Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.
Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.
Evaluate security controls and assess alignment with ISO 27001, SOC 2, NIST, and other frameworks.
Coordinate with internal teams and external auditors to support audit engagements and maintain control evidence.
Apply risk-based monitoring and contribute to compliance oversight, security operations, and secure-by-design initiatives.
The company is a mission-driven cybersecurity partner focused on strengthening information security, privacy, and organizational resilience. While specific size details are not provided, the team fosters a collaborative, high-impact environment with opportunities for continuous learning and career development.
Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
Represent the compliance program in customer-facing discussions and security due diligence reviews.
Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.
Own the IT evidence program across ISO 27001, SOC 1, SOC 2, PCI DSS, and HIPAA for approximately 13 operating sites, managing audits and remediation.
Manage vulnerability management end to end, oversee endpoint detection and response, and lead security incident response through to conclusion.
Contribute to identity governance across a hybrid cloud and on-premises IdP, overseeing access review and privileged access controls.
Serverfarm is a leading developer and operator of data centers with over 750 locations and key customer relationships in 45 countries. With Manulife Investment Management's acquisition in 2023, the company is positioned for explosive growth and offers a culture of innovation and career development.
Ensure day-to-day compliance activities across PCI DSS, SOC 2, NIST, GDPR, and ISO frameworks.
Lead preparation and execution of internal and external audits, including evidence collection and remediation tracking.
Perform technical security and compliance reviews of third-party vendors and service providers.
iSeatz drives enduring brand loyalty through digital commerce and technology solutions for travel and lifestyle bookings. The company processes over $9B per year in transactions and has been honored as an Inc. Magazine Best Workplace for three consecutive years, emphasizing transparency, trust, and open communication.
Lead the design, implementation, and maintenance of Hyland's enterprise ISO governance and certification program across multiple certifications, business units, and regions.
Drive strategic expansion of ISO scope, including advanced certifications like TISAX and C5, and establish governance models and control ownership across teams.
Measure and report ISO program health through metrics, dashboards, and reporting, while providing leadership and mentorship to compliance specialists.
Hyland is the pioneer of the Content Innovation Cloud, delivering enterprise intelligence through solutions that unlock actionable insights and drive automation. Trusted by thousands of organizations worldwide, including many Fortune 100 companies, Hyland has nearly 4,000 employees and fosters an employee-centric, inclusive culture.
Serve as Compliance Officer and HIPAA Security Officer, leading compliance and information security programs.
Own HIPAA/HITECH compliance, SOC 2 Type II certifications, and policy framework governance.
Partner with Engineering, DevOps, Legal, and other functions to embed security and compliance into operations.
Prompt delivers highly automated modern software to rehab therapy businesses, revolutionizing healthcare technology. As one of the fastest-growing healthcare SaaS companies, it fosters an innovative, remote-friendly culture with a talented team.
Own the audit journey for a portfolio of global customers from gap assessment through external audit closure.
Identify security and compliance gaps, turning them into practical remediation plans with engineering and leadership teams.
Serve as the coordination point between customers and independent auditors, facilitating evidence requests and communication.
Sprinto is an autonomous trust platform that centralizes compliance and security requirements across frameworks, vendors, and customers. Backed by Accel and Elevation, with $31.8M in funding, Sprinto serves over 4,000 organizations and fosters a remote-first culture of ownership and impact.
Build and maintain technical controls across security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, and other enterprise requirements.
Automate compliance workflows, evidence collection, access reviews, and security checks.
Partner with Engineering and Security to implement controls around access management, infrastructure, data protection, logging, and vulnerability management.
Retell AI is reimagining the call center with cutting-edge voice AI. Backed by Y Combinator, the company has scaled to $60M ARR with a team of 40 people, and is looking for ambitious builders to tackle hard technical problems.
Serve as the assigned security officer (vCISO) for a portfolio of client engagements, leading recurring meetings and providing strategic security guidance.
Lead CMMC Level 1 and 2 readiness engagements, including NIST SP 800-171 assessments, SSP development, and POA&M management.
Deliver compliance engagements across frameworks such as HIPAA, SOC 2, PCI DSS, ISO 27001, and more, while conducting risk assessments and coordinating remediation.
Intelligent Technical Solutions is a managed IT and cybersecurity services provider delivering compliance and security practice management to client organizations. The company employs a team of security professionals and fosters a culture of continuous improvement and knowledge sharing.
Serve as acting CISO for multiple client organizations and SGP, providing strategic security leadership and executive guidance.
Lead cybersecurity and compliance programs aligned with NIST SP 800-171, CMMC Levels 1-2, and ISO/IEC 27001.
Conduct security assessments, gap analyses, and risk reviews; develop SSPs, POA&Ms, and policies.
Strategic Growth Partners provides cybersecurity and compliance services to clients across multiple time zones. They foster a collaborative, innovative, and diverse work environment.
Review system documentation and technical evidence against NIST, FISMA, RMF, FedRAMP, and Zero Trust requirements.
Perform control-gap analyses, maturity assessments, and compliance reviews; identify risks and recommend corrective actions.
Support authorization activities by preparing security plans, control implementation statements, and remediation documentation.
9th Way Insignia is a service-disabled, veteran-owned small business providing transformative technology solutions including cybersecurity, cloud modernization, software development, and data analytics to government customers. As a small business, it empowers its people to fearlessly drive change and offers a comprehensive benefits package.
Lead and maintain ATO documentation and coordinate with security, engineering, and project teams to ensure compliance.
Monitor security events, investigate threats, and assess vulnerabilities across cloud and enterprise environments.
Develop and implement security policies, conduct risk analysis, and provide cybersecurity guidance to stakeholders.
The company is a partner organization focused on cybersecurity and federal technology modernization. It offers a fully remote, mission-driven culture with opportunities for growth in a technology-focused environment.
Lead compliance assessments and build-out of IL4/IL5 authorizations for DoD Cloud Computing Security Requirements Guide.
Maintain and evolve compliance posture for FedRAMP High, NIST SP 800-53, and other federal frameworks.
Serve as GRC liaison to engineering teams, translating complex federal compliance requirements into technical specifications for AWS environments.
Horizon3 is a fast-growing, remote cybersecurity company that provides autonomous pentesting through its NodeZero platform. The company is a fusion of former Special Operations cyber operators and engineers, fostering a culture of respect, collaboration, ownership, and results.
Lead IT governance and risk management, including executive reporting and risk register maintenance.
Develop KPI and KRI dashboards to translate complex data into actionable insights for senior leadership.
Oversee ITSM governance, ServiceNow optimization, and vendor risk management.
Our partner is a global organization operating in a sophisticated Governance, Risk & Compliance environment, connecting technology, cybersecurity, privacy, and operational risk. It fosters a collaborative culture with a focus on work-life balance and professional development.
Take ownership of information security governance, including policies, risk registers, and control documentation.
Manage day-to-day security program operations, mentor analysts, and coordinate cross-functional initiatives.
Lead incident response, compliance support, and serve as primary counterpart to the vCISO.
Aries is a financial technology company building modern infrastructure and products for active investors and traders. As a growing organization, they are investing in a practical, accountable security program deeply integrated into how the company operates.
Own and manage federal compliance frameworks including FedRAMP, NIST, CMMC, DFARS, and StateRAMP.
Translate regulatory controls into automated tests and machine-readable specifications for continuous authorization.
Collaborate with Engineering, Product, and Design to shape product capabilities and influence strategy.
Our partner company is a technology organization focused on federal compliance automation, serving organizations from emerging companies to large enterprises. They operate with a remote-first culture and value autonomy, accuracy, and scalability.
Support day-to-day information security operations and maintain strong operational security posture across the platform.
Develop and maintain the System Security Plan and other cybersecurity documentation for security authorization and compliance.
Support FedRAMP High and DoD IL5 compliance activities including continuous monitoring, audits, assessments, and remediation.
The partner company operates a secure, mission-focused technology platform supporting government and commercial teams. It is an equal opportunity workplace committed to considering qualified candidates from all backgrounds.
Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.
Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.