Lead GRC activities including risk management framework, security assessments, and continuous monitoring for assigned systems.
Collaborate with engineering and security teams to integrate GRC principles into system lifecycles and DevSecOps practices.
Develop and maintain security documentation, support ATO processes, and provide risk briefings to leadership.
The partner company helps organizations strengthen cybersecurity programs through modern GRC practices and engineering expertise. It is a fully remote organization with a collaborative culture focused on technical excellence and professional growth.
Provide advanced cybersecurity expertise to support secure system operations and compliance initiatives.
Analyze system designs and architectures to ensure appropriate security controls and protection mechanisms.
Collaborate with technical teams and security organizations to align priorities and security objectives.
The partner company is a mission-driven organization that strengthens cybersecurity capabilities for critical information systems. It offers a collaborative culture with opportunities for professional growth and impactful work.
Partner with application development teams to integrate security requirements into design, development, and deployment workflows.
Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation.
Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards.
Oddball builds quality software for the federal space, focusing on improving the daily lives of millions of people. They are a small company that values learning, growth, and making a big impact.
Lead RMF activities including control selection, POA&M management, and ATO support for the depot.
Design supply chain security controls such as SBOM generation, artifact signing, and vulnerability scanning.
Integrate security tooling into CI/CD pipelines and interface with government assessors and authorizing officials.
OpenTeams builds AI that empowers, focusing on energy-efficient, cost-effective models that give users full ownership of their data. As a small company, they value freedom, teamwork, accountability, and reinvest 3% of profits into the open-source community.
Act as a trusted consultant guiding clients through complex security and compliance challenges.
Develop security strategies aligned with frameworks like CMMC, NIST 800-171, and NIST 800-53.
Design and implement AWS and/or GCP security tools with deep expertise in cloud security.
Aprio is a Top 20 CPA and advisory firm that provides compliance and advisory services to fast-growing industries. With over 3,200 team members across 40 US and international offices, they foster a top-rated culture and collaborative environment.
Lead quality assurance for RMF authorization packages to ensure completeness and readiness for government review.
Coordinate with RMF analysts, ISSOs, system owners, and technical stakeholders to validate security documentation and evidence.
Mentor team members on documentation standards and best practices while tracking assessment readiness metrics to reduce rework.
True Zero Technologies is a veteran-owned small business that enables people and technology to drive quality outcomes. The company has been named a Best Place to Work multiple times and made the Inc. 5000 list of fastest-growing companies, reflecting its people-first culture and commitment to excellence.
Provide expert guidance on cybersecurity policies, Risk Management Framework (RMF) processes, and security control implementation.
Conduct vulnerability assessments, penetration testing, and Cybersecurity Compliance and Readiness Inspections (CCRI).
Prepare detailed technical reports and briefings for senior leadership on cybersecurity findings and progress.
The company is a partner organization focused on cybersecurity and mission-critical IT environments. They offer a remote work culture and support complex security initiatives for government and enterprise clients.
You will serve as a trusted security advisor, developing and implementing cybersecurity strategies aligned with business objectives.
You will design and implement advanced security controls, including SIEM, DLP, IDS/IPS, and identity management solutions.
You will lead secure architecture and integration projects across Microsoft cloud, AWS, GCP, and other platforms.
A partner company provides cybersecurity consulting services, helping organizations strengthen their security posture across cloud and enterprise technologies. They operate in a collaborative remote environment and seek independent, disciplined professionals.
Architect and automate security workflows across CI/CD and compliance operations.
Integrate and monitor security tooling within automated pipelines.
Build automation for compliance and ATO artifacts.
Our partner is a technology company that builds secure, automated cloud environments for mission-critical programs. They offer a fully remote work model with a focus on autonomy and work-life balance.
Lead and maintain ATO documentation and coordinate with security, engineering, and project teams to ensure compliance.
Monitor security events, investigate threats, and assess vulnerabilities across cloud and enterprise environments.
Develop and implement security policies, conduct risk analysis, and provide cybersecurity guidance to stakeholders.
The company is a partner organization focused on cybersecurity and federal technology modernization. It offers a fully remote, mission-driven culture with opportunities for growth in a technology-focused environment.
Design, implement, and maintain enterprise security solutions to strengthen cybersecurity defenses and support Zero Trust maturity.
Operate and manage security technologies including EDR, SIEM, web application firewalls, and vulnerability scanners.
Integrate security requirements into DevSecOps processes, CI/CD pipelines, and infrastructure-as-code environments.
The partner company specializes in enterprise cybersecurity and strengthening security capabilities. They have a collaborative, security-focused team and offer fully remote work.
Coordinate cybersecurity awareness campaigns and training programs.
Maintain documentation for data classification, retention, and security controls.
Support compliance with frameworks like ISO and NIST.
Our partner is a mission-driven organization focused on strengthening information security and compliance. They foster a collaborative, remote-first culture with emphasis on professional growth and continuous learning.
Monitor and enforce compliance with security frameworks like NIST CSF, ISO 27001, SOC 2, and regulations such as GLBA, CCPA, and GDPR.
Conduct comprehensive risk assessments, develop security policies, and lead internal and external security audits with cross-functional teams.
Evaluate third-party vendor security posture, maintain compliance records, and define metrics to assess the success of the security program.
Clear Capital is a national real estate analytics, data solutions and valuation technology company with a simple purpose: to build confidence in real estate decisions to strengthen communities and improve lives. The company values integrity, kindness, and grit, and has been committed to excellence since 2001.
Own and manage federal compliance frameworks including FedRAMP, NIST, CMMC, DFARS, and StateRAMP.
Translate regulatory controls into automated tests and machine-readable specifications for continuous authorization.
Collaborate with Engineering, Product, and Design to shape product capabilities and influence strategy.
Our partner company is a technology organization focused on federal compliance automation, serving organizations from emerging companies to large enterprises. They operate with a remote-first culture and value autonomy, accuracy, and scalability.
Design and implement security solutions across multi-cloud environments (AWS, GCP, Azure).
Lead threat detection, identity management, and compliance posture for clients.
Embed security into CI/CD pipelines and develop AI-accelerated internal tooling.
Riveron is a consulting firm that helps organizations implement governance, risk, and compliance practices, including cybersecurity advisory. The firm has an entrepreneurial culture focused on collaboration, diversity, and delivering exceptional outcomes.
Own and manage the end-to-end RMF lifecycle, including system categorization, control selection, and continuous monitoring.
Assess current-state RMF processes and design standardized target-state workflows aligned with NIST and federal requirements.
Serve as the primary functional subject matter expert for the new RMF solution, leading requirements gathering, testing, and training.
True Zero Technologies is a veteran-owned small business that enables people and technology to deliver top-tier cybersecurity services to customers. The company has been recognized as a Best Places to Work honoree and has appeared on the Inc. 5000 list of fastest-growing companies in America.
Develop and implement effective cybersecurity strategies aligned with client objectives and industry best practices.
Design and implement advanced security controls and technologies, including SIEM, DLP, and endpoint protection.
Lead complex cybersecurity projects, manage client relationships, and contribute to thought leadership.
Avertium provides cybersecurity consulting and managed security services, focusing on Microsoft Cloud and other platforms. The company fosters a culture of remote teamwork, self-discipline, and innovation, leveraging industry best practices to deliver cost-effective solutions.
You will lead the development and management of client Governance, Risk, and Compliance programs.
You will assess cybersecurity compliance against frameworks like CMMC, NIST SP 800-171, and DFARS.
You will provide advisory services and manage client expectations to ensure successful engagements.
This company provides cybersecurity compliance consulting services to organizations in the U.S. Defense Industrial Base. They foster a collaborative, security-first culture with a focus on advocacy and resilience.
Design and implement security controls across AWS GovCloud environments.
Integrate security into CI/CD pipelines using Terraform and GitLab.
Ensure compliance with FedRAMP and DoD IL-4/5 standards.
Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. We are a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, ownership, and results.
Perform enterprise risk assessments using NIST CSF, SOC 2, and CIS frameworks.
Develop and execute security awareness programs including training and phishing simulations.
Support governance and control management by maintaining policies and control libraries.
Protective helps protect customers against life's uncertainties by providing insurance and peace of mind. The company offers a collaborative environment with a focus on employee wellbeing and work-life balance.