Capital OneNYSE: COF: Financial services offering credit cards, banking, and loans.
4+ YOE4+ years in cyber security domains; 4+ years in GRC/compliance; high school diploma or equivalent; preferred BS degree; CISSP/CISM/CRISC certifications.
NIST CSF, NIST 800-53, ISO 27000-1, PCI DSS, FFIEC
Information System Security Officer (ISSO) - Hybrid
Washington, District of Columbia, United States
HybridFull Time
Coalfire: Provides professional cybersecurity advisory, assessment, and engineering services.
5+ YOE5+ years ISSO experience performing security assessments, RMF A&A, security documentation (SSP,SIA,POA&M), continuous monitoring, and advising system owners; bachelor’s in IT, CRISC/CISM/CISSP preferred.
Capital OneNYSE: COF: Provides credit card, banking, and auto loan services.
3+ YOERequires 3+ years in cybersecurity, technology, consulting, audit, or risk management and 1+ year in identity and access management; preferred certifications include CISSP, CISA, CRISC, CISM, CIAM, CIMP, or AIGP.
Identity Governance & Administration, Privileged Access Management, Entitlement Management, Single Sign-On (SSO), Multi-Factor Authentication (MFA), Segregation of Duties (SOD)
Presidio: Global provider of cloud, cybersecurity, and digital infrastructure solutions.
5+ YOE5+ years in IT security/managed security services, bachelor's degree or equivalent, working knowledge of security technologies and vendor products, professional security certifications highly desirable (CISSP, CISM, CRISC, CISA, GIAC).
Covington & Burling: Global law firm providing legal and regulatory counseling services.
15+ YOE10+ Mgmt15+ years cybersecurity experience with 10+ years running GRC functions; Bachelor's required; CISSP/CISM/CRISC/CISA preferred; experience with NIST, ISO 27001, GDPR, HIPAA, CMMC; strong communication and stakeholder leadership.
GRC, NIST CSF, ISO 27001, EU/UK GDPR, HIPAA, CMMC, ITAR/EAR
Valiant Solutions: Provides cybersecurity and IT services to federal government agencies.
6+ YOEU.S. citizen with 6+ years cybersecurity experience, OS and networking knowledge, Tenable/AquaSec/CDM experience, GCIH/CISSP/CISM/CRISC certification, POA&M and dashboarding experience, and ability to coordinate across security and engineering teams.
CVP: Provides technology and strategy consulting services to federal agencies.
6+ YOE6+ years cybersecurity experience, FISMA/FedRAMP A&A background, experience with risk assessments, security controls, POA&Ms, and team leadership; one of CISSP/CISA/CISM/CRISC required; familiarity with ITIL, GRC, and continuous monitoring tools.
GAMA-1 Technologies: Provides IT, cloud, and security services to federal agencies.
5+ YOEBachelor's degree, 5+ years AWS cloud security experience, hands-on with CloudFormation/IaC, Splunk/Nessus/Tenable, AWS security services, and must hold one of CISA/CRISC/CISM/CGEIT/CISSP/CAP; able to obtain security clearance.
VHC Health: Community health system providing comprehensive medical and hospital services.
10+ YOE5+ MgmtLeads healthcare organization's GRC program; 10+ years in IT security/risk/compliance; 5+ years in leadership in healthcare or regulated settings; HIPAA/HITECH, NIST/HITRUST/ISO knowledge; CISSP/CISM/CISA/CRISC and HCISPP/HITRUST CCSFP preferred.
Northern Virginia Electric Cooperative: Provides electric distribution and utility services in Northern Virginia.
7+ YOEBachelor's in CS/IT required; 7+ years cybersecurity experience with 3+ years in OT/ICS; experience managing technical teams; knowledge of NERC CIP/NIST, ITIL, SCADA, SIEM, and OT security tools; CISSP/CISM/CRISC/CSSA/SCADA preferred.
Koniag Government Services: Providing technical and professional services to federal agencies.
5+ YOEBachelor's degree, 5+ years in AI governance/technology policy or risk management, knowledge of federal AI policies and NIST AI RMF, ability to obtain Public Trust, and relevant certifications (CISSP,CIPP/G,PMP,CRISC or NIST AI RMF credentials).
TensorFlow, PyTorch, Scikit-learn, AWS SageMaker, Azure Machine Learning, Google Vertex AI, SHAP, LIME, NIST AI RMF
Kearney & Company: Provides financial, accounting, and consulting services to federal agencies.
4+ YOEBachelor's degree, 4+ years in IT risk/technology advisory/internal IT audit, experience with ITGCs and control assessments, client-facing consulting skills, ability to obtain US security clearance, and at least one professional certification (CISA/CISSP/CRISC/CGEIT/Security+/CPA).
VerisignNASDAQ: VRSN: Provides internet domain name registry and DNS infrastructure services.
8+ YOE2+ Mgmt8+ years in information security governance, risk, or compliance; 4+ years security control assessment; 2+ years managing staff; bachelor\u0002s in related field or equivalent; expertise with CIS, SOC 2/3, NIST frameworks; CISSP/CISA/CISM/CRISC preferred.
Metropolitan Washington Airports Authority: Operates major airports and transportation infrastructure in Washington, D.C.
5+ YOEFive years in cybersecurity compliance, governance, risk management, information security, internal audit, or regulatory compliance; bachelor's degree preferred or equivalent experience; driver's license required.
National Institute of Standards and Technology (NIST), Payment Card Industry Data Security Standard (PCI DSS), ISO 27001, CJIS, Health Insurance Portability and Accountability Act (HIPAA), Certified Information Systems Auditor (CISA), CRISC, CISM, CISSP
Prince George's County Government: Local government providing administrative and public services to residents.
Prince George's County resident, age 18–24 by October 1, 2026, GPA of 2.5 or higher, prior SYEP participation, interview, and possible assessment, background check, or driver's license by discipline.
Microsoft Excel, Microsoft Office Suite, Microsoft 365 Fundamentals, CISM, CRISC, CCNA, CCT, CSM, CompTIA A+
QTS Data Centers: Operates and provides large-scale data center colocation and infrastructure.
7+ YOE3+ MgmtBachelor’s degree or equivalent experience; 7+ years in enterprise technology, governance, or risk and controls; 3+ years leading technical teams; IAM, DLP, audited environments, vendors, budgets, and process improvement experience.
SailPoint, Saviynt, Okta, Microsoft Entra ID Governance, Veza, Microsoft Purview, Zscaler, Netskope, Microsoft Entra, Intune, ServiceNow, PMP, Lean Six Sigma, ITIL 4, CRISC, CGEIT, Five Whys