
11 - 50 employees
🔒 Cybersecurity
💼 Consulting
Cybersecurity • Consulting
Dragonfli Group is a Washington, DC based LLC specializing in management and technology consulting. The company transforms its clients’ businesses by leveraging high impact strategic planning and technology solutions coupled with expertise in infrastructure, corporate strategy, and operations. Dragonfli Group’s passionate and experienced consultants take a collaborative approach to provide strategic planning and information security solutions to organizations looking to increase profitability, streamline operations, manage risk, meet regulatory demands, and build market share.
🔥 15 hours ago
Improve your chances of getting an interview by checking your resume score before you apply.

11 - 50 employees
🔒 Cybersecurity
💼 Consulting
Cybersecurity • Consulting
Dragonfli Group is a Washington, DC based LLC specializing in management and technology consulting. The company transforms its clients’ businesses by leveraging high impact strategic planning and technology solutions coupled with expertise in infrastructure, corporate strategy, and operations. Dragonfli Group’s passionate and experienced consultants take a collaborative approach to provide strategic planning and information security solutions to organizations looking to increase profitability, streamline operations, manage risk, meet regulatory demands, and build market share.
• Provide information on whether information systems are operating at an acceptable level of risk to the organization • Support information system authorization decisions with technical analysis and supporting evidence • Perform risk trade-off analyses and develop risk mitigation strategies and solutions • Review information system Plans of Action and Milestones (POA&Ms) and track remediation • Support cybersecurity risk management activities including categorizing systems, selecting and implementing security controls, and providing comprehensive assessments of the organization’s risk posture • Execute Security Control Assessments in accordance with NIST SP 800-37 and NIST SP 800-53A • Prepare and deliver briefings of assessment results and recommendations supporting authorization decisions • Support implementation and maintenance of Integrated Risk Management (IRM) processes • Support the agency’s Supply Chain Risk Management (SCRM) and Third-Party Risk Management (TPRM) programs • Maintain the Cyber Risk Register and track cybersecurity regulations, guidance, and data calls • Support FISMA score and maturity improvements, and normalize and translate cyber risks to support enterprise-wide risk visibility • Develop and maintain cybersecurity dashboards aligned with key performance metrics, hosted on Power BI • Apply automation and AI tooling to streamline risk reporting, compliance tracking, performance analysis, and regulatory monitoring • Present findings and recommendations to technical and non-technical decision makers • Advise stakeholders on cybersecurity-protective designs, implementations, and solutions
• Bachelor’s degree in cybersecurity, information technology, or a related field • 4 or more years of cyber governance, risk, and compliance experience • Assessment and Authorization (RMF) subject matter expertise, including hands-on experience testing and assessing cybersecurity solutions • Demonstrated experience performing risk trade-off analyses and developing risk mitigation strategies • Experience reviewing POA&Ms and supporting authorization decisions • Experience presenting to clients or other decision makers, adapting the message to technical and non-technical audiences • Ability to work independently and as a member of a team • U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S. • Ability to pass a federal agency suitability or background investigation • Prior federal contracting experience supporting a civilian agency governance or compliance program preferred • Experience with Integrated Risk Management, Supply Chain Risk Management, or Third-Party Risk Management programs preferred • Experience supporting FISMA reporting and maturity improvement preferred • Experience building or maintaining cybersecurity dashboards and KPI reporting preferred • Experience with JCAM, the agency’s GRC platform of record (formerly known as CSAM) preferred • Familiarity with automation, low-code/no-code, or AI-assisted compliance tooling preferred • Certifications such as CGRC (formerly CAP), CISA, CRISC, CISM, or CISSP preferred • Clear written and verbal communication with both technical and non-technical audiences • Ability to work independently and as a contributing member of a distributed team • Comfort operating in a fully remote setting with a camera-on meeting culture • Sound judgment about when to decide and when to escalate • Collaborative posture with system owners, business owners, developers, and assessors • Attention to documentation quality and follow-through on commitments
• Medical: Multiple POS health plan options including an HSA-compatible plan • Dental: PPO coverage for preventive, basic, and major services • Vision: Annual exam, frames, lenses, and contact lens allowance • 401(k): Employer match up to 5% of eligible compensation • Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings • Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each • PTO: 15-25 days annually based on tenure • Paid Federal Holidays: All 11 federal holidays observed
Apply Now🔥 17 hours ago
Senior analyst managing pricing models, contract governance, and ASC 606 compliance for Baylor Genetics. Protecting margins and reducing revenue leakage across commercial finance operations.
🔥 18 hours ago
Senior data governance specialist building enterprise policies, quality controls, and compliance frameworks for L3Harris Technologies. Partnering across business, IT, legal, cybersecurity, and compliance teams.
🕒 Yesterday
Senior Property Risk Engineer delivering field risk engineering and advanced property consultations. Supporting Zurich’s underwriting teams and customers in reducing insurance losses.
🕒 Yesterday
Platform Manager governing enterprise technology standards, architecture, compliance, and lifecycle management. Supporting Stryker’s medical device technology platforms across Corporate Functions.
🕒 Yesterday
Business Risk Officer scaling non-financial risk programs for Mercury’s startup-focused finance stack. Partnering across Product, Operations, Compliance, and oversight teams.
🇺🇸 United States – Remote
💵 $146k - $203.8k / year
⏰ Full Time
🟡 Mid-level
🟠 Senior
🎲 Risk
🦅 H1B Visa Sponsor