Develop and execute enterprise cybersecurity strategy and multi-year security roadmap.
Lead cybersecurity risk management, security operations, and incident response programs.
Ensure compliance with HIPAA, HITRUST, NIST, and other regulatory frameworks.
Mom's Meals provides home-delivered meal solutions for individuals with health needs. The company values its team members and offers a generous benefits package.
Design and implement an end-to-end Enterprise Cybersecurity Risk Register.
Lead governance lifecycle, establish risk ownership, and drive cross-functional stakeholder alignment.
Deliver audit-ready documentation and ensure post-contract sustainability through structured knowledge transfer.
ASSYST is a technology consulting firm that provides staffing and solutions. The company seeks to place experienced professionals in client engagements, though size and culture are not specified.
Support governance, risk, privacy, and compliance programs to ensure alignment with regulatory requirements.
Conduct risk assessments for vendors and new technologies, and maintain compliance with GDPR and other regulations.
Manage data governance, privacy evaluations, and cybersecurity awareness training.
RMI is an independent nonprofit transforming global energy systems for a zero-carbon future. Founded in 1982, the organization has a global team and a remote-ready culture.
Take ownership of information security governance, including policies, risk registers, and control documentation.
Manage day-to-day security program operations, mentor analysts, and coordinate cross-functional initiatives.
Lead incident response, compliance support, and serve as primary counterpart to the vCISO.
Aries is a financial technology company building modern infrastructure and products for active investors and traders. As a growing organization, they are investing in a practical, accountable security program deeply integrated into how the company operates.
Own risk identification, analysis, and prioritization across third-party risk and security risk assessments using established frameworks.
Translate technical vulnerabilities and risk findings into clear, quantified risk statements for non-security stakeholders and leadership.
Drive remediation of findings and risk exceptions to closure, partnering with Engineering, IT, Product, and Legal.
GitLab is an intelligent orchestration platform for DevSecOps, helping organizations increase developer productivity and improve security. With over 50 million users, GitLab is trusted by more than 50% of the Fortune 100 and fosters a high-performance culture driven by values and continuous knowledge exchange.
Lead enterprise and division risk assessments to identify strategic, operational, compliance, technology, and cybersecurity risks.
Maintain the enterprise risk register, develop KRIs/KPIs, and produce executive-level risk reports and dashboards.
Evaluate policies and controls to address weaknesses, drive corrective actions, and improve ERM processes.
SkyePoint Decisions is a cybersecurity architecture and engineering IT service provider headquartered in Dulles, Virginia, serving federal government clients. It is a certified small business with a collaborative culture focused on innovation and mission success.
Assess and validate implementation of cybersecurity controls against regulatory requirements and security frameworks.
Conduct technical compliance reviews across infrastructure, cloud, applications, and critical assets.
Manage audit evidence, compliance documentation, and remediation tracking for ongoing compliance.
MENA Consultant is a consulting firm that connects talent with opportunities in the Middle East and North Africa region. It focuses on providing expert consultants for various projects, fostering a culture of professionalism and growth.
Own the overall security posture, including policy, standards, and risk framework.
Manage ISO 27001, SOC 2, FedRAMP, and CMMC compliance programs.
Lead incident response, vulnerability management, and customer security assurance.
RapidFort is a cybersecurity company that helps organizations secure and optimize their software supply chain and containerized environments. As a fast-growing startup, we foster a culture of ownership and direct communication, where every team member contributes to our mission of securing cloud-native applications for regulated industries.
Lead complex incident response investigations end-to-end with minimal supervision.
Perform alert triage, phishing investigations, endpoint forensics, and data exfiltration analysis.
Mentor junior analysts and drive improvements to security processes.
Version 1 is a technology and transformation solutions provider trusted by global brands. With over 3,300 employees and €350m revenue, it has been recognized as a Great Place to Work for over a decade.
Conduct cybersecurity risk assessments and compliance reviews to identify gaps and remediation needs.
Support internal and external audits against Federal requirements and organizational policies.
Develop and maintain cybersecurity policies, procedures, and compliance documentation.
PingWind is a Service-Disabled Veteran-Owned Small Business that delivers cybersecurity, IT infrastructure, supply chain management, and professional services to the federal government. As a small business with offices in Northern Virginia and Huntsville, AL, PingWind fosters a dynamic team environment focused on supporting large government clients.
Lead and mature cybersecurity compliance programs including SOC 2 Type 2 and ISO 27001 readiness.
Drive cloud and application security across AWS and Azure, integrating secure SDLC and DevSecOps practices.
Manage corporate IT operations, identity and access, and build the cybersecurity team as the organization grows.
Genea is a leader in property technology, providing cloud-based physical security, submeter billing, and on-demand HVAC solutions to over 1 million users across 39 countries. It has been recognized as a Top Workplace from 2021-2025 with a 4.3 Glassdoor rating, fostering a team-oriented and transparent culture.
Develop, implement, and manage GRC strategies to support compliance with frameworks like FedRAMP, IRAP, and SOC 2.
Lead security assessments, audits, and certification processes, ensuring timely and successful completion.
Collaborate with cross-functional teams to integrate GRC requirements into operations and technology.
GitLab is the intelligent orchestration platform for DevSecOps, enabling organizations to increase developer productivity, improve operational efficiency, and reduce security and compliance risk. More than 50 million registered users and over 50% of the Fortune 100 trust GitLab, driven by a high-performance culture of continuous knowledge exchange.
Lead cybersecurity governance, assessment, and audit activities supporting a federal customer.
Coordinate evidence, control assessments, and remediation across NIST, RMF, and federal compliance requirements.
Maintain quality control, configuration traceability, and readiness for IV&V, QA, and government surveillance.
SkyePoint Decisions is a cybersecurity architecture, engineering, and IT services provider supporting federal government clients. Headquartered in Dulles, Virginia, it is an ISO-certified small business with a collaborative culture focused on mission assurance.
Design, implement, and evolve security operations practices, controls, and tools across a globally distributed environment.
Identify, investigate, and contain sophisticated threats, guiding remediation and improving security assurance.
Influence engineering teams, contribute to threat intelligence, and share security expertise with the broader community.
Our partner company is a global technology organization focused on strengthening critical infrastructure and open-source ecosystems. They operate a remote-first environment with a distributed team, emphasizing autonomy, continuous learning, and high technical standards.
Lead and expand the security function across application security, security compliance, infrastructure & cloud security, and business application security.
Build and run the AppSec program with AI-assisted code review and integrate security into CI/CD pipelines.
Own ISO 27001 and SOC 2 certification, manage audits, and secure cloud and business applications.
Constructor provides an all-in-one platform for education and research using machine intelligence and data science to address educational challenges like access inequality and low engagement. The company is led by a gender-balanced board and fosters an inclusive culture, though employee size is not specified.
Lead and oversee cybersecurity assessment and authorization activities for a major federal program.
Serve as the primary interface with government leadership and stakeholders.
Manage task order execution, staffing, schedules, and contractual performance.
This company supports federal cybersecurity programs and manages contracts for government clients. It offers a remote work environment and emphasizes employee empowerment and accountability.
Develop and run cybersecurity programs, including training, threat intelligence sharing, and sector engagement, tailored to nonprofits' needs.
Represent NGO-ISAC with government, industry, and the cybersecurity community, and build partnerships.
Lead and mentor program staff, setting clear priorities and ensuring reliable delivery of services.
NGO-ISAC is a 501(c)(3) nonprofit that strengthens the security of U.S.-based nonprofits, serving 400+ members including think tanks, human rights organizations, and healthcare nonprofits. We are a small, collaborative team with a startup energy, focused on mission-driven work and work-life balance.
Provide overall program and contract management leadership for cybersecurity architecture and engineering activities.
Serve as primary interface with government stakeholders and translate requirements into actionable work plans.
Manage program schedules, risks, deliverables, and ensure alignment with Federal security standards.
9th Way Insignia is a service-disabled, veteran-owned small business bringing transformative technology to government customers. We specialize in cybersecurity, cloud modernization, and artificial intelligence.