Job Closed

This listing is no longer active.

Securitize

Securitize is a leader in real-world asset tokenization, providing institutional-grade infrastructure that bridges traditional finance and decentralized finance. The company enable

Chief Information Security Officer

Location

United States

Posted

44 days ago

Salary

0

Seniority

Lead

Job Description

Chief Information Security Officer

Securitize

Securitize, the leader in tokenizing real-world assets with $3.7B+ AUM (as of May 5, 2025), is bringing the world on-chain through tokenized funds in partnership with top-tier asset managers, such as Apollo, BlackRock, Hamilton Lane, KKR, and others. Securitize, through its subsidiaries, is a SEC-registered broker dealer, digital transfer agent, fund administrator, and operator of a SEC-regulated Alternative Trading System (ATS). Securitize is a global, fully remote team consisting of top talent from the blockchain and financial services industries. Having raised $170M overall to date, we are backed by some of the largest names in finance and technology, including BlackRock, Morgan Stanley, Blockchain Capital, MUFG, Sumitomo Mitsui Trust Bank, Sony Finance, Banco Santander, Coinbase, among others. Securitize has also been recognized as a 2025 Forbes Top 50 Fintech company. Before applying, we encourage you to visit us to learn more: Website | X/Twitter | LinkedIn Role Overview We are looking for a Chief Information Security Officer (CISO) to lead the company’s information security, IT operations, and technical compliance functions. This role is strategic and hands-on, combining executive-level ownership of security and compliance with operational responsibility for corporate IT. The CISO will ensure the company meets regulatory, audit, and security obligations while enabling the business to scale safely across regulated entities, funds, and tokenized products. The CISO reports directly to the CEO, with a dotted-line relationship to the CTO / CPO organization, reflecting the strong collaboration required with Product & Engineering. Scope of Responsibilities 1. Corporate IT Operations & Support Own and operate the company’s internal IT environment and end-user services across all business units and regulated entities, including: - Endpoint lifecycle management (laptops, mobile devices, accessories) - IT onboarding and offboarding processes - Identity and Access Management (IAM) and RBAC for corporate systems - Email, productivity, and collaboration tools - Helpdesk and Tier 1 / Tier 2 support operations - Software asset management and license compliance - Endpoint security tooling (EDR, MDM, antivirus, DLP) - Employee security awareness and phishing training - IT support for regulatory exams, subpoenas, and information requests 2. Information Security Governance & Risk Management Define and own the company-wide security framework, policies, and risk posture, including: - Corporate security policies (acceptable use, access control, incident response, vendor risk, etc.) - Vendor and third-party risk management programs - Security incident response governance for corporate systems - Business continuity and disaster recovery planning (for internal systems) - Asset inventory, audit logging, and evidence management - Participation in all material security incidents and retrospectives as part of fundamental risk governance 3. Technical Compliance, Audits & Certifications Own security-related compliance and act as the primary executive counterpart for audits and regulators, including: - SOC 1 / SOC 2 readiness and ongoing compliance - SOX IT controls and coordination with Internal Controls - DORA readiness and operational resilience requirements - ISO 27001 or similar certifications (as applicable) - Regulatory security reporting and remediation management - Ownership of audit responses, findings, and corrective action plans 4. Platform Security Oversight (Tokenization & Lifecycle Management Platform) While Product & Engineering owns implementation and operations of platform security, the CISO is responsible for policy, assessment, and external defensibility of the platform’s security posture, including: - Reviewing and approving security architecture principles for the platform - Oversight of secure software development practices (DevSecOps) - Coordination and oversight of platform penetration tests - Oversight of smart contract audits and third-party security reviews - Participation in platform incident response when required - Ability to clearly explain, present, and defend platform security controls to: - Auditors - Regulators - Institutional clients and partners 5. Crypto & Tokenization Security Given the company’s core business and growing use of crypto assets, the CISO must bring hands-on expertise in digital asset security, including: - Private key management models - MPC-based custody and signing infrastructures - Secure operational processes for crypto asset handling - Policy definition for wallets, signing authorities, and access controls - Risk assessments related to on-chain activity and smart contracts - Oversight of crypto-specific incident response scenarios Experience Must-have - Senior leadership experience in Information Security (CISO, VP Security, or equivalent) - Proven ownership of audits and certifications (SOC, SOX, ISO, regulatory exams) - Strong understanding of cloud security (AWS or equivalent) - Direct experience with: - Crypto assets - Private key management - MPC or HSM-based infrastructures - Smart contract audits and security reviews - Ability to operate credibly with: - Regulators - Auditors - Institutional partners - Experience operating in regulated financial environment Nice-to-have - Experience in fintech, capital markets, or digital securities - Familiarity with SEC-regulated entities and fund structures - Experience scaling security orgs in fast-growing companies Why Join Us? Become a part of our rapidly expanding organization and enjoy a supportive and rewarding work environment: - Flexible Paid Time Off – Promoting a healthy work-life balance. - Equity Grant Opportunities – Share in the success and future growth of the company. - Remote Work Flexibility – Work from anywhere while staying connected with a dynamic and collaborative team. Additional Benefits for US employees - Comprehensive Insurance Coverage – Employer-paid Medical, Dental, and Vision benefits for you and your family. - 401(k) Retirement Plan – Secure your financial future with employer-sponsored savings. Securitize is an equal opportunity employer and is committed to fostering a diverse, inclusive, and equitable workplace. We consider all qualified applicants for employment without regard to race, color, religion, sex, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital or family status, or any other characteristic protected by applicable law. All employment decisions at Securitize are based on job-related qualifications, merit, and business needs. We welcome candidates from all backgrounds, experiences, and perspectives to apply.

Related Categories

Related Job Pages

More Security Engineer Jobs

Account Director - National Security

TRM Labs

TRM Labs specializes in blockchain investigations and risk management, empowering organizations to detect, investigate, and prevent crypto-related fraud and financial crime. Founde

Build a Safer World. TRM Labs provides blockchain analytics and AI solutions to help law enforcement and national security agencies, financial institutions, and cryptocurrency businesses detect, investigate, and disrupt crypto-related fraud and financial crime. TRM’s blockchain intelligence and AI platforms include solutions to trace the source and destination of funds, identify illicit activity, build cases, and construct an operating picture of threats. TRM is trusted by leading agencies and businesses worldwide who rely on TRM to enable a safer, more secure world for all. The Sales Account Director for US National Security will join a team driving TRM’s crypto go-to-market strategy in the US Public Sector market. Their goal will be to increase and strengthen our foothold in the space. We're looking for a customer-obsessed, consultative salesperson to own the entire sales process with new and existing customers. This person will be knowledgeable about the cryptocurrency ecosystem and feel comfortable navigating complex US Public Sector processes to close six- and seven-figure deals. Responsibilities: - Account mapping - Connect with all the current key stakeholders within an account and identify what matters to them, what are their potential use cases, who holds budgets, who makes decisions, who influences decisions, who owns which process - Prospecting - Discover new stakeholders across an account and identify what matters to them, what are their potential use cases, who holds budgets, who makes decisions, who influences decisions, who owns which process - Nurturing - Own, plan, execute, and/or quarterback activities to nurture client relationships, feedback loops, referrals, renewals, upsells, cross-sells, expansions - Account planning - Create and execute strategic plans for every account to not only ensure company goals are met across key revenue and churn metrics, but also new growth opportunities are discovered and pursued - Product & subject matter expertise - Hone TRM product & customer vertical subject matter expertise to enrich every stage of the sales process from demonstrations to trial to customer advisory sessions to innovation workshops - Customer advocacy - Pro-actively gather and prioritize customer feedback and champion it within TRM - Loyalty - Develop a roster of happy customers that will refer new prospects, champion TRM, and provide crucial feedback Preferred Qualifications: - 5+ years of B2G SaaS sales experience with a demonstrated ability to consistently deliver against net new sales targets. - Strong customer-facing presentation/listening skills with the aptitude to establish credibility with senior financial and compliance executives. - Natural storyteller with the capacity to understand customer needs and convey compelling value propositions. - Exceptional communication and problem-solving skills. - Strong knowledge of cryptocurrencies, digital assets, and/or blockchains. - Familiarity with regulatory initiatives and changes related to cryptocurrency; understanding of Anti-Money Laundering (AML) and Know Your Customer (KYC) regulatory frameworks. - Previous experience working in a fast-paced, growing startup environment. - Experience selling into US National Security and Public Sector organizations. - TS/SCI with Full Scope Polygraph clearance required. - Individual pay is determined by skills, qualifications, experience, and location. The following represents the expected range of compensation for this role: - The estimated on target earnings (base and variable commission) for this role is $293,334 - $376,666. - Additionally, this role may be eligible to participate in TRM’s equity plan. Life at TRM We are building a safer world. That promise shows up in how we work every day. TRM moves quickly. We are a high velocity, high ownership team that expects clarity, follow-through, and impact. People who thrive here are energized by hard problems, experimentation, and continuous feedback. If something takes months elsewhere, it will ship here in days. Our work sits at the intersection of AI, national security, and fighting financial crime. The problems are complex, the stakes are real, and the environment evolves quickly. The pace and intensity of the work reflect the importance of the mission. As a result, the way we operate requires a high level of ownership, adaptability, collaboration, and creative problem-solving. At TRM, you should expect: - Priorities and targets to change quickly as we experiment and iterate - Work that often requires operating with a high degree of ambiguity - A high level of personal ownership and accountability - Close collaboration across teams and functions - Frequent, high-touch communication - Creative problem solving and out-of-the-box thinking - A pace that rewards urgency, adaptability, and outcomes This environment is energizing for people who enjoy building, solving hard problems, and making progress in situations that are not always fully defined. It also requires comfort navigating ambiguity, adjusting course as new information emerges, and maintaining focus and positivity in a fast-moving and intense environment. We also recognize that this style of operating is not for everyone. If you are primarily optimizing for predictability or a consistently balanced workload, we encourage you to use the interview process to pressure test whether this environment is truly the right fit. We want teammates who thrive here, not just survive here. At the same time, many people find this work deeply rewarding. If you are excited by meaningful problems, motivated by ambitious goals, and energized by working alongside mission-driven colleagues, there is a good chance you will find TRM to be an exceptional place to grow and contribute. Learn more: Interviewing at TRM: How We Hire and What Success Looks Like AI Fluency at TRM AI fluency is a baseline expectation at TRM. We believe AI meaningfully changes how top performers operate. We expect every team member to use AI to accelerate and reimagine their craft, not just automate surface tasks. At TRM, AI fluency means you are among the top 10 percent of operators in your function in how you apply AI to: - Accelerate repeatable workflows - Structure and solve problems - Improve output quality - Increase speed and leverage You will be evaluated on applied AI fluency during the interview process. Leadership Principles We hire and grow against three leadership principles. They’re the standards for how we operate, treat each other, and make decisions. - Impact-Oriented Trailblazer: We put customers first and move with speed, focus, and adaptability. We treat every plan like an experiment – test, ship, measure, and iterate quickly. - Master Craftsperson: We care deeply about our craft. We balance speed with high standards, own outcomes end‑to‑end, and invest in getting better everyday. - Inspiring Colleague: We add clarity and energy, not noise. We bring humility, candor, and a one‑team mindset — giving and receiving feedback to make the team stronger. Join our Mission At TRM we care deeply about our craft. We are looking for individuals who want their work to matter, who experiment with speed and rigor, and who take pride in building a safer world for billions of people. If you’re excited by TRM’s mission but don’t check every box, we encourage you to apply — we hire for slope, judgment, and the will to learn fast. TRM is a Series C company with $220M in total funding, backed by Blockchain Capital, Goldman Sachs, Bessemer, Y Combinator, Thoma Bravo, and others. Headquartered in San Francisco, TRM operates as a distributed-first company with hubs in Los Angeles, San Francisco, New York, Washington D.C., London, and Singapore. Privacy Policy and Additional Information By submitting your application, you are agreeing to allow TRM to process your personal information in accordance with the TRM Privacy Policy. Our typical hiring cycles for specialized roles span 24 to 36 months. Accordingly, we retain your personal information for up to 36 months to evaluate your application and to consider you for current and future employment opportunities, unless you request earlier deletion or a different retention period is required or permitted by law. To notify TRM Labs that you believe this job posting is non-compliant, please submit a report through this form. No response will be provided to inquiries unrelated to job posting compliance. The use of AI tools of any kind (including but not limited to notetakers, interview assistants, and real-time coaching tools such as Otter.ai, Fireflies, Fathom, Cluey, or similar) during TRM interviews is not permitted without prior approval from TRM. TRM uses its own internal tools for note-taking to ensure a consistent and confidential experience for all candidates. We are committed to providing reasonable accommodations to applicants with disabilities, and requests can be made via this form. Recruitment agencies TRM Labs does not accept unsolicited agency resumes. Please do not forward resumes to TRM employees. TRM Labs is not responsible for any fees related to unsolicited resumes and will not pay fees to any third-party agency or company without a signed agreement. Learn More: Company Values | Interviewing | FAQs

United States
$293K - $376K / year
Electrosoft logo

Senior Cybersecurity Auditor

Electrosoft

Electrosoft Services, Inc. is an award-winning company that provides comprehensive technology-based solutions and services to federal customers. While cybersecurity is our specialty, we also focus on ICAM, enterprise IT modernization, and software solutions. We always seek to delight our customers, so we retain highly qualified employees and offer them meaningful work, growth opportunities, and work-life balance. What sets us apart from all other contractors is the sense of teamwork our employees feel – and the knowledge that outstanding effort is recognized and rewarded. The camaraderie we share emanates from Lunch & Learn sessions where we explore new ideas together, fun group activities ranging from escape rooms to miniature golf, and much, much more. If we’ve described you and your dream workplace, please apply and share in the many benefits and opportunities we offer.

Full TimeRemoteTeam 51-200

Electrosoft Services, Inc. is an award-winning company that provides comprehensive technology-based solutions and services to federal customers. While cybersecurity is our specialty, we also focus on ICAM, enterprise IT modernization, and software solutions. We always seek to delight our customers, so we retain highly qualified employees and offer them meaningful work, growth opportunities, and work-life balance. What sets us apart from all other contractors is the sense of teamwork our employees feel – and the knowledge that outstanding effort is recognized and rewarded. The camaraderie we share emanates from Lunch & Learn sessions where we explore new ideas together, fun group activities ranging from escape rooms to miniature golf, and much, much more. If we’ve described you and your dream workplace, please apply and share in the many benefits and opportunities we offer. Senior Cybersecurity Auditor Responsibilities and Duties: Independently performs complex security analysis of classified and unclassified applications, systems, and enclaves for compliance with security requirements. Performs Command Cyber Readiness Inspections and cybersecurity vulnerability evaluations. Uses a variety of security techniques, technologies, and tools to evaluate security posture in highly complex computer systems and networks. Performs vulnerability and risk analysis and participates in a variety of computer security penetration studies. Analyzes and defines security requirements for computer and networking systems, to include mainframes, workstations, and personal computers. Recommends solutions to meet security requirements. Gathers and organizes technical information about an organization's mission goals and needs and makes recommendations to improve existing security posture. Provides enterprise-wide technical analysis and direction for problem definition, analysis and remediation for complex systems and enclaves. Provides workable recommendations and advice to client executive management on system improvements, optimization, and maintenance in the following areas: Information Systems Architecture, Automation, Telecommunications, Networking, Communication Protocols, Application Software, Electronic Email, VOIP and VTC. Competence to work at the highest level of all phases of information systems auditing. Basic Qualifications: - Associates or higher degree preferred - Proven proficiency performing CCRI/ vulnerability assessment/ penetration testing on networks, databases, computer applications and IT frameworks. - Seven (7) years of IT experience - Five (5) years of cybersecurity experience - Strong analytical and problem-solving skills for resolving security issues. - Strong skills implementing and configuring networks and networks components. - Command Cyber Readiness Inspection certification or equivalent in at least one of the following areas: - Nessus Scan Analysis - Operating Systems (Windows, Unix) - Boundary Defense) Network Policy, Router, Firewall) - Internal Defense (L2 Switch, L3 Switch) - DNS (Policy, BIND/Windows) - HBSS (remote console, AV, ABM, PA HIPS, ePO) - Traditional Security (Common, Basic, NCV, SCV) - Wireless Communications (BES, Handhelds) - Tenable Certified NESSUS Auditory - Knowledge and understanding of DOD security regulations, DISA Security Technica Implementation Guides - Understanding of SCAP - Familiarity with AUTOCHECKLIST Tool - Knowledge of and proficiency with: - VULNERATOR - USCYBERCOM CTO Compliance Program - Wireless vulnerability assessment - Web Services (IIS, Apache, Proxy) - Database (SQL Server, Oracle) - Email Services (Exchange) - Vulnerability Scans (NESSUS, SCCM) - Knowledge of Phishing exercises - Cloud Security - Operational Technology - Artificial Intelligence - USB Detection - Physical Security - Required to possess experience as a DISA Risk Management Executive, Cyber Standards Branch Command Cyber Readiness Inspection (CCRI) or Cyber Operational Readiness Assessment (CORA) Team Lead and have a certification in penetration testing, such as: - Licensed Penetration Tester (LPT) - Certified Expert Penetration Tester (CEPT) - Certified Ethical Hacker (CEH) - Global Information Assurance Certification Penetration Tester (GPEN) - Security Clearance Level: SECRET and be eligible for an IT-II Non-Critical Sensitive security clearance or Tier 3 (T3) upon assignment.

United States
Job Closed
SkyePoint Decisions logo

Security Control Assessor

SkyePoint Decisions

SkyePoint Decisions is an established ISO 9001:2015 and ISO/IEC 27001:2013 certified small business and appraised at CMMI Level 3 for Services and Development. We possess a common vision of excellence and foster a collaborative team culture built upon individual performance and accountability. We invest in our people and systems to create value for our clients. It is the SkyePoint Way. We are grateful for the opportunity to work with exceptional people and give back to the communities we serve. Our employees value the flexibility at SkyePoint that allows them to balance quality work and their personal lives. SkyePoint Decisions is a participating E-Verify Employer. U.S. Citizenship is required for most positions. Equal Opportunity Employer/Veterans/Disabled.

Full TimeRemoteTeam 51-200

SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex challenges faced by our federal government clients. Our focus is on enabling our clients to deliver their mission most efficiently and effectively – anytime, anywhere, securely. We combine technical expertise, mission awareness, and an empowered workforce to produce meaningful results. This is a contingent position based upon customer approval. SkyePoint Decisions is seeking a Security Control Assessor to join our team supporting a government contract. This is a remote position. Responsibilities: - Provide overall SA/OSA subject matter expertise to the Information System Security and Authorization (SA) program. - Provide specific guidance and technical expertise in the form of standards, policies, procedures, and oversight for the program. - Review and provide guidance on OSA program and continuous monitoring capabilities, PIA, SSPs and identity updates to enhance the quality of these assessments. - Review and provide advice based on analysis for Privacy Impact Assessments (PIA). - Review and provide advice based on analysis for Third Party Website and Applications (TPWA). - Review and analyze all system artifacts for accuracy, completeness, in support of an authorization to operate (ATO) requests. - Review ATO packages under the RMF for customer systems and the systems of the external partners and create or updated ATO packages as necessary before submission for approval. - Create or Review ATO packages prior to submission to CISO and CIO approval. - Ensure all assessment and audit reports are uploaded properly to the FISMA Management Tool: (Cyber Security Assessment and Management (CSAM)). - Coordinate and assist with data calls and data collection efforts for compiled and managed responses from stakeholders for audit and compliance reporting. - Conduct audits of closed Plan of Actions and Milestones (POA&M) for completeness and compliance. - Support the ongoing security authorization (OA) process that includes continuous monitoring. - Provide document development support for CISO sponsored events and responses to questions and concerns. - Draft document review and feedback on application of security and privacy requirements (e.g., technical review boards, review of SSPs, RA’s, contingency plan, POA&M reports). - Track the renewal dates for the security authorizations and ongoing security authorizations to ensure the ATO renewal efforts by working with respective stakeholders, SOs, and ISSOs. - Conduct lessons learned sessions and developing best practices. Required Qualifications: - Must be able to obtain a High Risk/Public Trust Security Clearance. - Bachelor’s or equivalent and five to ten (5-10) years related experience. - At least three years of experience in a computer security incident response role. - At least three years of enterprise Linux and Windows administration. - Experience working in a Security Operations Center. - Experience with Active Directory and other enterprise credential stores. - Passion for information security and incident response. - Experience with cyber threat intelligence. - Excellent communications and interpersonal skills. - Critical thinking and problem-solving skills. - Ability to quickly learn new technologies and respond to changing requirements and environment. - Ability to work independently and in a cross functional team. - Ability to identify both tactical and strategic solutions to complex issues. - Advanced malware analysis experience, such as reverse engineering and disassembly design.  - Must be a U.S. citizen. Preferred Qualifications: - Active Secret or Top Secret security clearance. Compensation: Salary Range: $100,000-$120,000 The SkyePoint Decisions salary range for this position is a general guideline only. It represents an estimated range for this position and is just one piece of our total compensation package. Salary at SkyePoint is determined by various factors, including but not limited to location, work schedule, the candidate’s combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability, market data and business considerations. In addition to a competitive salary, SkyePoint offers benefits including a certification incentive program, PTO, floating federal holiday options, several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, Vision, ST/LT Disability, Life Insurance, and 401k matched. What We Can Offer You: - At SkyePoint, we go B.I.G. (beginning in GRATITUDE) by recognizing all we have and giving back to our employees, families, and communities. It instills a positive mindset that permeates all we do. By beginning in gratitude, SkyePoint can continue to spread living in gratitude each day. - Great Benefits: Several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, ST/LT Disability, Life Insurance, floating federal holiday options, and 401k matched - Certificate Incentive Program: To promote professional development, we recognize and reward employees who obtain new certifications aligned with business needs. - Flexible Work Environment SkyePoint Decisions is an established ISO 9001:2015 and ISO/IEC 27001:2013 certified small business and appraised at CMMI Level 3 for Services and Development. We possess a common vision of excellence and foster a collaborative team culture built upon individual performance and accountability. We invest in our people and systems to create value for our clients. It is the SkyePoint Way. We are grateful for the opportunity to work with exceptional people and give back to the communities we serve. Our employees value the flexibility at SkyePoint that allows them to balance quality work and their personal lives. SkyePoint Decisions is a participating E-Verify Employer. U.S. Citizenship is required for most positions. Equal Opportunity Employer/Veterans/Disabled. CCPA Disclosure Notice Here

United States
$100K - $120K / year
Job Closed
SkyePoint Decisions logo

Sr. Security Control Assessor

SkyePoint Decisions

SkyePoint Decisions is an established ISO 9001:2015 and ISO/IEC 27001:2013 certified small business and appraised at CMMI Level 3 for Services and Development. We possess a common vision of excellence and foster a collaborative team culture built upon individual performance and accountability. We invest in our people and systems to create value for our clients. It is the SkyePoint Way. We are grateful for the opportunity to work with exceptional people and give back to the communities we serve. Our employees value the flexibility at SkyePoint that allows them to balance quality work and their personal lives. SkyePoint Decisions is a participating E-Verify Employer. U.S. Citizenship is required for most positions. Equal Opportunity Employer/Veterans/Disabled.

Full TimeRemoteTeam 51-200

SkyePoint Decisions is a leading Cybersecurity Architecture and Engineering, Critical Infrastructure and Operations, and Applications Development and Maintenance IT service provider headquartered in Dulles, Virginia with operations across the U.S. We provide innovative enterprise-wide solutions as well as targeted services addressing the complex challenges faced by our federal government clients. Our focus is on enabling our clients to deliver their mission most efficiently and effectively – anytime, anywhere, securely. We combine technical expertise, mission awareness, and an empowered workforce to produce meaningful results. This is a contingent position based upon customer approval. SkyePoint Decisions is seeking a Sr. Security Control Assessor to join our team supporting a government contract. This is a remote position. Responsibilities: - Provide overall SA/OSA subject matter expertise to the Information System Security and Authorization (SA) program. - Provide specific guidance and technical expertise in the form of standards, policies, procedures, and oversight for the program. - Review and provide guidance on OSA program and continuous monitoring capabilities, PIA, SSPs and identity updates to enhance the quality of these assessments. - Review and provide advice based on analysis for Privacy Impact Assessments (PIA). - Review and provide advice based on analysis for Third Party Website and Applications (TPWA). - Review and analyze all system artifacts for accuracy, completeness, in support of an authorization to operate (ATO) requests. - Review ATO packages under the RMF for customer systems and the systems of the external partners and create or updated ATO packages as necessary before submission for approval. - Create or Review ATO packages prior to submission to CISO and CIO approval. - Ensure all assessment and audit reports are uploaded properly to the FISMA Management Tool: (Cyber Security Assessment and Management (CSAM)). - Coordinate and assist with data calls and data collection efforts for compiled and managed responses from stakeholders for audit and compliance reporting. - Conduct audits of closed Plan of Actions and Milestones (POA&M) for completeness and compliance. - Support the ongoing security authorization (OA) process that includes continuous monitoring. - Provide document development support for CISO sponsored events and responses to questions and concerns. - Draft document review and feedback on application of security and privacy requirements (e.g., technical review boards, review of SSPs, RA’s, contingency plan, POA&M reports). - Track the renewal dates for the security authorizations and ongoing security authorizations to ensure the ATO renewal efforts by working with respective stakeholders, SOs, and ISSOs. - Conduct lessons learned sessions and developing best practices. Required Qualifications: - Must be able to obtain a High Risk/Public Trust Security Clearance. - Bachelor’s or equivalent and five to ten (5-10) years related experience. - At least three years of experience in a computer security incident response role. - At least three years of enterprise Linux and Windows administration. - Experience working in a Security Operations Center. - Experience with Active Directory and other enterprise credential stores. - Passion for information security and incident response. - Experience with cyber threat intelligence. - Excellent communications and interpersonal skills. - Critical thinking and problem-solving skills. - Ability to quickly learn new technologies and respond to changing requirements and environment. - Ability to work independently and in a cross functional team. - Ability to identify both tactical and strategic solutions to complex issues. - Advanced malware analysis experience, such as reverse engineering and disassembly design.  - Must be a U.S. citizen. Preferred Qualifications: - Active Secret or Top Secret security clearance. Compensation: Salary Range: $100,000-$120,000 The SkyePoint Decisions salary range for this position is a general guideline only. It represents an estimated range for this position and is just one piece of our total compensation package. Salary at SkyePoint is determined by various factors, including but not limited to location, work schedule, the candidate’s combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability, market data and business considerations. In addition to a competitive salary, SkyePoint offers benefits including a certification incentive program, PTO, floating federal holiday options, several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, Vision, ST/LT Disability, Life Insurance, and 401k matched. What We Can Offer You: - At SkyePoint, we go B.I.G. (beginning in GRATITUDE) by recognizing all we have and giving back to our employees, families, and communities. It instills a positive mindset that permeates all we do. By beginning in gratitude, SkyePoint can continue to spread living in gratitude each day. - Great Benefits: Several insurance options including HMO and High Deductible plans with Health Savings Accounts [HSAs], Flex Spending Accounts [FSAs], Full Dental Plans, ST/LT Disability, Life Insurance, floating federal holiday options, and 401k matched - Certificate Incentive Program: To promote professional development, we recognize and reward employees who obtain new certifications aligned with business needs. - Flexible Work Environment SkyePoint Decisions is an established ISO 9001:2015 and ISO/IEC 27001:2013 certified small business and appraised at CMMI Level 3 for Services and Development. We possess a common vision of excellence and foster a collaborative team culture built upon individual performance and accountability. We invest in our people and systems to create value for our clients. It is the SkyePoint Way. We are grateful for the opportunity to work with exceptional people and give back to the communities we serve. Our employees value the flexibility at SkyePoint that allows them to balance quality work and their personal lives. SkyePoint Decisions is a participating E-Verify Employer. U.S. Citizenship is required for most positions. Equal Opportunity Employer/Veterans/Disabled. CCPA Disclosure Notice Here

United States
$100K - $120K / year