Lead RMF authorization activities, including SSP, SAP, SAR, and POA&M development.
Conduct vulnerability assessments and enforce secure configurations using CIS Benchmarks and DISA STIGs.
Support cloud security initiatives in AWS GovCloud and advise on AI-enabled system security.
This company provides cybersecurity solutions for federal government systems. They are a mid-sized organization with a collaborative culture focused on security and compliance.
Lead ISSO activities to ensure confidentiality, integrity, availability, and compliance of enterprise applications and information systems.
Manage RMF processes including ATO packages, continuous monitoring, risk assessments, and accreditation documentation within eMASS.
Implement and maintain compliance with DISA STIGs, NIST 800-53 controls, and federal cybersecurity requirements.
Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. The company facilitates the hiring process by sharing top-fitting candidate shortlists with partner companies, focusing on efficiency and objectivity.
Lead implementation and maintenance of enterprise cybersecurity programs across cloud and corporate environments.
Manage compliance initiatives aligned with frameworks such as NYDFS Cybersecurity Regulation 500 and ISO 27001.
Conduct vulnerability assessments, coordinate penetration testing, and drive timely remediation of identified risks.
Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. They operate with a remote team and use technology to streamline the application process.
Perform enterprise risk assessments using NIST CSF, SOC 2, and CIS frameworks.
Develop and execute security awareness programs including training and phishing simulations.
Support governance and control management by maintaining policies and control libraries.
Protective helps protect customers against life's uncertainties by providing insurance and peace of mind. The company offers a collaborative environment with a focus on employee wellbeing and work-life balance.
Lead RMF activities including control selection, POA&M management, and ATO support for the depot.
Design supply chain security controls such as SBOM generation, artifact signing, and vulnerability scanning.
Integrate security tooling into CI/CD pipelines and interface with government assessors and authorizing officials.
OpenTeams builds AI that empowers, focusing on energy-efficient, cost-effective models that give users full ownership of their data. As a small company, they value freedom, teamwork, accountability, and reinvest 3% of profits into the open-source community.
Serve as the Information Systems Security Officer for assigned systems, maintaining security documentation and supporting authorization activities.
Coordinate security control implementation with Engineering, DevOps, and IT teams, managing Plans of Action and Milestones.
Support continuous monitoring, vulnerability management, and incident response for FedRAMP and GovRAMP environments.
Keeper Security is a cybersecurity software company that protects organizations and individuals globally with zero-trust and zero-knowledge solutions. It is a fast-growing company with FedRAMP and GovRAMP high authorizations, recognized in the Gartner Magic Quadrant for PAM.
Partner with application development teams to integrate security requirements into design, development, and deployment workflows.
Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation.
Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards.
Oddball builds quality software for the federal space, focusing on improving the daily lives of millions of people. They are a small company that values learning, growth, and making a big impact.
Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.
USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.
Defines program goals, governance frameworks, and measurable objectives for cyber risk and compliance programs.
Manages user attestations, third-party risk, cyber contract negotiation, and coordination of IT audits/assessments.
Implements GRC tooling and monitors program effectiveness through KPIs, QA reviews, and control testing.
Velera is a credit union service organization providing fintech solutions to over 4,000 financial institutions. The company fosters a remote-first, inclusive culture with a focus on employee wellbeing and belonging.
Design and evolve security architecture across cloud infrastructure, applications, and CI/CD pipeline.
Conduct threat modeling, architecture reviews, and define secure design patterns for GCP-based environment.
Evaluate emerging technologies like AI and GenAI platforms to identify risks and define secure adoption patterns.
Airship provides a no-code, AI-powered platform for brands like Alaska Airlines and BBC to create personalized cross-channel customer experiences. The company fosters a digital-first, flexible remote culture with a collaborative team across time zones.
Provide advanced cybersecurity expertise to support secure system operations and compliance initiatives.
Analyze system designs and architectures to ensure appropriate security controls and protection mechanisms.
Collaborate with technical teams and security organizations to align priorities and security objectives.
The partner company is a mission-driven organization that strengthens cybersecurity capabilities for critical information systems. It offers a collaborative culture with opportunities for professional growth and impactful work.
Architect and maintain secure, resilient, and optimized cloud environments primarily in GCP, with AWS and Azure.
Partner with Developer Platform and IAM teams to embed security into architecture and identity strategies.
Harden cloud platforms against emerging threats, bring a DevOps mindset with Terraform/IaC and Kubernetes, and help secure AI-driven pipelines.
Chainguard is the trusted source for open source software, delivering hardened and secure builds. They are a venture-backed late-stage startup serving Fortune 500 enterprises and global industry leaders.
Design and implement security capabilities to satisfy FedRAMP KSIs within your team's specialty domains.
Build automated, repeatable deployments using infrastructure-as-code and CI/CD pipelines.
Deploy into client environments as a subject-matter expert, integrating and hardening capabilities.
Coalfire is a cybersecurity firm that helps clients navigate the ever-changing cybersecurity landscape through advisory, assessment, and automation. The company is headquartered in Chicago with offices across the U.S. and U.K., and fosters a collaborative team culture of passionate problem-solvers.
Act as a trusted consultant guiding clients through complex security and compliance challenges.
Develop security strategies aligned with frameworks like CMMC, NIST 800-171, and NIST 800-53.
Design and implement AWS and/or GCP security tools with deep expertise in cloud security.
Aprio is a Top 20 CPA and advisory firm that provides compliance and advisory services to fast-growing industries. With over 3,200 team members across 40 US and international offices, they foster a top-rated culture and collaborative environment.
Design and implement security solutions across multi-cloud environments (AWS, GCP, Azure).
Lead threat detection, identity management, and compliance posture for clients.
Embed security into CI/CD pipelines and develop AI-accelerated internal tooling.
Riveron is a consulting firm that helps organizations implement governance, risk, and compliance practices, including cybersecurity advisory. The firm has an entrepreneurial culture focused on collaboration, diversity, and delivering exceptional outcomes.
Design and implement security controls across AWS GovCloud environments.
Integrate security into CI/CD pipelines using Terraform and GitLab.
Ensure compliance with FedRAMP and DoD IL-4/5 standards.
Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. We are a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, ownership, and results.
Design and implement cloud security posture and automation to protect customer trust.
Enable cyber resilience and lead zero trust initiatives across the infrastructure.
Collaborate with engineering teams to enhance reliability and security of cloud systems.
Mercury is a fintech company providing banking and financial services for startups, focusing on simplicity and security. With a team of around 500 employees, the culture is collaborative, innovative, and values diversity.
Lead security compliance initiatives across ISO 27001, SOC 2, GDPR, and more.
Conduct internal audits and mentor junior specialists.
Collaborate with product teams to integrate compliance requirements.
Our partner is a fast-growing technology company specializing in security compliance and automation for European businesses. They have a startup culture with a focus on innovation and collaboration.
Lead security discovery workshops and translate high-level architectural requirements into actionable security roadmaps.
Design end-to-end cloud security frameworks and document controls for SOC 2 and HITRUST compliance.
Establish governance and security processes for AI and manage vulnerability remediation with development teams.
Ollion is a global technology partner that helps organizations solve their toughest business challenges in AI, data, and cloud. They are a remote-first, globally distributed team focused on making a world of difference through innovation and collaboration.
Design, develop, and maintain automated workflows for RMF, A&A, and continuous monitoring.
Develop integrations between GRC platforms, security tools, and reporting solutions.
Automate evidence collection, control validation, and compliance activities to improve efficiency.
True Zero Technologies is a veteran-owned small business that enables people and technology to deliver top-tier cybersecurity services. With a people-first approach, the company has been recognized as a Best Places to Work honoree and made the Inc. 5000 list, reflecting a culture of driven and passionate individuals.