security operations.
Help integrate security tools with CI/CD pipelines, monitoring systems, and incident response processes.
Automate repetitive security tasks such as log analysis, vulnerability scanning, and alert triage.
PatientPoint is a leading digital health company that connects patients, providers, and life sciences companies with the right information at the moments care decisions are made. With a network of digital devices in 35,000 physician offices serving over 750 million patient visits annually, the company offers a dynamic, purpose-driven culture.
Monitor and optimize Azure infrastructure for high availability and performance.
Troubleshoot DevSecOps tools and CI/CD pipeline operational issues.
Implement security tools and ensure compliance with DoD standards.
Falconwood, Inc. is a woman/veteran-owned business providing executive-level consultants and programmatic support to Department of Defense IT initiatives. They specialize in acquisition, cloud computing, and cybersecurity, and are a small company focused on DoD support.