
11 - 50 employees
🔒 Cybersecurity
💼 Consulting
Cybersecurity • Consulting
Dragonfli Group is a Washington, DC based LLC specializing in management and technology consulting. The company transforms its clients’ businesses by leveraging high impact strategic planning and technology solutions coupled with expertise in infrastructure, corporate strategy, and operations. Dragonfli Group’s passionate and experienced consultants take a collaborative approach to provide strategic planning and information security solutions to organizations looking to increase profitability, streamline operations, manage risk, meet regulatory demands, and build market share.
🕒 Yesterday
🏛️ District of Columbia, Washington – Remote
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
👻 Ghost score 21%
Improve your chances of getting an interview by checking your resume score before you apply.

11 - 50 employees
🔒 Cybersecurity
💼 Consulting
Cybersecurity • Consulting
Dragonfli Group is a Washington, DC based LLC specializing in management and technology consulting. The company transforms its clients’ businesses by leveraging high impact strategic planning and technology solutions coupled with expertise in infrastructure, corporate strategy, and operations. Dragonfli Group’s passionate and experienced consultants take a collaborative approach to provide strategic planning and information security solutions to organizations looking to increase profitability, streamline operations, manage risk, meet regulatory demands, and build market share.
• Own the security posture for assigned systems, advising on architecture, authorization boundaries, and risk decisions • Lead control compliance and assessment readiness, maintaining key artifacts including the System Security Plan • Coordinate audits and assessments, including scheduling, evidence readiness, and response to assessor findings • Run continuous monitoring and reporting, defining metrics and escalating material risks and issues • Drive vulnerability remediation and POA&M corrective actions, including exceptions, compensating controls, and risk acceptances • Execute Risk Management Framework tasks across categorization, control selection, implementation, assessment, and authorization in accordance with NIST SP 800-37 • Support the transition to and management of an Ongoing Authorization program • Provide cybersecurity guidance to Business Owners and System Owners and serve as a liaison between those stakeholders and the cybersecurity staff • Support System Owner system access reviews and account management compliance • Apply automation and AI tooling to streamline RMF documentation, control assessments, and continuous monitoring activities
• Bachelor's degree in cybersecurity, information technology, or a related field • 4 years of ISSO experience, including ownership of security posture for one or more systems • Demonstrated experience maintaining SSPs and leading a system through assessment or authorization • Hands-on experience managing POA&Ms, including exceptions, compensating controls, and risk acceptances • Working knowledge of NIST SP 800-37 and NIST SP 800-53, and of continuous monitoring practice • Experience advising system owners or engineering teams on risk decisions • U.S. Citizenship or Permanent Residency, with all work performed within the continental U.S. • Ability to pass a federal agency suitability or background investigation • Prior federal contracting experience as an ISSO at a civilian agency preferred • Experience with Ongoing Authorization or continuous ATO programs preferred • Experience with a GRC platform such as Xacta, eMASS, CSAM, Archer, or ServiceNow IRM preferred • Cloud authorization experience, including FedRAMP inheritance and interconnection agreements preferred • Experience defining security metrics and reporting posture to non-technical stakeholders preferred • Certifications such as CISSP, CGRC (formerly CAP), CISM, or CCSP preferred • System security posture ownership and risk-based decision support • SSP and authorization artifact development and maintenance • Risk Management Framework execution under NIST SP 800-37 • Security control assessment readiness under NIST SP 800-53A • POA&M management, compensating controls, exceptions, and risk acceptance • Continuous monitoring, security metrics definition, and posture reporting • Vulnerability management and remediation coordination • GRC tooling and cloud authorization models including FedRAMP • Clear written and verbal communication with both technical and non-technical audiences • Ability to work independently and as a contributing member of a distributed team • Comfort operating in a fully remote setting with a camera-on meeting culture • Sound judgment about when to decide and when to escalate • Collaborative posture with system owners, business owners, developers, and assessors • Attention to documentation quality and follow-through on commitments
• Medical: Multiple POS health plan options including an HSA-compatible plan • Dental: PPO coverage for preventive, basic, and major services • Vision: Annual exam, frames, lenses, and contact lens allowance • 401(k): Employer match up to 5% of eligible compensation • Long-Term Disability: 100% employer-paid coverage at 50% of pre-disability earnings • Life Insurance & AD&D: 100% employer-paid coverage valued at $10,000 each • PTO: 15–25 days annually based on tenure • Paid Federal Holidays: All 11 federal holidays observed
Apply Now🕒 Yesterday
Senior Cyber Security Engineer securing Rolls-Royce’s power and propulsion technology networks. Designing network defenses, monitoring threats, and maintaining on-premises and cloud security tooling.
🕒 Yesterday
Senior Information Security Engineer securing eMoney’s wealth management platform and AI environments. Managing cloud, network, incident response, compliance, and data protection operations.
🇺🇸 United States – Remote
💵 $115k - $150k / year
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🕒 Yesterday
Security Engineer strengthening Dizzion’s secure digital workspace infrastructure. Owning incident response, vulnerability remediation, security controls, KPIs, and compliance readiness.
🇺🇸 United States – Remote
💵 $120k - $130k / year
💰 Private Equity Round - Dizzion on 2021-01
⏰ Full Time
🟡 Mid-level
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🕒 Yesterday
Associate Director investigating fraud, misconduct, and score validity issues for College Board assessments. Analyzing exam data and monitoring social media to protect assessment integrity.
🕒 Yesterday
Cyber Security Engineer securing Emprise Bank through vulnerability management, identity access, DLP, vendor reviews, and incident response. Providing tier 3 security support and leading IT Security projects.