Design and maintain cybersecurity automation workflows in an enterprise SOAR environment.
Develop REST API integrations and Python scripts for security operations and compliance.
Troubleshoot and optimize workflows while collaborating with cross-functional teams.
True Zero Technologies is a veteran-owned small business that enables organizations through purposeful integration of people and technology. They have been named a Best Place to Work in 2023 and 2025, and are recognized as an Inc. 5000 fastest-growing company, fostering a people-first culture.
Perform enterprise risk assessments using NIST CSF, SOC 2, and CIS frameworks.
Develop and execute security awareness programs including training and phishing simulations.
Support governance and control management by maintaining policies and control libraries.
Protective helps protect customers against life's uncertainties by providing insurance and peace of mind. The company offers a collaborative environment with a focus on employee wellbeing and work-life balance.
Design automation and build data-driven security workflows to embed security-by-design principles across the product development lifecycle.
Establish and maintain product security governance processes, ensuring traceability, accountability, and audit readiness.
Develop automated dashboards, KPIs, and security metrics using tools like Power BI, Tableau, or Grafana, and automate security workflows using Python and APIs.
The company is a technology organization focused on security solutions. It fosters a collaborative culture emphasizing innovation, continuous improvement, and professional growth.
Lead GRC activities including risk management framework, security assessments, and continuous monitoring for assigned systems.
Collaborate with engineering and security teams to integrate GRC principles into system lifecycles and DevSecOps practices.
Develop and maintain security documentation, support ATO processes, and provide risk briefings to leadership.
The partner company helps organizations strengthen cybersecurity programs through modern GRC practices and engineering expertise. It is a fully remote organization with a collaborative culture focused on technical excellence and professional growth.
Own FedRAMP and GovRAMP certifications and roadmaps, including package management and compliance timelines.
Manage 3PAO relationships and assessments, coordinating scoping, evidence, and results validation.
Lead continuous monitoring, POA&M processes, and drive compliance automation and efficiency.
Smartsheet empowers teams to manage work seamlessly and scale solutions smarter, now uniting human teams with AI agents. It is an equal opportunity employer committed to fostering an inclusive environment with the best employees.
Defines program goals, governance frameworks, and measurable objectives for cyber risk and compliance programs.
Manages user attestations, third-party risk, cyber contract negotiation, and coordination of IT audits/assessments.
Implements GRC tooling and monitors program effectiveness through KPIs, QA reviews, and control testing.
Velera is a credit union service organization providing fintech solutions to over 4,000 financial institutions. The company fosters a remote-first, inclusive culture with a focus on employee wellbeing and belonging.
Design and implement security capabilities to satisfy FedRAMP KSIs within your team's specialty domains.
Build automated, repeatable deployments using infrastructure-as-code and CI/CD pipelines.
Deploy into client environments as a subject-matter expert, integrating and hardening capabilities.
Coalfire is a cybersecurity firm that helps clients navigate the ever-changing cybersecurity landscape through advisory, assessment, and automation. The company is headquartered in Chicago with offices across the U.S. and U.K., and fosters a collaborative team culture of passionate problem-solvers.
Lead quality assurance for RMF authorization packages to ensure completeness and readiness for government review.
Coordinate with RMF analysts, ISSOs, system owners, and technical stakeholders to validate security documentation and evidence.
Mentor team members on documentation standards and best practices while tracking assessment readiness metrics to reduce rework.
True Zero Technologies is a veteran-owned small business that enables people and technology to drive quality outcomes. The company has been named a Best Place to Work multiple times and made the Inc. 5000 list of fastest-growing companies, reflecting its people-first culture and commitment to excellence.
Lead ISSO activities to ensure confidentiality, integrity, availability, and compliance of enterprise applications and information systems.
Manage RMF processes including ATO packages, continuous monitoring, risk assessments, and accreditation documentation within eMASS.
Implement and maintain compliance with DISA STIGs, NIST 800-53 controls, and federal cybersecurity requirements.
Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. The company facilitates the hiring process by sharing top-fitting candidate shortlists with partner companies, focusing on efficiency and objectivity.
Take ownership of building and scaling comprehensive security, privacy, and compliance programs that protect customer data.
Lead compliance initiatives such as SOC 2 Type 2 audits and evaluate additional frameworks like ISO 27001 and HIPAA.
Build scalable automated security processes by replacing manual tasks with scripts, APIs, and AI-powered solutions.
Our partner is a technology company focused on building secure, scalable systems. They operate with a remote, collaborative culture emphasizing ownership, transparency, and continuous improvement, with around 50–300 employees.
Manage and implement complex controls frameworks for large systems consisting of Cloud infrastructure and SaaS services.
Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
Conduct risk assessments across business units and processes, identifying risk findings and recommending remediation strategies.
Virtru is a data protection platform that enables secure sharing without sacrificing security or privacy. Backed by top venture capital firms, the company helps Fortune 500 companies and government agencies achieve true data security with freedom to share.
Design and implement cybersecurity architectures, controls, and technologies for secure government systems.
Manage Authority to Operate (ATO) activities, including security documentation, compliance tracking, and continuous monitoring.
Apply NIST SP 800 security controls and support Risk Management Framework (RMF) implementation.
The partner organization provides advanced cybersecurity solutions for critical government technology environments. They operate in a mission-driven, collaborative culture with a focus on protecting federal systems.
Partner with application development teams to integrate security requirements into design, development, and deployment workflows.
Support ATO efforts including development of System Security Plans (SSPs), POA&Ms, and control documentation.
Conduct risk assessments, vulnerability scans, and threat modeling aligned with NIST SP 800-53 and VA security standards.
Oddball builds quality software for the federal space, focusing on improving the daily lives of millions of people. They are a small company that values learning, growth, and making a big impact.
Lead RMF activities including control selection, POA&M management, and ATO support for the depot.
Design supply chain security controls such as SBOM generation, artifact signing, and vulnerability scanning.
Integrate security tooling into CI/CD pipelines and interface with government assessors and authorizing officials.
OpenTeams builds AI that empowers, focusing on energy-efficient, cost-effective models that give users full ownership of their data. As a small company, they value freedom, teamwork, accountability, and reinvest 3% of profits into the open-source community.
Own the design and implementation of Onebrief's GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.
Build and manage the control environment, including policies, procedures, and evidence collection systems.
Design and implement technical security controls in partnership with Product, Engineering, Infrastructure and Corporate IT.
Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination. Founded in 2019 and valued at over $2 billion, the company is a distributed team of builders from military, operational, and technology backgrounds.
Lead RMF authorization activities, including SSP, SAP, SAR, and POA&M development.
Conduct vulnerability assessments and enforce secure configurations using CIS Benchmarks and DISA STIGs.
Support cloud security initiatives in AWS GovCloud and advise on AI-enabled system security.
This company provides cybersecurity solutions for federal government systems. They are a mid-sized organization with a collaborative culture focused on security and compliance.
Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.
USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.
Design, implement, and maintain privileged access solutions to secure critical systems and accounts.
Administer Delinea PAM operations, including integration with enterprise identity and security tooling.
Troubleshoot and resolve PAM issues, ensuring compliance and audit readiness.
Cotiviti is a healthcare analytics company that provides data-driven solutions to improve payment accuracy and quality outcomes. It is a large organization with a culture focused on innovation, collaboration, and security.
Design and implement security controls across AWS GovCloud environments.
Integrate security into CI/CD pipelines using Terraform and GitLab.
Ensure compliance with FedRAMP and DoD IL-4/5 standards.
Horizon3.ai is a fast-growing, remote cybersecurity company dedicated to enabling organizations to proactively find and fix and verify exploitable attack vectors before criminals exploit them. We are a fusion of former U.S. Special Operations cyber operators and startup engineers, committed to a culture of respect, collaboration, ownership, and results.
Own and automate our GRC program, including SOC 2 audits, risk assessments, and vendor security reviews.
Drive internal security across identity, device management, access reviews, and incident response.
Build customer-facing trust resources and coordinate product security audits with engineering.
Close builds a communication-first, AI-powered CRM designed to simplify sales for small businesses. The bootstrapped and profitable company has a 120-person, 100% remote team focused on helping customers scale.