Assess and mitigate privacy risks across enterprise operations and third-party relationships, including PIAs and DPAs.
Support responsible AI governance by conducting AI risk assessments and monitoring emerging regulations.
Collaborate with Legal, Security, IT, and business stakeholders to ensure compliance with global privacy laws like HIPAA and GDPR.
Accuray develops, manufactures, and sells radiotherapy systems for alternative cancer treatments. With a global presence, they foster an inclusive and collaborative work environment focused on patient-first outcomes.
Manage governance forums, agendas, decision logs, and action tracking.
Support execution of strategic compliance priorities and monitor cross-functional dependencies.
Coordinate departmental KPIs and executive dashboarding.
HealthEdge is a healthcare technology company that provides software solutions for health plans and payers. The company fosters a culture of accountability, transparency, and compliance, operating remotely across the US.
Lead and advance governance, risk management, compliance, and information security programs to support organizational objectives and regulatory requirements.
Manage vulnerability management, third-party risk, security governance, policy development, and AI governance initiatives.
Partner with leaders to foster a culture of accountability, risk awareness, and continuous improvement.
Ultimate Medical Academy is a non-profit healthcare educational institution with a national presence, headquartered in Tampa, Florida and founded in 1994. The organization offers online and on-campus programs and fosters a culture of integrity, student success, and team member development.
Assist in monitoring compliance with frameworks like ISO 27001, SOC 2, and Cyber Essentials.
Maintain the central Risk Register and track remediation progress across departments.
Support policy management and compliance training across the organization.
We are a global Physical AI company using data and AI to improve critical industries like healthcare, water, energy, and telecom. Our teams are ambitious, curious, and practical, with colleagues across Africa, Europe, the UK, and the US.
Own GRC workstreams from initial request through evidence collection, testing, and remediation.
Test security controls and conduct risk assessments to identify gaps and drive realistic remediation.
Support audits, vendor reviews, customer questionnaires, and policy maintenance across teams.
YipitData is a leading market research and analytics firm for the disruptive economy, providing actionable insights from alternative data. The company has a global presence with offices in the US, APAC, and India, and is recognized as an Inc. Best Workplace for three consecutive years, emphasizing transparency, ownership, and continuous mastery.
Lead and mature the GRC program across SOC 2, ISO 27001, PCI DSS, and other compliance frameworks, including audit preparation and evidence collection.
Own the annual security risk assessment process using NIST SP 800-30 methodology, including stakeholder interviews and risk scoring.
Drive security awareness training, AI governance, and Data Loss Prevention program development while collaborating with cross-functional teams.
RainFocus is a rapidly growing software company that provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, growing fast, and building a culture that is challenging, fun, and exciting.
Lead privacy and security impact assessments for partner-facing business applications.
Design and improve the Partner Data Privacy & Security Impact Assessment process.
Evaluate risks throughout the data lifecycle and recommend mitigation strategies.
Del Oro Consulting is a staffing and consulting firm that connects professionals with contract opportunities. They are a mid-sized organization focused on delivering specialized talent solutions in a collaborative environment.
Own and strengthen the controls environment, ensuring compliance requirements are effectively implemented and maintained.
Support and mature the GRC program, including SOC 2 operations and alignment with frameworks such as NIST.
Manage vendor risk assessments, regulatory licensing, and security issue lifecycle across jurisdictions.
Mesh enables consumers to pay and be paid with any asset, bridging crypto payments into everyday commerce. Backed by investors like PayPal Ventures and Paradigm, the company is building infrastructure for the global economy with a small, fast-moving team.
Maintain traceability from Federal Zero Trust guidance and VA objectives to assessment criteria, architecture patterns, and implementation priorities.
Support preparation and documentation for Architecture Review Boards, technical reviews, and executive governance forums.
Coordinate documentation needed to transition implementation outcomes into sustainable governance and RMF processes.
True Zero Technologies is a veteran-owned small business that enables people and technology to drive quality outcomes. It has been recognized as a Best Places to Work in 2023 and 2025, and made the Inc. 5000 list in 2022, 2023, and 2025, reflecting a people-first culture and sustained growth.
Serve as primary escalation point for compliance representatives, researching and resolving escalated matters.
Develop and maintain compliance SOPs, training materials, and provide ongoing coaching to team members.
Assist with compliance reporting, monitoring, and ensure policies are followed consistently.
PeopleFinders.com is an online service for locating, contacting, and verifying people and businesses. Over the past couple of decades, it has become one of the largest owners of public records data in the country.
Conduct data governance assessments and gap analysis across client environments.
Develop and maintain data governance policies, standards, and procedures.
Collaborate with senior consultants and client stakeholders to gather requirements and validate governance controls.
GuidePoint Security provides trusted cybersecurity expertise, solutions, and services that help organizations make better decisions and minimize risk. With over 1,300 employees, the company fosters a collaborative culture and serves Fortune 500 companies and U.S. government agencies.
Support enterprise cybersecurity governance, compliance, and risk management programs.
Conduct security control assessments, audit readiness, and policy development.
Coordinate with technical teams and executive leadership to drive cybersecurity modernization.
ERP International is a nationally respected provider of health, science, and technology solutions supporting government and commercial clients. The company has been named a Top Workplace by WTOP News for 7 years and offers a culture of employee recognition, community outreach, and professional development.
Lead IT governance and risk management, including executive reporting and risk register maintenance.
Develop KPI and KRI dashboards to translate complex data into actionable insights for senior leadership.
Oversee ITSM governance, ServiceNow optimization, and vendor risk management.
Our partner is a global organization operating in a sophisticated Governance, Risk & Compliance environment, connecting technology, cybersecurity, privacy, and operational risk. It fosters a collaborative culture with a focus on work-life balance and professional development.
Influence entire compliance programs by translating strategic priorities into clear visions and executable programs with measurable outcomes.
Establish portfolio management frameworks and serve as the primary point of contact for executive leadership on mission-critical compliance programs.
Drive cross-functional delivery of regulatory compliance programs and improve audit processes for R&D.
Twilio is a leading communications platform that delivers innovative solutions to hundreds of thousands of businesses and empowers millions of developers worldwide. They are a remote-first company with a strong culture of connection and global inclusion.
Interpret and operationalize global regulations into technical controls, ensuring compliance across infrastructure, cloud, and data environments.
Design and validate technical controls, lead audits, and automate compliance validation with tools like CSPM and GRC platforms.
Manage compliance strategy globally, perform risk assessments, and provide executive-level reporting on compliance posture.
Vailexa is a company that builds thinkers, creators, and future leaders, giving people space to grow and the opportunity to create real impact from day one. They foster a culture of ownership, learning, and ambition, where employees take ownership and grow beyond limits.
Build and scale Enterprise Risk Management, Third-Party Risk Management, and policy frameworks for a leading fintech company.
Lead regulatory examination and audit readiness, ensuring institutional-grade compliance.
Work remotely with a collaborative team backed by top-tier investors and industry experts.
Ondo Finance offers institutional-grade, blockchain-enabled investment products and services, including tokenized funds and decentralized finance technology. The company is a well-funded, fully remote team backed by leading investors such as Founders Fund and Coinbase Ventures, with a culture focused on innovation and collaboration.
Own and continuously improve Camunda's Information Security Management System (ISMS), driving measurable improvements.
Drive security audit cycles for ISO 27001, SOC 2, and future frameworks with minimal supervision.
Review information security requirements in customer contracts and lead responses to complex security questionnaires.
We are the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex business processes. We are a fully remote, global team trusted by over 700 organizations, named a GP Bullhound Next Unicorn and Great Place to Work certified.
Lead day-to-day management of cybersecurity and information security programs, including schedules, milestones, and performance metrics.
Serve as the primary liaison between executives, cybersecurity teams, and operational stakeholders, facilitating governance forums and executive reviews.
Support strategic planning, risk management, and organizational change initiatives to modernize cybersecurity capabilities.
ERP International provides health, science, and technology solutions to government and commercial sectors. Founded in 2006, the company is headquartered in Laurel, MD, with satellite offices nationwide and has been recognized as a Top Workplace for seven consecutive years.
Serve as the executive owner of Horizon's CMMC Level 2 compliance program, overseeing governance, risk management, and audit readiness.
Provide executive oversight of Microsoft GCC High environment security, including identity, endpoint, and vulnerability management.
Lead risk assessments, review POA&M activities, and ensure alignment with NIST SP 800-171 and DoD requirements.
Horizon Industries is a company focused on providing cybersecurity compliance services, particularly relating to CMMC and federal contracting. The company is an Equal Employment Opportunity employer that considers all applicants for employment.
Lead research governance and compliance processes for biomedical research programs, ensuring ethical and regulatory adherence.
Design data governance frameworks for sharing sensitive human data, balancing access with responsible stewardship.
Collaborate with scientific communities and institutional partners to implement governance systems that protect participant rights and research integrity.
Sage Bionetworks architects a more open, equitable, and data-driven scientific ecosystem by democratizing information and breaking down disciplinary barriers to accelerate research. Founded in 2009, this high-agility nonprofit fosters a culture of curiosity, innovation, and diverse perspectives, operating at the intersection of science, technology, and ethical data sharing.