Maintain Risk Management Framework artifacts for DevSecOps pipeline inheritance of NIST SP 800-53 controls.
Complete and validate STIG/SRG checklists quarterly and provide monthly application STIG status reports.
Evaluate program risks, document mitigation strategies, and recommend courses of action to ensure continuous ATO compliance.
DecisionPoint is a company providing cloud services and DevSecOps solutions, supporting ARTRANS AWS environments. It is a regular full-time employer fostering a culture of security and compliance, with an active Secret clearance required for this role.
Lead ISSO activities to ensure confidentiality, integrity, availability, and compliance of enterprise applications and information systems.
Manage RMF processes including ATO packages, continuous monitoring, risk assessments, and accreditation documentation within eMASS.
Implement and maintain compliance with DISA STIGs, NIST 800-53 controls, and federal cybersecurity requirements.
Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. The company facilitates the hiring process by sharing top-fitting candidate shortlists with partner companies, focusing on efficiency and objectivity.
Lead RMF authorization activities, including SSP, SAP, SAR, and POA&M development.
Conduct vulnerability assessments and enforce secure configurations using CIS Benchmarks and DISA STIGs.
Support cloud security initiatives in AWS GovCloud and advise on AI-enabled system security.
This company provides cybersecurity solutions for federal government systems. They are a mid-sized organization with a collaborative culture focused on security and compliance.
Serves as a cybersecurity SME for Assessment and Authorization (A&A) of information systems, applying NIST 800-53 security controls and the Risk Management Framework (RMF) process.
Possesses five years of relevant RMF, NIST, and A&A experience, including assessing security controls for large, complex organizations like DLA.
Briefs senior management on authorization progress and understands cybersecurity in emerging technology areas such as Cloud and Industrial Control Systems.
Horizon Industries Limited is a dynamic IT and Management Consulting firm based in the Washington, DC area, providing full-cycle IT consulting and management support to both private and public sectors. Founded in 1996, the company prides itself on a diverse, employee- and family-centric culture with a focus on professional growth.
Execute formal SCA/R duties and lead security assessment efforts.
Establish reusable security playbooks and assessment frameworks for rapid AI deployment.
Evaluate technical control effectiveness across AWS cloud, DevSecOps pipelines, and AI/LLM stacks.
Dark Wolf Solutions specializes in cybersecurity engineering, cloud architecture, and DevSecOps prototyping for high-priority projects, including AI/LLM technologies. The company is an EEO/AA employer and focuses on fast-paced, collaborative environments.
Lead Risk Management Framework activities for a federal AI platform deployment in AWS GovCloud.
Own authorization artifacts and coordinate with ISSOs and Authorizing Officials for ATO.
Partner with platform engineers on cloud and container security, vulnerability management, and hardening.
LMI is a digital solutions provider dedicated to accelerating government impact with innovation and speed, bringing commercial-grade platforms and mission-ready AI to federal agencies. Headquartered in Tysons, Virginia, it serves the defense, space, healthcare, and energy sectors, with a culture more startup than traditional government contractor.
Lead FedRAMP Moderate and CMMC readiness assessments, including system boundary validation and control gap analysis.
Design and implement cloud security architectures aligned to NIST 800-53 and NIST 800-171 requirements.
Develop and own System Security Plans (SSPs), control narratives, and compliance documentation.
Riveron helps organizations implement leading governance, risk and compliance practices with a hands-on approach. The company fosters an entrepreneurial culture with collaboration and diverse perspectives, offering flexible work and progressive benefits.
Provide advanced cybersecurity expertise to support secure system operations and compliance initiatives.
Analyze system designs and architectures to ensure appropriate security controls and protection mechanisms.
Collaborate with technical teams and security organizations to align priorities and security objectives.
The partner company is a mission-driven organization that strengthens cybersecurity capabilities for critical information systems. It offers a collaborative culture with opportunities for professional growth and impactful work.
Consult onsite and remotely with customers to collect and analyze data related to policies, infrastructure, and compliance requirements.
Perform gap analyses of current environments and recommend remediation steps.
Assist with sales and marketing activities as a subject matter expert and prepare industry presentations.
CampusGuard provides information security and privacy consulting and compliance services for campus-based organizations. It is a full-service firm leveraging industry standards to deliver world-class security and compliance services.
Manage and maintain version control of all documentation related to compliance for each standard and track implementation status of security controls.
Oversee preparation and execution of external compliance audits, including facilitating security assessments.
Support mapping of compliance requirements to security control implementation using agile development processes.
Hypori is a high-growth cybersecurity SaaS company providing a virtual workspace platform for secure mobile access. Backed by $55M in funding, the company is expanding into commercial and regulated markets with a focus on innovation and security.
Manage and implement complex controls frameworks for large systems consisting of Cloud infrastructure and SaaS services.
Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
Conduct risk assessments across business units and processes, identifying risk findings and recommending remediation strategies.
Virtru is a data protection platform that enables secure sharing without sacrificing security or privacy. Backed by top venture capital firms, the company helps Fortune 500 companies and government agencies achieve true data security with freedom to share.
Design and implement enterprise security controls aligned with NIST SP 800-53 and Zero Trust Architecture principles.
Conduct continuous security monitoring, incident response, and vulnerability management across cloud, network, and endpoint environments.
Develop and maintain cybersecurity SOPs, security baselines, and asset inventories to support audit readiness.
DMI is a leading provider of digital services and technology solutions, headquartered in Tysons Corner, VA, supporting public sector agencies and commercial enterprises globally. Recognized as a Top Workplace, the company delivers secure, efficient, and cost-effective solutions through a culture guided by five core values.
Own RMF authorizations across Department of War components and FedRAMP High, alongside CMMC 2.0 and SOC 2 compliance for corporate systems.
Maintain authorization and audit evidence, including SSPs, SARs, POA&Ms, STIGs, and control mappings.
Partner with Engineering, Product, and Security to embed compliance requirements into system design and CI/CD workflows.
Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination. Founded in 2019, valued at over $2 billion, they are a distributed team of builders from military, operational, and technology backgrounds.
Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.
USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.
Develop and execute cybersecurity strategy, roadmap, and governance to protect Voyager's information systems and mission-critical environments.
Lead security operations, incident response, vulnerability management, and compliance with government regulations like CMMC and NIST.
Oversee security architecture, risk management, and team leadership to enable secure innovation in aerospace and defense.
Voyager is an innovative space, defense, and national security technology company delivering transformative, mission-critical solutions. It fosters a culture where innovation thrives, curiosity is rewarded, and impact is real, with a team of doers, thinkers, and builders united by purpose.