Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.
Lead the technical roadmap for FedRAMP Continuous Monitoring, moving from manual reporting to automated, real-time telemetry.
Architect compliance outcomes by translating NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering solutions.
Engineer evidence generation frameworks to reduce manual effort for 3PAO assessments and automate compliance validation.
Wiz provides an AI-powered platform to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. It is one of the fastest-growing startups, trusted by over 65% of the Fortune 100, with a global team and a culture that values world-class talent.
Design and evolve highly available cloud architecture on Google Cloud using Terraform and GitOps.
Build and maintain secure CI/CD pipelines for Infrastructure-as-Code and develop self-service developer platforms.
Strengthen platform observability and apply SRE principles to improve reliability and operational maturity.
They are a financial technology company that provides production-critical infrastructure. They have a globally distributed team and a culture of autonomy and async-first collaboration.
Lead end-to-end customer engagements for Zero Trust Cloud deployments, including design, deployment, and go-live.
Utilize Terraform and Infrastructure as Code to build scalable deployments across AWS, Azure, and GCP.
Collaborate with cross-functional teams to ensure successful customer outcomes and knowledge transfer.
Zscaler accelerates digital transformation by providing a cloud-native Zero Trust Exchange platform that secures customers from cyberattacks and data loss. The company fosters a culture of execution, transparency, and collaboration, emphasizing impact over activity and customer obsession.
Lead technical roadmap for FedRAMP Continuous Monitoring, transitioning manual reporting to automated telemetry and validation.
Design compliance-as-code frameworks and automated evidence generation to reduce manual effort during assessments and audits.
Partner with cross-functional teams to define compliance verification requirements and mentor on FedRAMP practices.
Our partner is a technology company specializing in security and compliance for public sector cloud environments. They foster a collaborative, fast-moving culture with significant autonomy and cross-functional exposure.
Lead compliance engineering for FedRAMP High-aligned environments, translating obligations into practical infrastructure changes.
Design and operate secure cloud infrastructure using AWS, Terraform, and Kubernetes across commercial and GovCloud environments.
Improve platform reliability, release operations, and incident response while mentoring engineers on secure operations.
Arch Systems empowers discrete manufacturing facilities with data insights for optimal efficiency and proactive decision-making. It is a rapidly scaling, remote-first company that values collaboration, innovation, and continuous learning.
Build and configure GKE clusters and Google Cloud project environments using Terraform.
Implement and maintain CI/CD pipelines and environment promotion workflows.
Configure and maintain Google Cloud-native monitoring, alerting, and logging.
We design, build, and scale AI-powered solutions that create real business impact. We are building a high-performance culture grounded in five values: Empowering Excellence, Collaborative Teamwork, Unsolicited Respect, Consistent Transparency, and Efficient Communication.
Improve security design and controls within GCP and Kubernetes.
Champion secure development by integrating security best practices early into the software development lifecycle.
Build and automate security tooling for vulnerability detection, remediation, and compliance verification.
Virta Health is a healthcare company that reverses type 2 diabetes and obesity through individualized nutrition and clinical support. They have raised over $350 million from top-tier investors and partner with major health plans, employers, and government organizations.
Design and implement scalable, secure, and reliable cloud solutions in AWS and other platforms.
Lead complex production incidents and drive automation to reduce operational toil.
Mentor junior engineers and establish cloud engineering best practices.
Peraton is a national security company that provides mission capability integration and transformative IT solutions to government agencies and the U.S. armed forces. They employ a large, diverse workforce and emphasize innovation and reliability in their operations.
Set and execute the technical vision for the Security Engineering Platform team, spanning AWS and GCP hardening and tier-0 services.
Own the hardening roadmap for tier-0 cloud infrastructure and access services, backed by rigorous, follow-the-sun on-call.
Coach and mentor highly skilled tech leads and engineers as a player-coach, leaning in on cloud hardening, identity, and secrets management problems.
DoorDash is a technology and logistics company that started by enabling door-to-door delivery and now builds the industry's most scalable and reliable delivery network. The company is growing rapidly with a global team committed to empowering local economies and supporting employees' well-being through comprehensive benefits.
Maintain and improve FedRAMP compliance within an AWS environment using Terraform and infrastructure-as-code.
Identify and remediate vulnerabilities in Golang and containers, and investigate cloud misconfigurations.
Develop CI/CD automation with GitHub Actions and integrate security into the software development lifecycle.
Epsilon ASI is a cloud security company that maintains FedRAMP-compliant environments. They are a growing organization seeking a skilled engineer to strengthen security and compliance.
Own end-to-end audit evidence collection and validation across multiple compliance frameworks including FedRAMP, ISO 27001, and SOC 2.
Maintain and continuously verify technical controls across GCP, GitHub, and Microsoft 365 environments.
Serve as the primary liaison between GRC and technical teams to reduce audit burden and ensure continuous audit readiness.
A-LIGN is a leading provider of cybersecurity compliance programs, offering services including SOC 2, ISO 27001, HITRUST, FedRAMP, and PCI. They are the number one issuer of SOC 2 and HITRUST and a top three FedRAMP assessor, operating in a high-growth, PE-backed environment.
Design, implement, and maintain SIEM platform architectures across AWS, Azure, and GCP environments.
Build and operate reliable log collection and ingestion pipelines using forwarders, connectors, APIs, syslog, and agents.
Support FedRAMP continuous monitoring and compliance requirements while partnering with detection engineering and security operations teams.
Coalfire is a leading cybersecurity solutions provider that advises, assesses, automates, and helps clients navigate the ever-changing cybersecurity landscape. The company has offices across the U.S. and U.K. and fosters a culture of passionate problem-solvers who are hungry to learn and grow.
You will serve as a trusted technical advisor guiding federal customers through Wiz deployment, configuration, and operationalization using cloud-security best practices.
You will act as the primary technical liaison for complex architectural and operational challenges in federal cloud environments.
You will help customers develop success plans with measurable goals aligned to their organizational security, compliance, and mission objectives.
Wiz is a cloud security platform that redefines security for the AI era, enabling teams to secure cloud and AI applications. They are one of the fastest-growing startups, trusted by over 65% of the Fortune 100, scanning over 230 billion files daily, with a culture that values world-class talent and is now powered by Google.
Own and evolve Orca’s FedRAMP environment across AWS GovCloud, Azure Government, and GCP, including infrastructure code, production health, and incident response.
Design automation to make compliance a byproduct of system operation, covering continuous validation, drift detection, and evidence collection.
Serve as the technical interface to federal customers, agency security teams, and assessors, leading authorization efforts and security reviews.
Orca Security is a cloud security innovation leader that invented agentless technology for comprehensive cloud security. The company is a unicorn with a $1.8 billion valuation, backed by top investors, and fosters a respectful and transparent culture.
Architect, deploy, and manage highly available, fault-tolerant cloud infrastructure across Google Cloud Platform (GCP) and Google Kubernetes Engine (GKE).
Maintain and scale declarative infrastructure using Terraform across a multi-hundred-file estate, enforcing GitOps workflows with Atlantis.
Build, maintain, and optimize robust automated pipelines for continuous integration and delivery using GitHub Actions, Jenkins, and ArgoCD.
Point Wild helps customers monitor, manage, and protect against the risks associated with their identities and personal information in a digital world. Backed by WndrCo, Warburg Pincus and General Catalyst, Point Wild is a scrappy, nimble organization dedicated to creating the world’s most comprehensive portfolio of industry-leading cybersecurity solutions.
Support management and maintenance of Google Cloud Platform infrastructure.
Assist in ensuring reliability, scalability, and performance of cloud services.
Contribute to GitLab CI/CD pipelines, work with Kubernetes, and write automation scripts.
Miratech is a global IT services and consulting company that helps visionaries change the world through digital transformation. With nearly 1,000 professionals across 25 countries, the company maintains a culture of Relentless Performance with a 99% project success rate and over 30% year-over-year growth.
Deploy and administer cloud infrastructure ensuring reliability, security, and efficiency of networks.
Collaborate with development and operations teams to enhance network performance and support cloud services.
Automate infrastructure management using Infrastructure as Code (IaC) tools and scripting languages.
Millennium is a cybersecurity firm providing Red Team, Defensive Cyber, Software Engineering, and Technical Engineering services. Since 2004, an elite team of over 300 professionals delivers threat intelligence and battle-tested expertise to the Department of Defense and federal civilian customers.
Lead the security authorization process for systems and applications in compliance with NIST and DoD regulations.
Conduct risk assessments and develop security documentation to ensure high standards of security and compliance.
Work with sponsors to automate manual processes and implement technical solutions for cyber defense.
Dark Wolf Solutions provides cybersecurity and risk management services to protect sensitive information and critical infrastructure. They are a mid-sized company that values motivated, detail-oriented professionals and are an EEO/AA employer committed to diversity.