Build and own federal compliance frameworks for FedRAMP, NIST, and CMMC.
Interpret controls at the mechanics level and author precise technical guidance.
Lead Vanta's machine-readable future with OSCAL and FedRAMP 20x.
Vanta helps businesses earn and prove trust by automating security monitoring and compliance. Founded in 2018, the company has a kind and talented team and is used by thousands of companies.
Lead RMF activities including control selection, POA&M management, and ATO support for the depot.
Design supply chain security controls such as SBOM generation, artifact signing, and vulnerability scanning.
Integrate security tooling into CI/CD pipelines and interface with government assessors and authorizing officials.
OpenTeams builds AI that empowers, focusing on energy-efficient, cost-effective models that give users full ownership of their data. As a small company, they value freedom, teamwork, accountability, and reinvest 3% of profits into the open-source community.
Drive compliance, risk management, and security assurance as a GRC Specialist.
Own third-party risk management and maintain security documentation.
Support audits, self-assessments, and customer security inquiries.
Avid provides technology and collaboration tools for creators to entertain, inform, educate, and enlighten the world. The company fosters a culture of passion, customer focus, and innovation, with employees who believe in their mission.
Provide expert guidance on cybersecurity policies, Risk Management Framework (RMF) processes, and security control implementation.
Conduct vulnerability assessments, penetration testing, and Cybersecurity Compliance and Readiness Inspections (CCRI).
Prepare detailed technical reports and briefings for senior leadership on cybersecurity findings and progress.
The company is a partner organization focused on cybersecurity and mission-critical IT environments. They offer a remote work culture and support complex security initiatives for government and enterprise clients.
Manage and maintain version control of all documentation related to compliance for each standard and track implementation status of security controls.
Oversee preparation and execution of external compliance audits, including facilitating security assessments.
Support mapping of compliance requirements to security control implementation using agile development processes.
Hypori is a high-growth cybersecurity SaaS company providing a virtual workspace platform for secure mobile access. Backed by $55M in funding, the company is expanding into commercial and regulated markets with a focus on innovation and security.
Own the design and implementation of Onebrief's GRC framework across RMF, FedRAMP, CMMC, SOC 2, and other applicable standards.
Build and manage the control environment, including policies, procedures, and evidence collection systems.
Design and implement technical security controls in partnership with Product, Engineering, Infrastructure and Corporate IT.
Onebrief builds collaboration and AI-powered workflow software for military planning and operational coordination. Founded in 2019 and valued at over $2 billion, the company is a distributed team of builders from military, operational, and technology backgrounds.
Lead FedRAMP Moderate and CMMC readiness assessments, including system boundary validation and control gap analysis.
Design and implement cloud security architectures aligned to NIST 800-53 and NIST 800-171 requirements.
Develop and own System Security Plans (SSPs), control narratives, and compliance documentation.
Riveron helps organizations implement leading governance, risk and compliance practices with a hands-on approach. The company fosters an entrepreneurial culture with collaboration and diverse perspectives, offering flexible work and progressive benefits.
Manage and implement complex controls frameworks for large systems consisting of Cloud infrastructure and SaaS services.
Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
Conduct risk assessments across business units and processes, identifying risk findings and recommending remediation strategies.
Virtru is a data protection platform that enables secure sharing without sacrificing security or privacy. Backed by top venture capital firms, the company helps Fortune 500 companies and government agencies achieve true data security with freedom to share.
Provide RMF security artifacts for ARTRANS programs to inherit NIST 800-53 controls.
Maintain STIG/SRG checklists and monthly status reports.
Evaluate risk assessments and develop plans for full inheritance from DevSecOps pipeline.
DecisionPoint Corporation provides IT and cloud services, specializing in DevSecOps platforms and security compliance. They are a mid-sized company with a focus on supporting government programs through robust security practices.
Own FedRAMP and GovRAMP certifications and roadmaps, including package management and compliance timelines.
Manage 3PAO relationships and assessments, coordinating scoping, evidence, and results validation.
Lead continuous monitoring, POA&M processes, and drive compliance automation and efficiency.
Smartsheet empowers teams to manage work seamlessly and scale solutions smarter, now uniting human teams with AI agents. It is an equal opportunity employer committed to fostering an inclusive environment with the best employees.