Lead security risk assessments across engineering, IT, operations, and business functions.
Maintain a risk register and provide leadership with a clear view of the company's risk posture.
Partner with teams to drive remediation of risks and map controls to compliance frameworks like NIST 800-171.
Muon Space is an end-to-end Space Systems Provider that designs, builds, and operates LEO satellite constellations delivering mission-critical data. Founded in 2021, the company operates a state-of-the-art facility in Silicon Valley and is committed to fostering a diverse and dynamic workforce.
Review system documentation and technical evidence against NIST, FISMA, RMF, FedRAMP, and Zero Trust requirements.
Perform control-gap analyses, maturity assessments, and compliance reviews; identify risks and recommend corrective actions.
Support authorization activities by preparing security plans, control implementation statements, and remediation documentation.
9th Way Insignia is a service-disabled, veteran-owned small business providing transformative technology solutions including cybersecurity, cloud modernization, software development, and data analytics to government customers. As a small business, it empowers its people to fearlessly drive change and offers a comprehensive benefits package.
Conduct cybersecurity risk assessments and compliance reviews to identify gaps and remediation needs.
Support internal and external audits against Federal requirements and organizational policies.
Develop and maintain cybersecurity policies, procedures, and compliance documentation.
PingWind is a Service-Disabled Veteran-Owned Small Business that delivers cybersecurity, IT infrastructure, supply chain management, and professional services to the federal government. As a small business with offices in Northern Virginia and Huntsville, AL, PingWind fosters a dynamic team environment focused on supporting large government clients.
Monitor, investigate, and respond to cybersecurity alerts, incidents, vulnerabilities, and threats across enterprise, endpoint, cloud, network, and application environments.
Support compliance with NIST SP 800-171, CMMC, and applicable federal/DoD cybersecurity requirements, including protection of CUI and FCI.
Conduct cybersecurity risk assessments, vulnerability assessments, and security reviews; prioritize findings and coordinate remediation efforts.
Tlingit Haida Tribal Business Corporation (THTBC) delivers mission-critical services to federal clients globally, including logistics, IT, cybersecurity, and facilities operations. For over 35 years, the company has been committed to generating economic opportunity for the Tlingit & Haida Tribes of Alaska, fostering a purpose-driven culture.
Serve as the assigned security officer (vCISO) for a portfolio of client engagements, leading recurring meetings and providing strategic security guidance.
Lead CMMC Level 1 and 2 readiness engagements, including NIST SP 800-171 assessments, SSP development, and POA&M management.
Deliver compliance engagements across frameworks such as HIPAA, SOC 2, PCI DSS, ISO 27001, and more, while conducting risk assessments and coordinating remediation.
Intelligent Technical Solutions is a managed IT and cybersecurity services provider delivering compliance and security practice management to client organizations. The company employs a team of security professionals and fosters a culture of continuous improvement and knowledge sharing.
Lead coordination and implementation of a comprehensive information security program, including policies, processes, and technical controls.
Assess security threats, evaluate emerging technologies, and develop countermeasures to protect sensitive systems and data.
Collaborate across teams to translate risks into practical strategies and ensure compliance with security regulations and privacy laws.
This organization protects critical technology and information systems across internal IT, e-commerce, web, and cloud environments in the healthcare sector. It fosters a mission-driven, inclusive culture with employee resource groups and career development programs.
Support information assurance and cybersecurity activities for the Army Contract Writing System (ACWS).
Assist with implementation and maintenance of security controls per NIST, RMF, STIG, and DoD requirements.
Develop and maintain security documentation including SSPs, POA&Ms, and continuous monitoring artifacts.
LMI is a digital solutions provider dedicated to accelerating government impact with innovation and speed. Headquartered in Tysons, Virginia, the company delivers mission-ready technology and solutions to federal agencies.
Provide technical expertise on security control implementations and develop information security procedures for systems and applications.
Perform pre-assessment activities including detailed analysis of vendor technology stacks for NIST and agency compliance.
Support A&A (NIST 800-53) and compliance activities, reviewing third-party security assessment reports and communicating with stakeholders.
Valiant Solutions is a security-focused IT solutions provider serving public clients nationwide. The company is known for its employee-centric culture, has been named a Best Place to Work in the DC area for 12 consecutive years, and offers strong benefits and career development.
Provide technical expertise on security controls and system architecture for FedRAMP compliance.
Perform detailed architecture reviews of Cloud Service Providers (CSPs) and author package briefings.
Lead architecture interviews and reviews, ensuring alignment with NIST, FISMA, and FedRAMP standards.
Valiant Solutions is a security-focused IT solutions provider with public clients nationwide. Named one of the fastest growing privately held companies, it has been recognized as a Best Place to Work in the D.C. area for 12 consecutive years, fostering a culture of trust, growth, and work-life balance.
Take ownership of information security governance, including policies, risk registers, and control documentation.
Manage day-to-day security program operations, mentor analysts, and coordinate cross-functional initiatives.
Lead incident response, compliance support, and serve as primary counterpart to the vCISO.
Aries is a financial technology company building modern infrastructure and products for active investors and traders. As a growing organization, they are investing in a practical, accountable security program deeply integrated into how the company operates.
Develop and implement cybersecurity strategies and architectures aligned with organizational objectives and regulatory requirements.
Lead RMF activities for large distributed systems to obtain and maintain Authority to Operate.
Collaborate with government stakeholders and cross-functional teams to integrate security across systems and networks.
The company specializes in cybersecurity architecture and Zero Trust solutions for U.S. Department of Defense clients. It offers a fully remote work environment with a focus on work-life balance and professional development opportunities.
Own assigned federal security and compliance workstreams from requirement interpretation through implementation, evidence collection, and remediation.
Drive recurring continuous monitoring and evidence workflows across multiple teams.
Support vulnerability detection and response, including reconciling findings from tools like Wiz, Nessus, and Burp.
Abnormal protects the humans behind the world's most critical organizations from AI-powered cybercrime. 4,500+ enterprises trust their behavioral AI platform.
Manage day-to-day security operational availability and supportability of a 24x7x365 infrastructure.
Make recommendations on enhancements to security hardware, software, and tools, and perform risk analysis.
Configure, implement, monitor, and support security software/systems including firewalls, VPNs, IDS/IPS, DLP, etc.
eMoney Advisor is a wealth management system that offers transparency, security, mobile access, and superior organization. We serve more than 109,000 financial professionals and support over 6 million end clients, fostering a culture that values diversity and inclusion.
Own the overall security posture, including policy, standards, and risk framework.
Manage ISO 27001, SOC 2, FedRAMP, and CMMC compliance programs.
Lead incident response, vulnerability management, and customer security assurance.
RapidFort is a cybersecurity company that helps organizations secure and optimize their software supply chain and containerized environments. As a fast-growing startup, we foster a culture of ownership and direct communication, where every team member contributes to our mission of securing cloud-native applications for regulated industries.
Lead compliance assessments and build-out of IL4/IL5 authorizations for DoD Cloud Computing Security Requirements Guide.
Maintain and evolve compliance posture for FedRAMP High, NIST SP 800-53, and other federal frameworks.
Serve as GRC liaison to engineering teams, translating complex federal compliance requirements into technical specifications for AWS environments.
Horizon3 is a fast-growing, remote cybersecurity company that provides autonomous pentesting through its NodeZero platform. The company is a fusion of former Special Operations cyber operators and engineers, fostering a culture of respect, collaboration, ownership, and results.
Design and implement cybersecurity controls for satellite software, ground systems, and mission infrastructure.
Develop secure software practices including threat modeling, code reviews, and vulnerability management.
Monitor networks for cyber threats, lead incident response, and support compliance with NIST 800-171 and CMMC.
Muon Space is an end-to-end Space Systems Provider that designs, builds, and operates LEO satellite constellations delivering mission-critical data. Founded in 2021, the company is based in Silicon Valley and offers a comprehensive benefits package including equity, medical, dental, vision, 401k, paid vacation, and parental leave.
Lead and mature the information security program, building on ISO 27001 and SOC 2 foundations.
Develop and operationalize security policies, risk management, and incident response.
Partner with Engineering and Product to integrate security into software development.
This is a partner company role managed by Jobgether, a platform that uses AI-powered matching to connect candidates with hiring companies. The partner is a rapidly scaling SaaS and cloud technology environment, with a growing security team and established ISO 27001 and SOC 2 programs.
Own end-to-end vulnerability lifecycle, attack surface management, and cloud security posture across AWS, Azure, and OCI.
Operate CTEM phases, consolidate exposure data into prioritized views, and track KPIs for stakeholder reporting.
Embed security into SDLC, support penetration testing, and translate technical risk clearly for business audiences.
Version 1 is a trusted technology and transformation solutions provider with partnerships including Microsoft, AWS, and Oracle. We're an award-winning, values-driven employer of 3,300+ people and a Great Place to Work in the UK and Ireland.
Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.
Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.
Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.