Review system documentation and technical evidence against NIST, FISMA, RMF, FedRAMP, and Zero Trust requirements.
Perform control-gap analyses, maturity assessments, and compliance reviews; identify risks and recommend corrective actions.
Support authorization activities by preparing security plans, control implementation statements, and remediation documentation.
9th Way Insignia is a service-disabled, veteran-owned small business providing transformative technology solutions including cybersecurity, cloud modernization, software development, and data analytics to government customers. As a small business, it empowers its people to fearlessly drive change and offers a comprehensive benefits package.
Monitor, investigate, and respond to cybersecurity alerts, incidents, vulnerabilities, and threats across enterprise, endpoint, cloud, network, and application environments.
Support compliance with NIST SP 800-171, CMMC, and applicable federal/DoD cybersecurity requirements, including protection of CUI and FCI.
Conduct cybersecurity risk assessments, vulnerability assessments, and security reviews; prioritize findings and coordinate remediation efforts.
Tlingit Haida Tribal Business Corporation (THTBC) delivers mission-critical services to federal clients globally, including logistics, IT, cybersecurity, and facilities operations. For over 35 years, the company has been committed to generating economic opportunity for the Tlingit & Haida Tribes of Alaska, fostering a purpose-driven culture.
Lead security risk assessments across engineering, IT, operations, and business functions.
Maintain a risk register and provide leadership with a clear view of the company's risk posture.
Partner with teams to drive remediation of risks and map controls to compliance frameworks like NIST 800-171.
Muon Space is an end-to-end Space Systems Provider that designs, builds, and operates LEO satellite constellations delivering mission-critical data. Founded in 2021, the company operates a state-of-the-art facility in Silicon Valley and is committed to fostering a diverse and dynamic workforce.
Lead and oversee cybersecurity assessment and authorization activities for a major federal program.
Serve as the primary interface with government leadership and stakeholders.
Manage task order execution, staffing, schedules, and contractual performance.
This company supports federal cybersecurity programs and manages contracts for government clients. It offers a remote work environment and emphasizes employee empowerment and accountability.
Serve as the assigned security officer (vCISO) for a portfolio of client engagements, leading recurring meetings and providing strategic security guidance.
Lead CMMC Level 1 and 2 readiness engagements, including NIST SP 800-171 assessments, SSP development, and POA&M management.
Deliver compliance engagements across frameworks such as HIPAA, SOC 2, PCI DSS, ISO 27001, and more, while conducting risk assessments and coordinating remediation.
Intelligent Technical Solutions is a managed IT and cybersecurity services provider delivering compliance and security practice management to client organizations. The company employs a team of security professionals and fosters a culture of continuous improvement and knowledge sharing.
Provide technical expertise on security controls and system architecture for FedRAMP compliance.
Perform detailed architecture reviews of Cloud Service Providers (CSPs) and author package briefings.
Lead architecture interviews and reviews, ensuring alignment with NIST, FISMA, and FedRAMP standards.
Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies, it has been recognized as a Best Place to Work in the D.C. area for 12 consecutive years, fostering a culture of trust, growth, and work-life balance.
Lead compliance assessments and build-out of IL4/IL5 authorizations for DoD Cloud Computing Security Requirements Guide.
Maintain and evolve compliance posture for FedRAMP High, NIST SP 800-53, and other federal frameworks.
Serve as GRC liaison to engineering teams, translating complex federal compliance requirements into technical specifications for AWS environments.
Horizon3 is a fast-growing, remote cybersecurity company that provides autonomous pentesting through its NodeZero platform. The company is a fusion of former Special Operations cyber operators and engineers, fostering a culture of respect, collaboration, ownership, and results.
Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.
Ensure day-to-day compliance activities across PCI DSS, SOC 2, NIST, GDPR, and ISO frameworks.
Lead preparation and execution of internal and external audits, including evidence collection and remediation tracking.
Perform technical security and compliance reviews of third-party vendors and service providers.
iSeatz drives enduring brand loyalty through digital commerce and technology solutions for travel and lifestyle bookings. The company processes over $9B per year in transactions and has been honored as an Inc. Magazine Best Workplace for three consecutive years, emphasizing transparency, trust, and open communication.
Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, and remediation.
Drive recurring continuous monitoring and evidence workflows across multiple teams.
Support vulnerability detection and response, including reconciling findings from tools like Wiz, Nessus, and Burp.
Abnormal protects the humans behind the world's most critical organizations from AI-powered cybercrime. 4,500+ enterprises trust their behavioral AI platform.
Lead cybersecurity governance, assessment, and audit activities supporting a federal customer.
Coordinate evidence, control assessments, and remediation across NIST, RMF, and federal compliance requirements.
Maintain quality control, configuration traceability, and readiness for IV&V, QA, and government surveillance.
SkyePoint Decisions is a cybersecurity architecture, engineering, and IT services provider supporting federal government clients. Headquartered in Dulles, Virginia, it is an ISO-certified small business with a collaborative culture focused on mission assurance.
Lead enterprise and division risk assessments to identify strategic, operational, compliance, technology, and cybersecurity risks.
Maintain the enterprise risk register, develop KRIs/KPIs, and produce executive-level risk reports and dashboards.
Evaluate policies and controls to address weaknesses, drive corrective actions, and improve ERM processes.
SkyePoint Decisions is a cybersecurity architecture and engineering IT service provider headquartered in Dulles, Virginia, serving federal government clients. It is a certified small business with a collaborative culture focused on innovation and mission success.
Participate in assessing client environments against frameworks like NIST CSF 2.0, CIS Controls, and ISO 27001.
Design and implement secure solutions across cybersecurity, networking, and cloud technologies.
Perform configuration, installation, and maintenance of security products and services.
Apollo Information Systems is a cybersecurity services company delivering unified security and compliance programs through a subscription-based platform. Backed by Series A funding, the company is growing rapidly with a collaborative, mission-driven culture and a remote-first team with a hub in Denver.
Support information assurance and cybersecurity activities for the Army Contract Writing System (ACWS).
Assist with implementation and maintenance of security controls per NIST, RMF, STIG, and DoD requirements.
Develop and maintain security documentation including SSPs, POA&Ms, and continuous monitoring artifacts.
LMI is a digital solutions provider dedicated to accelerating government impact with innovation and speed. Headquartered in Tysons, Virginia, the company delivers mission-ready technology and solutions to federal agencies.
Support governance, risk, privacy, and compliance programs to ensure alignment with regulatory requirements.
Conduct risk assessments for vendors and new technologies, and maintain compliance with GDPR and other regulations.
Manage data governance, privacy evaluations, and cybersecurity awareness training.
RMI is an independent nonprofit transforming global energy systems for a zero-carbon future. Founded in 1982, the organization has a global team and a remote-ready culture.
Develop and implement cybersecurity strategies and architectures aligned with organizational objectives and regulatory requirements.
Lead RMF activities for large distributed systems to obtain and maintain Authority to Operate.
Collaborate with government stakeholders and cross-functional teams to integrate security across systems and networks.
The company specializes in cybersecurity architecture and Zero Trust solutions for U.S. Department of Defense clients. It offers a fully remote work environment with a focus on work-life balance and professional development opportunities.
Own the overall security posture, including policy, standards, and risk framework.
Manage ISO 27001, SOC 2, FedRAMP, and CMMC compliance programs.
Lead incident response, vulnerability management, and customer security assurance.
RapidFort is a cybersecurity company that helps organizations secure and optimize their software supply chain and containerized environments. As a fast-growing startup, we foster a culture of ownership and direct communication, where every team member contributes to our mission of securing cloud-native applications for regulated industries.
Perform cybersecurity and technology risk assessments across systems, vendors, and business processes.
Support compliance with SOC 2, HIPAA, HITRUST, and PCI DSS frameworks.
Manage third-party risk assessments and track remediation of security findings.
Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. They partner with companies to manage applications and hiring processes, offering remote roles and streamlined recruitment.
Provide overall program and contract management leadership for cybersecurity architecture and engineering activities.
Serve as primary interface with government stakeholders and translate requirements into actionable work plans.
Manage program schedules, risks, deliverables, and ensure alignment with Federal security standards.
9th Way Insignia is a service-disabled, veteran-owned small business bringing transformative technology to government customers. We specialize in cybersecurity, cloud modernization, and artificial intelligence.
Assist with IT automation processes and documentation of security practices.
Contribute to Virtual Desktop Infrastructure (VDI) implementation and secure remote access.
Conduct security audits, vulnerability analysis, and support compliance reporting.
FWI is a company that provides cybersecurity and IT services, supporting federal clients. It has been recognized as a Top Workplace by the Washington Post in 2024 and 2025, offering excellent growth opportunities in a collaborative environment.