Serve as the Information Systems Security Officer for assigned systems, maintaining security documentation and supporting authorization activities.
Coordinate security control implementation with Engineering, DevOps, and IT teams, managing Plans of Action and Milestones.
Support continuous monitoring, vulnerability management, and incident response for FedRAMP and GovRAMP environments.
Keeper Security is a cybersecurity software company that protects organizations and individuals globally with zero-trust and zero-knowledge solutions. It is a fast-growing company with FedRAMP and GovRAMP high authorizations, recognized in the Gartner Magic Quadrant for PAM.
Lead technical roadmap for FedRAMP Continuous Monitoring, transitioning manual reporting to automated telemetry and validation.
Design compliance-as-code frameworks and automated evidence generation to reduce manual effort during assessments and audits.
Partner with cross-functional teams to define compliance verification requirements and mentor on FedRAMP practices.
Our partner is a technology company specializing in security and compliance for public sector cloud environments. They foster a collaborative, fast-moving culture with significant autonomy and cross-functional exposure.
Lead the technical roadmap for FedRAMP Continuous Monitoring, moving from manual reporting to automated, real-time telemetry.
Architect compliance outcomes by translating NIST 800-53 Rev. 5 and FedRAMP CR26 rulesets into scalable engineering solutions.
Engineer evidence generation frameworks to reduce manual effort for 3PAO assessments and automate compliance validation.
Wiz provides an AI-powered platform to secure cloud and AI applications by connecting code, cloud, and runtime into a single shared context. It is one of the fastest-growing startups, trusted by over 65% of the Fortune 100, with a global team and a culture that values world-class talent.
Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
Represent the compliance program in customer-facing discussions and security due diligence reviews.
Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.
Develop and implement effective cybersecurity strategies aligned with client objectives and industry best practices.
Design and implement advanced security controls and technologies, including SIEM, DLP, and endpoint protection.
Lead complex cybersecurity projects, manage client relationships, and contribute to thought leadership.
Avertium provides cybersecurity consulting and managed security services, focusing on Microsoft Cloud and other platforms. The company fosters a culture of remote teamwork, self-discipline, and innovation, leveraging industry best practices to deliver cost-effective solutions.
Partner with application development teams to integrate security requirements into design, development, and deployment workflows.
Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation.
Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards.
Oddball builds quality software for the federal space, focusing on improving the daily lives of millions of people. They are a small company that values learning, growth, and making a big impact.
Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and Management Review Meetings.
Support ISO 27001 and SOC 2 Type 2 audits from readiness through certification, including evidence preparation.
Lead the security policy program and collaborate across teams to translate compliance requirements into practical practices.
Mozilla Corporation is a non-profit-backed tech company behind Firefox, focused on making the internet better. With 225+ million monthly users, it is a wholly owned subsidiary of the Mozilla Foundation, promoting privacy, AI, and open-source.
Execute NIST SP 800-53 control mappings and implement security baselines.
Develop and maintain SSPs, POA&Ms, and authorization documentation.
Support continuous monitoring and gap assessments for ATO and FedRAMP.
This company provides cybersecurity and compliance consulting services, supporting defense contractors and federal organizations with NIST and FedRAMP requirements. It is an early-stage, remote-first company with a collaborative culture focused on federal cybersecurity.
Own IRAP and ISMAP program strategy and execution across Australia and Japan.
Coordinate with regional assessors and government agencies to maintain compliance.
Design and maintain compliance documentation and manage continuous monitoring.
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. They are now uniting human teams with AI agents to automate tasks and uncover insights.
Operate and monitor cybersecurity controls for a FedRAMP- and CJIS-regulated SaaS product in AWS.
Triage security events, investigate threats, and support incident response with root-cause analysis.
Maintain security platforms, vulnerability management, and data protection operations across the environment.
Granicus provides cloud-based technology for government agencies to improve digital services and connect with communities. Over 25 years, they serve 5,500 agencies and 300 million subscribers, with a remote-first, inclusive culture.
Perform analysis of existing and emerging DLA information systems, OT, and IT infrastructure for compliance with DLA, DoD, and Federal IA policy.
Conduct Security Test and Evaluation, IA/cybersecurity assessment reviews, and document risk assessments with decision recommendations.
Handle COMSEC material per DoD/DLA policy and maintain regular access to an authorized SIPRNet location for classified data compilation.
Zantech is a dynamic Woman Owned Small Business focused on providing complex, mission-focused solutions with a proven track record of outstanding customer performance and high employee satisfaction. We are a performance-based company that values long-term relationships with clients and employees.
Lead GRC activities including risk management framework, security assessments, and continuous monitoring for assigned systems.
Collaborate with engineering and security teams to integrate GRC principles into system lifecycles and DevSecOps practices.
Develop and maintain security documentation, support ATO processes, and provide risk briefings to leadership.
The partner company helps organizations strengthen cybersecurity programs through modern GRC practices and engineering expertise. It is a fully remote organization with a collaborative culture focused on technical excellence and professional growth.
Own compliance operations for FedRAMP, DoD Impact Levels, and CMMC programs.
Manage federal obligation registers, POA&Ms, and continuous monitoring.
Produce artifacts including NIST 800-171 self-assessments and certification packages.
Kaizen builds modern, AI-native software for government services to restore public trust. Founded in 2022 and based in NYC, the company has raised $35 million from top venture firms and reaches 55 million Americans across 50+ agencies.
Serve as acting CISO for multiple client organizations and SGP, providing strategic security leadership and executive guidance.
Lead cybersecurity and compliance programs aligned with NIST SP 800-171, CMMC Levels 1-2, and ISO/IEC 27001.
Conduct security assessments, gap analyses, and risk reviews; develop SSPs, POA&Ms, and policies.
Strategic Growth Partners provides cybersecurity and compliance services to clients across multiple time zones. They foster a collaborative, innovative, and diverse work environment.
Own cybersecurity strategy and operations across all AIOS entities.
Lead identity, access, endpoint, application, and infrastructure security.
Drive risk and compliance for HIPAA, GDPR, SOC 2, and ISO 27001.
AIOS is building the world's first full-stack AI doctor, serving 150k monthly patients through Bolt Pharmacy. We're a profitable, founder-led company scaling from $10M to $350M ARR in 12 months, with a culture of extreme ownership and speed.
Provide expert guidance on cybersecurity policies, Risk Management Framework (RMF) processes, and security control implementation.
Conduct vulnerability assessments, penetration testing, and Cybersecurity Compliance and Readiness Inspections (CCRI).
Prepare detailed technical reports and briefings for senior leadership on cybersecurity findings and progress.
The company is a partner organization focused on cybersecurity and mission-critical IT environments. They offer a remote work culture and support complex security initiatives for government and enterprise clients.
Lead and maintain ATO documentation and coordinate with security, engineering, and project teams to ensure compliance.
Monitor security events, investigate threats, and assess vulnerabilities across cloud and enterprise environments.
Develop and implement security policies, conduct risk analysis, and provide cybersecurity guidance to stakeholders.
The company is a partner organization focused on cybersecurity and federal technology modernization. It offers a fully remote, mission-driven culture with opportunities for growth in a technology-focused environment.
Lead IT governance and risk management, including executive reporting and risk register maintenance.
Develop KPI and KRI dashboards to translate complex data into actionable insights for senior leadership.
Oversee ITSM governance, ServiceNow optimization, and vendor risk management.
Our partner is a global organization operating in a sophisticated Governance, Risk & Compliance environment, connecting technology, cybersecurity, privacy, and operational risk. It fosters a collaborative culture with a focus on work-life balance and professional development.
Own and manage federal compliance frameworks including FedRAMP, NIST, CMMC, DFARS, and StateRAMP.
Translate regulatory controls into automated tests and machine-readable specifications for continuous authorization.
Collaborate with Engineering, Product, and Design to shape product capabilities and influence strategy.
Our partner company is a technology organization focused on federal compliance automation, serving organizations from emerging companies to large enterprises. They operate with a remote-first culture and value autonomy, accuracy, and scalability.
Maintain traceability from Federal Zero Trust guidance and VA objectives to assessment criteria, architecture patterns, and implementation priorities.
Support preparation and documentation for Architecture Review Boards, technical reviews, and executive governance forums.
Coordinate documentation needed to transition implementation outcomes into sustainable governance and RMF processes.
True Zero Technologies is a veteran-owned small business that enables people and technology to drive quality outcomes. It has been recognized as a Best Places to Work in 2023 and 2025, and made the Inc. 5000 list in 2022, 2023, and 2025, reflecting a people-first culture and sustained growth.