Creative Information Technology: Provides IT solutions and software for government and healthcare sectors.
1+ YOE1 year information security/IT/GRC experience preferred; bachelor\u0002s degree in related field preferred; experience with ServiceNow and Office 365; knowledge of NIST, risk scoring, HIPAA; certifications earn points.
CGINYSE: GIB: Provides information technology and business consulting services.
9+ YOEBachelor's in cyber field, 9+ years relevant experience, experience with ServiceNow/Archer/eMASS, RMF automation, FAIR, AI governance familiarity, strong communication and executive engagement skills.
Agency: Automates cybersecurity compliance and managed security operations for startups.
6+ YOE4+ Mgmt6+ years GRC/cybersecurity experience with 4+ years managing teams; experience with SOC 2, ISO 27001, NIST frameworks, audit readiness, client advisory, and project delivery; strong communication and project management skills; in-person from Richmond, VA.
New York City or Maryland or Massachusetts or Virginia or Georgia or New York
$97k-$184k/yrOnsiteFull Time
Chainalysis: Blockchain data platform for cryptocurrency investigation and compliance.
Experience implementing and operating security and compliance controls in cloud/SaaS environments; built evidence collection, control testing, or remediation workflows; supported SOC 2/ISO 27001 or similar; strong written/verbal communication; US citizenship required.
CoStar GroupNASDAQ: CSGP: Global provider of commercial and residential real estate data.
1+ YOEBachelor's degree,1+ year experience in IT/audit/compliance or related role; knowledge of core security concepts, strong written communication, organizational skills, and curiosity about cybersecurity.
CoStar GroupNASDAQ: CSGP: Provides global real estate information, analytics, and online marketplaces.
1+ YOEBachelor's degree,1+ year experience in IT/audit/compliance/info security,knowledge of core security concepts,excellent written communication,organizational skills,curiosity about cybersecurity.
CapTech: Provides technology and management consulting services to large enterprises.
6+ YOE6+ years in information security/GRC/IT audit with experience owning SOC 2, NIST 800-53, or NIST AI RMF; CRISC or CISM (or to be attained); strong executive communication and automation experience.
Digital Global Connectors: Provides cybersecurity, engineering, and compliance services to federal agencies.
5+ YOEBachelor's degree, 5+ years performing RMF/GRC security control assessments using NIST SP 800-53, experience supporting ATO and continuous monitoring, strong technical writing and analytical skills, U.S. citizenship and ability to obtain Tier 2 Public Trust.
Risk Consulting - Risk Technology - Oracle GRC - Manager (New York, NY, US, 10001-8604)
New York or Atlanta or Boston or Chicago or Cleveland or Dallas or Detroit or Pittsburgh or Hoboken or Houston or Los Angeles or McLean or Miami or Minneapolis or North Carolina or Philadelphia or Portland or San Francisco or Seattle or Tampa
$150k-$260k/yrHybridFull Time
EY: Global firm providing audit, tax, and professional consulting services.
5+ YOEBachelor's or master's degree with ~5 years related experience; Oracle security/controls and controls testing experience; strong project management, client service, leadership, communication, analytical skills; valid US driver’s license and passport; willing to travel.
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
8+ YOE8+ years in ISSO/SCA/ISSE/ISSM roles, experience configuring and automating GRC platforms (ServiceNow, Archer, Xacta, eMASS), knowledge of NIST frameworks and federal security standards, HS diploma/GED, U.S. citizenship required.
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
8+ YOE8+ years in ISSO/SCA/ISSE/ISSM roles; experience configuring and automating GRC platforms (ServiceNow, Archer, Xacta, eMASS); strong process/change management, policy-to-implementation translation, and knowledge of NIST RMF/FISMA/FedRAMP; U.S. citizenship required.
ServiceNow, Archer, RSA Archer, Xacta, Telos Xacta, eMASS, CSAM, API
COMPLIANCE DATA ARCHITECT / GRC RECONILIATION ENGINEER
Arlington or Alexandria
$145k-$180k/yrHybridFull Time
Zermount: Provider of cybersecurity and IT solutions to government agencies.
15+ YOE15+ years in database/data architecture across cloud and on-prem, strong data modeling, ETL and reconciliation, hands-on NIST SP 800-53 and POA&M/ATO experience, T-SQL and PowerShell skills, attention to detail.
Guidehouse: Provides management and technology consulting services to diverse organizations.
3+ YOE3+ years in cybersecurity or IT risk management; Bachelor's degree; ability to obtain Public Trust; experience with GRC, NIST SP 800-53, FISMA; strong communication and analytical skills.
AptNexus: A provider of information technology and security services.
7+ YOESenior ISSO with 7-10 years in federal or federal contractor environment; proficient in RMF/NIST controls; SA&A packaging; GRC tools; cloud security; active Secret clearance.
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
5+ YOE5+ years compliance, audit, or risk management experience; Bachelor’s degree or equivalent required; deep knowledge of COSO 2013, SEC/PCAOB, ITGCs, SOX scoping, control design, testing, remediation, and GRC platforms.
Asurion: Provides insurance and repair services for consumer electronics.
15+ YOE12+ MgmtMaster's preferred; 15+ years cybersecurity/technology risk experience and 12+ years leading teams; deep governance, GRC/TPRM, third-party risk, audit, and security awareness expertise; strong executive communication.
TelosNASDAQ: TLS: Provides cyber, cloud, and enterprise security solutions for government and commercial clients.
5+ YOEActive TS/SCI clearance and US citizenship, 5+ years IT experience (degree may be substituted), DOD 8140 eligibility, cloud provider experience (AWS/Azure/GCP), RMF/GRC and audit experience, strong analytical and communication skills.
VHC Health: Community health system providing comprehensive medical and hospital services.
10+ YOE5+ MgmtLeads healthcare organization's GRC program; 10+ years in IT security/risk/compliance; 5+ years in leadership in healthcare or regulated settings; HIPAA/HITECH, NIST/HITRUST/ISO knowledge; CISSP/CISM/CISA/CRISC and HCISPP/HITRUST CCSFP preferred.