Build and maintain technical controls across security and compliance frameworks such as SOC 2, ISO 27001, HIPAA, and other enterprise requirements.
Automate compliance workflows, evidence collection, access reviews, and security checks.
Partner with Engineering and Security to implement controls around access management, infrastructure, data protection, logging, and vulnerability management.
Retell AI is reimagining the call center with cutting-edge voice AI. Backed by Y Combinator, the company has scaled to $60M ARR with a team of 40 people, and is looking for ambitious builders to tackle hard technical problems.
Assess and manage third-party risks across the full vendor lifecycle, including due diligence and ongoing monitoring.
Evaluate cybersecurity, technology, operational, compliance, privacy, and resilience risks of third parties.
Collaborate with procurement, legal, and cybersecurity teams to support informed vendor decisions and strengthen TPRM frameworks.
MENA Consultant is a consulting firm that provides risk management and advisory services. The company size and culture are not disclosed in the posting.
Build and maintain compliance frameworks in the Secfix platform, including ISO 27001, TISAX, SOC 2, GDPR, and more.
Own internal audits end-to-end for customers, ensuring they are prepared for external audits.
Collaborate with product and engineering to translate compliance gaps into structured product work and enhance platform quality.
Secfix automates security compliance for European companies, helping them achieve ISO 27001, GDPR, TISAX, and SOC 2 efficiently. They are a 100% remote team with hubs in Munich, Berlin, and London, recently raised a $12M Series A, and are backed by top VCs.
Interpret and operationalize global regulations into technical controls, ensuring compliance across infrastructure, cloud, and data environments.
Design and validate technical controls, lead audits, and automate compliance validation with tools like CSPM and GRC platforms.
Manage compliance strategy globally, perform risk assessments, and provide executive-level reporting on compliance posture.
Vailexa is a company that builds thinkers, creators, and future leaders, giving people space to grow and the opportunity to create real impact from day one. They foster a culture of ownership, learning, and ambition, where employees take ownership and grow beyond limits.
Review system documentation and technical evidence against NIST, FISMA, RMF, FedRAMP, and Zero Trust requirements.
Perform control-gap analyses, maturity assessments, and compliance reviews; identify risks and recommend corrective actions.
Support authorization activities by preparing security plans, control implementation statements, and remediation documentation.
9th Way Insignia is a service-disabled, veteran-owned small business providing transformative technology solutions including cybersecurity, cloud modernization, software development, and data analytics to government customers. As a small business, it empowers its people to fearlessly drive change and offers a comprehensive benefits package.
Perform cybersecurity and technology risk assessments across systems, vendors, and business processes.
Support compliance with SOC 2, HIPAA, HITRUST, and PCI DSS frameworks.
Manage third-party risk assessments and track remediation of security findings.
Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. They partner with companies to manage applications and hiring processes, offering remote roles and streamlined recruitment.
Conduct cybersecurity risk assessments and compliance reviews to identify gaps and remediation needs.
Support internal and external audits against Federal requirements and organizational policies.
Develop and maintain cybersecurity policies, procedures, and compliance documentation.
PingWind is a Service-Disabled Veteran-Owned Small Business that delivers cybersecurity, IT infrastructure, supply chain management, and professional services to the federal government. As a small business with offices in Northern Virginia and Huntsville, AL, PingWind fosters a dynamic team environment focused on supporting large government clients.
Lead and mature Fullscript's security compliance program across SOC 2, PCI DSS, and HITRUST frameworks.
Manage internal and external audits, coordinate remediation efforts, and maintain continuous audit-readiness.
Partner cross-functionally with Security, Engineering, Privacy, Legal, and Product to translate compliance requirements into scalable practices.
Fullscript is a health technology company that powers every part of care by providing practitioners with clinical insights, lab interpretations, and high-quality supplements. With over 125,000 practitioners and 10 million patients, they foster a culture of curiosity, collaboration, and putting people first.
Independently execute endpoint security, identity management, and vulnerability remediation across Windows, macOS, Linux, and cloud platforms.
Monitor and analyze alerts within SIEM and EDR, conduct initial investigations, and escalate complex findings as needed.
Partner with IT, Engineering, DevOps, and IAM teams to maintain security controls and support compliance frameworks like SOC 2, HIPAA, and ISO 27001.
Accela is an industry leader in designing and delivering government software to improve efficiency, increase citizen engagement, and enable the development of thriving communities. The company has been operating for nearly 20 years, fosters a diverse and inclusive culture, and is committed to equity and belonging.
Develop and improve cybersecurity governance frameworks, strategies, and roadmaps.
Manage policy approvals, exceptions, and maintain documentation for audits.
Provide governance reporting and insights to senior management.
MENA Consultant is a regional consulting firm based in the Middle East, providing talent and consulting solutions. The size and culture are not detailed in the posting.