Lead compliance initiatives across commercial and federal lines, driving FedRAMP, CMMC, ISO 27001, SOC 2, and HITRUST programs.
Coordinate internal and external audits, ensuring stakeholder readiness and timely remediation of findings.
Manage program roadmaps, risk registers, and cross-functional execution to translate regulatory requirements into actionable plans.
We provide an AI-infused scenario planning and analysis platform to optimize business decision-making. We serve over 2,400 global customers including Fortune 50 companies and foster a Winning Culture focused on innovation, diversity, and leadership.
Lead control implementation and audit readiness across multiple compliance frameworks including FedRAMP, SOC 2, ISO 27001, and TISAX.
Partner with engineering, product, and security teams to translate compliance requirements into practical controls.
Represent the compliance program in customer-facing discussions and security due diligence reviews.
Rescale is pioneering the future of engineering and scientific discovery through intelligent automation, applied AI, and data management. We are a diverse, collaborative, and mission-driven team that unlocks innovation across aerospace, energy, life sciences, and manufacturing industries.
Build and own federal compliance frameworks for FedRAMP, NIST, and CMMC.
Interpret controls at the mechanics level and author precise technical guidance.
Lead Vanta's machine-readable future with OSCAL and FedRAMP 20x.
Vanta helps businesses earn and prove trust by automating security monitoring and compliance. Founded in 2018, the company has a kind and talented team and is used by thousands of companies.
Maintain and mature the ISMS, including the Statement of Applicability, risk treatment plans, and Management Review Meetings.
Support ISO 27001 and SOC 2 Type 2 audits from readiness through certification, including evidence preparation.
Lead the security policy program and collaborate across teams to translate compliance requirements into practical practices.
Mozilla Corporation is a non-profit-backed tech company behind Firefox, focused on making the internet better. With 225+ million monthly users, it is a wholly owned subsidiary of the Mozilla Foundation, promoting privacy, AI, and open-source.
Own and continuously improve Camunda's Information Security Management System (ISMS), driving measurable improvements.
Drive security audit cycles for ISO 27001, SOC 2, and future frameworks with minimal supervision.
Review information security requirements in customer contracts and lead responses to complex security questionnaires.
We are the enterprise platform for agentic orchestration, enabling organizations to coordinate AI agents, people, and systems across complex business processes. We are a fully remote, global team trusted by over 700 organizations, named a GP Bullhound Next Unicorn and Great Place to Work certified.
Own and strengthen the controls environment, ensuring compliance requirements are effectively implemented and maintained.
Support and mature the GRC program, including SOC 2 operations and alignment with frameworks such as NIST.
Manage vendor risk assessments, regulatory licensing, and security issue lifecycle across jurisdictions.
Mesh enables consumers to pay and be paid with any asset, bridging crypto payments into everyday commerce. Backed by investors like PayPal Ventures and Paradigm, the company is building infrastructure for the global economy with a small, fast-moving team.
Take ownership of the information security program, lead the IT team, and collaborate with engineering on deep technical work.
Own SOC 2, Vanta, governance, IT/TechOps, vendor diligence, SIEM, vulnerability management, and cloud security.
Partner with the CTO and AI Labs to build security capabilities and automate with AI tooling.
We are a Forbes Fintech 50, SHRM-backed company tackling employer talent retention and the student debt crisis. We are a Series B startup with a strong technical team, enterprise customers, and a high security bar.
Serve as the Information Systems Security Officer for assigned systems, maintaining security documentation and supporting authorization activities.
Coordinate security control implementation with Engineering, DevOps, and IT teams, managing Plans of Action and Milestones.
Support continuous monitoring, vulnerability management, and incident response for FedRAMP and GovRAMP environments.
Keeper Security is a cybersecurity software company that protects organizations and individuals globally with zero-trust and zero-knowledge solutions. It is a fast-growing company with FedRAMP and GovRAMP high authorizations, recognized in the Gartner Magic Quadrant for PAM.
Own IRAP and ISMAP program strategy and execution across Australia and Japan.
Coordinate with regional assessors and government agencies to maintain compliance.
Design and maintain compliance documentation and manage continuous monitoring.
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. They are now uniting human teams with AI agents to automate tasks and uncover insights.
Execute NIST SP 800-53 control mappings and implement security baselines.
Develop and maintain SSPs, POA&Ms, and authorization documentation.
Support continuous monitoring and gap assessments for ATO and FedRAMP.
This company provides cybersecurity and compliance consulting services, supporting defense contractors and federal organizations with NIST and FedRAMP requirements. It is an early-stage, remote-first company with a collaborative culture focused on federal cybersecurity.
Own the security compliance program end-to-end, including audits, customer trust, vendor risk, and vulnerability management.
Automate evidence collection and control monitoring to be audit-ready year-round, not just during the August–November season.
Act as the external security face for enterprise prospects and translate AI regulatory changes into requirements.
Ada is an AI customer service company that helps enterprises automate customer conversations with AI agents. Founded in 2016, we've powered over 5.5 billion interactions and raised over $250M from top investors.
Manage and maintain version control of all documentation related to compliance for each standard and track implementation status of security controls.
Oversee preparation and execution of external compliance audits, including facilitating security assessments.
Support mapping of compliance requirements to security control implementation using agile development processes.
Hypori is a high-growth cybersecurity SaaS company providing a virtual workspace platform for secure mobile access. Backed by $55M in funding, the company is expanding into commercial and regulated markets with a focus on innovation and security.
Lead and mature the GRC program across SOC 2, ISO 27001, PCI DSS, and other compliance frameworks, including audit preparation and evidence collection.
Own the annual security risk assessment process using NIST SP 800-30 methodology, including stakeholder interviews and risk scoring.
Drive security awareness training, AI governance, and Data Loss Prevention program development while collaborating with cross-functional teams.
RainFocus is a rapidly growing software company that provides an industry-disrupting event management platform for Fortune 500 companies like Adobe, Cisco, and IBM. The company is well-funded, growing fast, and building a culture that is challenging, fun, and exciting.
Own the design and implementation of Onebrief's GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.
Build and manage the control environment, including policies, procedures, and evidence collection systems.
Design and implement technical security controls in partnership with Product, Engineering, Infrastructure and Corporate IT.
Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination. Founded in 2019 and valued at over $2 billion, the company is a distributed team of builders from military, operational, and technology backgrounds.
Lead customer security reviews, RFPs, RFIs, and questionnaires to keep deals moving.
Own SOC 2 Type II program management and the customer-facing trust portal.
Author security policies and manage AI compliance frameworks.
Sparkrock helps social benefit organizations like nonprofits, school boards, and government agencies reach their full potential through technology. They are a best-in-class, 100% remote organization with a focus on culture and growth, serving over 150,000 users.
Own and continuously improve the company's compliance program across SOC 2, GDPR, ISO 27001, and other frameworks.
Lead external audits, develop security policies, and partner with engineering teams to implement controls.
Manage third-party risk, respond to customer security questionnaires, and build compliance metrics for executive reporting.
10a Labs is the safety and threat-intelligence layer trusted by frontier AI labs, AI unicorns, Fortune 10 companies, and leading global technology platforms. They are a high-growth technology company with a collaborative culture, operating in a fast-moving environment.
Lead vulnerability management and SOC 2 compliance across SaaS products and cloud infrastructure.
Harden Azure and Microsoft security tooling (Defender, Intune) and respond to security alerts.
Partner with engineering, IT, and legal to drive secure SDLC, policies, and customer security reviews.
HSP Group is a premier provider of global expansion services, helping companies with legal setup, HR, payroll, compliance, and tax across international markets. The company partners with scale-ups and innovative technology firms to reduce risk and scale faster, fostering a trusted-partner culture.
Manage the Compliance and Security workstream, coordinating SOC 2, ISO 27001, GDPR, and related audit-readiness activities.
Build and maintain execution plans with clear owners, milestones, dependencies, risks, and decision points.
Facilitate workshops, track evidence, and escalate risks to keep audits on schedule.
Miratech is a global IT services and consulting company that helps visionaries change the world through digital transformation. With nearly 1000 full-time professionals across 25+ countries, the company maintains a culture of Relentless Performance and has achieved over 99% project success since 1989.
You will own end-to-end compliance audits (SOC 1, SOC 2, HITRUST) and manage compliance automation platforms.
You will run the vulnerability management program and remediate security findings across AWS.
You will support security incident response, fraud investigations, and third-party risk assessments.
We are transforming post-acute care as the leading digital ordering platform for medical equipment and supplies. We connect major health systems, health plans, and suppliers to help patients get life-saving products at home, with a network of 300,000+ clinicians and 3,000+ supplier locations across all 50 states.
Lead the design and evolution of a multi-framework compliance offering for European businesses.
Drive end-to-end ISO 27001 implementations and manage a team of compliance specialists.
Act as a senior security partner to customers, sales, and product teams.
This company provides a security and compliance platform that helps modern businesses achieve certifications across frameworks like ISO 27001 and SOC 2. It is a fast-growing, remote-first technology environment with a strong emphasis on collaboration and team connection.