Own FedRAMP and GovRAMP certifications and roadmaps, including package management and compliance timelines.
Manage 3PAO relationships and assessments, coordinating scoping, evidence, and results validation.
Lead continuous monitoring, POA&M processes, and drive compliance automation and efficiency.
Smartsheet empowers teams to manage work seamlessly and scale solutions smarter, now uniting human teams with AI agents. It is an equal opportunity employer committed to fostering an inclusive environment with the best employees.
Lead FedRAMP Moderate and CMMC readiness assessments, including system boundary validation and control gap analysis.
Design and implement cloud security architectures aligned to NIST 800-53 and NIST 800-171 requirements.
Develop and own System Security Plans (SSPs), control narratives, and compliance documentation.
Riveron helps organizations implement leading governance, risk and compliance practices with a hands-on approach. The company fosters an entrepreneurial culture with collaboration and diverse perspectives, offering flexible work and progressive benefits.
Own RMF authorizations across Department of War components and FedRAMP High, alongside CMMC 2.0 and SOC 2 compliance for corporate systems.
Maintain authorization and audit evidence, including SSPs, SARs, POA&Ms, STIGs, and control mappings.
Partner with Engineering, Product, and Security to embed compliance requirements into system design and CI/CD workflows.
Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination. Founded in 2019, valued at over $2 billion, they are a distributed team of builders from military, operational, and technology backgrounds.
Lead the end-to-end authorization process for FedRAMP High, while driving alignment with CMMC and MARS-E.
Manage ongoing FedRAMP continuous monitoring, including monthly deliverables and vulnerability management.
Collaborate with engineering, security, and operations teams to develop a 'comply once, satisfy many' strategy.
Amwell provides a technology-enabled care platform for healthcare organizations, offering services across the care continuum. With a team passionate about transforming care delivery, they have served large healthcare organizations for nearly two decades.
Lead delivery of FedRAMP, CMMC, HITRUST, and NIST compliance engagements where federal authorization is on the line.
Build reusable IP like control-mapping libraries, SSP templates, and evidence-collection playbooks for complex frameworks.
Own pricing, margin, and utilization for specialized federal engagements, plus leverage AI to standardize deliverables.
Sprinto is an Autonomous Trust Platform that centralizes trust requirements across security frameworks, vendors, and customers. Backed by top-tier investors like Accel, Elevation, and Blume Ventures, we've raised $31.8M and are trusted by over 3,000 organizations across 75 countries, with a remote culture built on ownership and progress over perfection.
Own Filevine's FedRAMP 20x strategy and execution, including evidence automation, continuous monitoring, and certification readiness.
Drive the security compliance and trust program across FedRAMP, SOC 2, ISO, HIPAA, and PCI-DSS, converting obligations into engineering work.
Lead cross-functional alignment and executive reporting to ensure compliance, privacy, and security priorities are shipped on time.
Filevine is a Legal AI company delivering Legal Operating Intelligence for the future of legal work. Fueled by a team of exceptional collaborators and innovators, Filevine’s rapid growth has earned AI awards and recognition from Deloitte and Inc. as one of the most innovative and fastest-growing technology companies in the country.
Manage and implement complex controls frameworks for large systems consisting of Cloud infrastructure and SaaS services.
Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
Conduct risk assessments across business units and processes, identifying risk findings and recommending remediation strategies.
Virtru is a data protection platform that enables secure sharing without sacrificing security or privacy. Backed by top venture capital firms, the company helps Fortune 500 companies and government agencies achieve true data security with freedom to share.
Manage the Compliance and Security workstream within a telecom transformation program, coordinating SOC 2, ISO/IEC 27001, and GDPR readiness activities.
Build and maintain the workstream plan with milestones, deliverables, and RAID logs, while driving evidence collection and control-owner alignment.
Facilitate workshops, track remediation across multiple domains, and ensure alignment with adjacent program streams and governance forums.
Miratech helps visionaries change the world as a global IT services and consulting company supporting digital transformation for large enterprises. With nearly 1000 professionals operating across 25+ countries and a 99% project success rate, their culture emphasizes relentless performance and growth.
Identify products or programs through the FedRAMP (Joint Authorization Board or Agency) authorization process.
Collaborate with the Program Manager Public Sector Compliance to define strategic roadmaps and support full product lifecycle.
Provide product architectural guidance for Vultr's public sector cloud product roadmap.
Vultr makes high-performance cloud infrastructure easy to use, affordable, and locally accessible for enterprises and AI innovators worldwide. We are the world's largest privately-held cloud infrastructure company, trusted by hundreds of thousands of active customers across 185 countries.
Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, and third-party risk.
Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, and more.
Manage third-party and supply chain risk management, including vendor security reviews, due diligence, and remediation tracking.
Accela provides government software solutions to improve efficiency, increase citizen engagement, and enable thriving communities. They have been an industry leader for nearly 20 years and are committed to diversity, equity, and inclusion.
Serve as a primary compliance resource embedded in the Alma-to-Spring Health integration, mapping control environments and building a unified compliance organization.
Own and lead enterprise-level compliance programs including SOC 2 Type II, HITRUST, HIPAA, GDPR, ISO 27001, ISO 42001, and ITGC-SOX.
Develop and operationalize Spring Health's AI governance program, including policies, risk frameworks, and AI-specific compliance documentation.
Spring Health is a global mental health company on a mission to eliminate every barrier to mental health. With outcomes independently validated by JAMA Network Open, Spring Health reaches more than 170 million people worldwide through leading employers, health plans, and partners.
Own and manage the compliance program including SOC 2 and ISO 27001 readiness and audits.
Lead risk assessments, control testing, and enterprise risk management processes.
Partner with Engineering, Security, Product, Legal, HR, and Operations to embed compliance into business processes.
Calendly is a scheduling platform used by millions to automate meetings and streamline time management. They are a rapidly growing SaaS company fostering a culture of learning and high performance.
Lead end-to-end service delivery operations for cybersecurity and cloud security professional services engagements.
Own the delivery lifecycle for FedRAMP advisory, implementation, continuous monitoring, and related security programs.
Develop operational strategies and governance models ensuring compliance with NIST 800-53, FedRAMP, and DoD frameworks.
This company specializes in cybersecurity and cloud service delivery for federal agencies, managing mission-critical environments with strict compliance requirements. They are a mid-sized organization focused on scalable operations and measurable outcomes.
Manage and support compliance certifications including SOC 2, HITRUST, and ISO 27001 audits across the audit lifecycle.
Serve as the subject matter expert across the company on compliance frameworks and primary point of contact for external auditors.
Maintain the risk register, drive risk identification and reporting, and scale GRC function with AI and automation.
Garner transforms the healthcare economy by partnering with employers to redesign healthcare benefits using data-driven insights. It is a fast-growing healthcare technology company with a mission-driven team focused on making healthcare more affordable and high-quality.
Serve as a trusted compliance advisor for DoD contractors, guiding them through NIST SP 800-171, CMMC 2.0, and DFARS requirements from gap analysis to audit readiness.
Conduct recurring strategy meetings, review implementation progress, translate complex regulations into practical recommendations, and collaborate with client leadership.
Prepare professional assessment reports, maintain compliance documentation, deliver training, and support clients through ongoing compliance management and SPRS submissions.
On Call Computer Solutions is a nationwide leader in cybersecurity, compliance, and managed IT services for Department of Defense contractors. Since 2003, they have helped organizations meet DFARS, NIST SP 800-171, and CMMC requirements with an award-winning team.
Maintain and improve the Quality Management System (QMS) and support compliance with CMMI, CMMC, and ISO standards.
Support government contract compliance, coordinate audits, and manage documentation for contracts and IDIQ vehicles.
Develop dashboards and reports for compliance, audits, and PMO maturity metrics.
True Zero Technologies is a veteran-owned small business that focuses on enabling people and technology to drive quality outcomes. The company has been recognized as a Best Places to Work honoree and has appeared on the Inc. 5000 list of fastest-growing companies, reflecting its people-first culture and commitment to excellence.
Develop and maintain the enterprise IT GRC strategy, framework, and roadmap, presenting updates to executive leadership.
Lead enterprise IT risk assessments, maintain risk registers, and oversee remediation efforts.
Ensure compliance with regulations like NIST, ISO 27001, SOC, PCI-DSS, HIPAA, GDPR, and SOX.
Mission Critical Group is an end-to-end power solutions and services provider that accelerates time-to-power for mission critical environments. With over 1.5 million square feet of U.S. manufacturing capacity, the company supports data centers, healthcare, and industrial facilities where uptime is non-negotiable.
Defines program goals, governance frameworks, and measurable objectives for cyber risk and compliance programs.
Manages user attestations, third-party risk, cyber contract negotiation, and coordination of IT audits/assessments.
Implements GRC tooling and monitors program effectiveness through KPIs, QA reviews, and control testing.
Velera is a credit union service organization providing fintech solutions to over 4,000 financial institutions. The company fosters a remote-first, inclusive culture with a focus on employee wellbeing and belonging.
Lead the MyFitnessPal Federal business unit, establishing governance and internal controls for a federal-facing entity.
Own the P&L, operating budget, and KPIs, partnering with corporate functions to maintain alignment.
Manage federal security and compliance frameworks, ensuring proper handling of sensitive data and audit readiness.
MyFitnessPal provides tools and resources to help users reach their health goals. The company's culture emphasizes kindness, data-driven decisions, and continuous improvement.
Manage and conduct internal and external compliance audits for frameworks like ISO, SOC, and NIST.
Work with global teams to implement and update compliance controls, policies, and training.
Stay updated on regulatory changes and perform gap analysis to maintain certifications.
QAD is building a world-class SaaS company that solves real-world problems in manufacturing and supply chain. They are a growing, virtual-first company with a collaborative culture that values idea-sharing and growth.