Arlington or Washington or Springfield or Chantilly or Tysons Corner
$105k-$200k/yrHybridFull Time
Technomics: Provides cost analysis and decision support services for government.
10+ YOE10+ years cyber risk assessment experience; deep knowledge of NIST SP 800-30, RMF, MITRE ATT&CK; strong writing/briefing skills; ability to obtain/hold DOE Q clearance; travel to client sites.
Asurion: Provides insurance and repair services for consumer electronics.
10+ YOE5+ Mgmt10+ years in cybersecurity/IT risk or GRC with 5+ years leading managers; bachelor’s or equivalent; deep knowledge of NIST CSF 2.0 and ISO 27001/27005; GRC platform and risk-quantification experience; strong executive communication.
Capital OneNYSE: COF: Financial services offering credit cards, banking, and loans.
4+ YOE4+ MgmtRequires 4+ years in technology, cybersecurity, consulting, audit, or risk management and 4+ years managing multiple projects or initiatives; risk frameworks and financial services experience preferred.
Capital OneNYSE: COF: Provides credit card, banking, and auto loan services.
5+ YOEBachelor's degree or military experience and 5+ years of program or project management experience; technology risk, audit, frameworks, ITGC, cloud governance, and AWS experience preferred.
Capital OneNYSE: COF: A diversified financial services providing banking and credit products.
4+ YOERequires 4+ years in technology, cybersecurity, consulting, audit, or risk management and 4+ years managing multiple projects or initiatives. Risk framework experience required; CISSP, CISA, CRISC, or CISM preferred.
VP - Cyber, Technology, and Information Risk Manager
Alpharetta or Baltimore
$95k-$165k/yrOnsiteFull Time
Morgan StanleyNYSE: MS: Global financial services firm providing investment and wealth management.
8+ YOEDegree required (risk/computer/IT/cyber preferred), 8+ years relevant experience, familiarity with CTIS frameworks (CRI, NIST CSF, ISO 27001, CIS Controls), strong analytical and communication skills.
Steampunk: Federal digital transformation and consulting services provider.
6+ YOEAbility to obtain U.S. security clearance; 6–12 years cybersecurity/FISMA experience depending on degree; professional certification required (CISSP,CASP,CISA,CISM or GSLC); strong RMF, FedRAMP, cloud security, and continuous monitoring experience.
CyberLinx Solutions: Provides specialized cybersecurity and IT services to federal agencies.
8+ YOE3+ MgmtBachelor's in a related field, 8+ years in cybersecurity with 3+ years of GRC leadership, strong knowledge of NIST CSF/RMF and NIST SP 800-53/800-171, audit/compliance experience, and executive communication skills.
Covington & Burling: Global law firm providing legal and regulatory counseling services.
15+ YOE10+ Mgmt15+ years cybersecurity experience with 10+ years running GRC functions; Bachelor's required; CISSP/CISM/CRISC/CISA preferred; experience with NIST, ISO 27001, GDPR, HIPAA, CMMC; strong communication and stakeholder leadership.
GRC, NIST CSF, ISO 27001, EU/UK GDPR, HIPAA, CMMC, ITAR/EAR
New York City or Chicago or Washington or Dallas or Houston or Boston or San Francisco or Atlanta
OnsiteFull Time
Kroll: Provides global risk and financial advisory solutions.
15+ YOEBachelor’s degree and 15+ years in cybersecurity consulting, advisory, or risk management; 7+ years with private equity; executive relationships, revenue generation, team leadership, and cyber due diligence expertise.
Brown Advisory: Provides investment management and financial advisory services to global clients.
3+ YOE3–6 years in cyber GRC, information security, technology risk, IT audit, compliance, or control management preferred; knowledge of security frameworks and GRC platforms required.
Vanta, Archer, ServiceNow GRC, OneTrust, Drata, ISO 27001, SOC 2, NIST CSF, CIS Controls, Microsoft Excel
Redhorse: Delivering data insights and technology solutions to government agencies.
8+ YOEActive TS/SCI with Polygraph required,8+ years cyber security experience with penetration testing,expertise in Linux/Windows/hypervisors,network analysis,security architecture,and risk mitigation.
Clark Creative Solutions: Provides professional services and IT solutions to government agencies.
5+ YOEBachelor's degree,5+ years relevant experience,active Top Secret/SCI clearance,knowledge of cybersecurity principles,Risk Management Framework (RMF),NIST guidance,cyber policy development and readiness reporting.
JPMorgan ChaseNYSE: JPM: Global financial services firm providing banking and investment solutions.
5+ YOECybersecurity training or certification and 5+ years in threat intelligence, supplier risk, or cyber operations; requires threat hunting, OSINT, risk assessment, communication, scripting, and SIEM expertise.
Python, Bash, JavaScript, PowerShell, Security Information and Event Management (SIEM), Splunk, Elasticsearch, ISO 27001, NIST Cybersecurity Framework, MITRE ATT&CK, Open-Source Intelligence (OSINT)
Systems Planning and Analysis: Provides technical and analytical support to national security agencies.
8+ YOEBachelor's in a technical field, 8+ years in cyber operations/engineering or cyber risk for mission-critical DoD/IC systems, experience with resiliency/survivability assessments, RMF/eMASS/IAVM/NIST application, and active TS/SCI clearance.
DCCA: Provides IT and engineering solutions for government and defense agencies.
Experience in cyber/InfoSec, vulnerability scanning and testing, risk assessment and accreditation, Linux, technical writing, and communicating with technical and non-technical stakeholders.
Annapolis Junction or Roy or San Antonio or Redondo Beach or Huntsville or San Diego or Colorado Springs
$195k-$292k/yrOnsiteFull Time
Northrop GrummanNYSE: NOC: Develops and manufactures advanced aerospace, defense, and space systems.
12+ YOERequires Secret clearance, DoD 8570 IASAE Level II (CISSP), NIST SP 800-160 and RMF experience, systems engineering background, ability to produce RMF documentation and assess cyber risk; bachelor\u0002s+ experience alternatives accepted.
NIST SP 800-160, DoD 8570, DoD 8510, AFI 17-101, CNSSI 1253, DOORS, CAMEO, SonarQube, Fortify, DevSecOps, Agile, RMF
Peraton: National security and mission-critical government technology services provider.
3+ YOERequires 3–12+ years depending on degree, cloud data warehousing and BDP experience, BDP parser development, Kafka, Apache NiFi, cloud storage, SQL/NoSQL, cyber operations expertise, U.S. citizenship, and active or obtainable TS/SCI clearance.
Big Data Platform (BDP), Kafka, Apache NiFi, SQL, NoSQL, Task Management Tool (TMT)