Own the overall security posture, including policy, standards, and risk framework.
Manage ISO 27001, SOC 2, FedRAMP, and CMMC compliance programs.
Lead incident response, vulnerability management, and customer security assurance.
RapidFort is a cybersecurity company that helps organizations secure and optimize their software supply chain and containerized environments. As a fast-growing startup, we foster a culture of ownership and direct communication, where every team member contributes to our mission of securing cloud-native applications for regulated industries.
Own and mature internal and Managed GRC programs, including federal SSPs, POA&Ms, audits, and risk assessments.
Collaborate with CISOs, engineers, and control owners to translate compliance requirements into practical technical controls.
Lead and develop a GRC team while introducing automation and AI to improve scalability and consistency.
The company provides managed Governance, Risk & Compliance (GRC) and security assurance services, with a strong focus on federal security programs and frameworks like NIST, SOC 2, and CMMC. It supports a growing GRC team and emphasizes low-ego collaboration, automation, and AI-enabled approaches to scale delivery.
Lead enterprise and division risk assessments to identify strategic, operational, compliance, technology, and cybersecurity risks.
Maintain the enterprise risk register, develop KRIs/KPIs, and produce executive-level risk reports and dashboards.
Evaluate policies and controls to address weaknesses, drive corrective actions, and improve ERM processes.
SkyePoint Decisions is a cybersecurity architecture and engineering IT service provider headquartered in Dulles, Virginia, serving federal government clients. It is a certified small business with a collaborative culture focused on innovation and mission success.
Lead and mature cybersecurity compliance programs including SOC 2 Type 2 and ISO 27001 readiness.
Drive cloud and application security across AWS and Azure, integrating secure SDLC and DevSecOps practices.
Manage corporate IT operations, identity and access, and build the cybersecurity team as the organization grows.
Genea is a leader in property technology, providing cloud-based physical security, submeter billing, and on-demand HVAC solutions to over 1 million users across 39 countries. It has been recognized as a Top Workplace from 2021-2025 with a 4.3 Glassdoor rating, fostering a team-oriented and transparent culture.
Lead and mature the information security program, building on ISO 27001 and SOC 2 foundations.
Develop and operationalize security policies, risk management, and incident response.
Partner with Engineering and Product to integrate security into software development.
This is a partner company role managed by Jobgether, a platform that uses AI-powered matching to connect candidates with hiring companies. The partner is a rapidly scaling SaaS and cloud technology environment, with a growing security team and established ISO 27001 and SOC 2 programs.
Conduct cybersecurity risk assessments and compliance reviews to identify gaps and remediation needs.
Support internal and external audits against Federal requirements and organizational policies.
Develop and maintain cybersecurity policies, procedures, and compliance documentation.
PingWind is a Service-Disabled Veteran-Owned Small Business that delivers cybersecurity, IT infrastructure, supply chain management, and professional services to the federal government. As a small business with offices in Northern Virginia and Huntsville, AL, PingWind fosters a dynamic team environment focused on supporting large government clients.
Own global certification programs like ISO 27001 and SOC 2, and advise engineering teams on secure development.
Collaborate directly with engineers to audit cloud infrastructure, CI/CD pipelines, and AI-driven security controls.
Assess risks of emerging technologies and drive continuous compliance improvements across the organization.
Picus Security is an exposure validation company that proves what attackers can exploit and what defenses stop, turning exposures into defensible decisions. As a fast-growing global remote team, it values continuous security validation and has a 95% recommendation rate.
Lead security risk assessments across engineering, IT, operations, and business functions.
Maintain a risk register and provide leadership with a clear view of the company's risk posture.
Partner with teams to drive remediation of risks and map controls to compliance frameworks like NIST 800-171.
Muon Space is an end-to-end Space Systems Provider that designs, builds, and operates LEO satellite constellations delivering mission-critical data. Founded in 2021, the company operates a state-of-the-art facility in Silicon Valley and is committed to fostering a diverse and dynamic workforce.
Serve as the assigned security officer (vCISO) for a portfolio of client engagements, leading recurring meetings and providing strategic security guidance.
Lead CMMC Level 1 and 2 readiness engagements, including NIST SP 800-171 assessments, SSP development, and POA&M management.
Deliver compliance engagements across frameworks such as HIPAA, SOC 2, PCI DSS, ISO 27001, and more, while conducting risk assessments and coordinating remediation.
Intelligent Technical Solutions is a managed IT and cybersecurity services provider delivering compliance and security practice management to client organizations. The company employs a team of security professionals and fosters a culture of continuous improvement and knowledge sharing.
Lead ISO 27001 and SOC 2 audit cycles end-to-end, owning compliance and audit.
Own customer trust by responding to security questionnaires and representing InfoSec to enterprise clients.
Drive risk management, vendor security, and incident response while building AI-assisted workflows.
We are the first AI-native Employee Experience Platform, helping organizations unlock inspirational communication. Our diverse team of 550+ employees supports over 1,500 customers, and we are a unicorn company valued at over $1 billion.
Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.
Lead end-to-end service delivery for cybersecurity professional services, ensuring quality, timelines, and compliance for a portfolio of customers.
Drive operational strategy, governance frameworks, and KPIs for predictable delivery across FedRAMP advisory, implementation, and continuous monitoring programs.
Mentor and grow high-performing technical teams including project managers, cloud architects, security engineers, and analysts.
Quantum Sky engineers cybersecurity and cloud solutions for U.S. Federal agencies, focusing on FedRAMP, RMF, and post-quantum mission needs. The company fosters a collaborative, innovative, mission-driven culture with a high-performing team of technical professionals.
Plan, implement, and upgrade security controls and architecture to safeguard systems and sensitive information.
Conduct risk assessments, penetration testing, and vulnerability assessments, then track mitigation plans.
Support compliance with NIST 800-171, develop governance documentation, and deliver security awareness training.
Insitu, a Boeing Company, provides unmanned air systems and software solutions for collecting, processing, and understanding sensor data to support critical decision-making. With over 1 million operational flight hours, the company values integrity, collaboration, and adaptability in a fast-paced, mission-driven environment.
Lead the design and execution of cybersecurity architecture and engineering to ensure compliance with internal and external policies.
Partner with business leaders to identify risks, develop solutions, and embed security into enterprise strategy.
Oversee deployment, integration, and optimization of security tools while driving cloud-native security improvements.
U.S. Financial Technology builds and operates the world's largest mortgage securitization platform, supporting the Uniform Mortgage-Backed Security of Fannie Mae and Freddie Mac. It handles 70% of mortgage-backed securities and fosters a collaborative, remote-first culture.
Review system documentation and technical evidence against NIST, FISMA, RMF, FedRAMP, and Zero Trust requirements.
Perform control-gap analyses, maturity assessments, and compliance reviews; identify risks and recommend corrective actions.
Support authorization activities by preparing security plans, control implementation statements, and remediation documentation.
9th Way Insignia is a service-disabled, veteran-owned small business providing transformative technology solutions including cybersecurity, cloud modernization, software development, and data analytics to government customers. As a small business, it empowers its people to fearlessly drive change and offers a comprehensive benefits package.
Lead Atmosera's internal GRC program and managed GRC service delivery.
Manage federal System Security Plans, POA&Ms, and audit responses.
Serve as a senior GRC advisor bridging executive and technical teams.
Atmosera empowers businesses to redefine what's possible with modern technology and human expertise across Applications, Data & AI, DevOps, Security, and Microsoft Azure. As a Microsoft Partner with seven specializations, the company values humility, hunger, and mindfulness in a collaborative team environment.
Own and scale the GSI partnership strategy for ServiceNow Cyber and Risk across North America.
Lead and mentor a team of GSI Partner Managers to drive joint pipeline generation and revenue impact.
Build deep relationships with GSI practice leaders and execute Joint Go-to-Market motions with major partners.
ServiceNow is an AI control tower for business reinvention, bringing together AI, data, and workflows to help organizations work smarter. The company serves 85% of the Fortune 500 and is building an AI-native culture where technology and talent are unstoppable together.
Lead cybersecurity governance, assessment, and audit activities supporting a federal customer.
Coordinate evidence, control assessments, and remediation across NIST, RMF, and federal compliance requirements.
Maintain quality control, configuration traceability, and readiness for IV&V, QA, and government surveillance.
SkyePoint Decisions is a cybersecurity architecture, engineering, and IT services provider supporting federal government clients. Headquartered in Dulles, Virginia, it is an ISO-certified small business with a collaborative culture focused on mission assurance.
Lead adoption and implementation for platinum-level customers, ensuring value realization.
Build trusted relationships with technical stakeholders and act as customer advocate.
Stay current on integrations and serve as a subject matter expert.
ServiceNow is an AI platform that automates workflows for 85% of the Fortune 500. They have a collaborative, AI-driven culture focused on innovation and customer success.