Build the identity infrastructure the world trusts.

We run certified IAL3 proofing for the agencies and enterprises that can't afford to get identity wrong. Come build it with us.

Careers

Why NextgenID

At NextgenID, we recognize the value of every team member. Our supportive culture encourages growth from within and rewards loyal employees with ownership opportunities through our Employee Stock Ownership Plan (ESOP). Join us on this journey as part of a family that is driven to take our company to new heights!

Current openings

Join our team

Client Solutions Engineer

This is a hands-on, cross-functional role. Under the Senior Manager of Client Solutions & Operations, you will support the full post-release lifecycle: deploying systems, troubleshooting hardware and software, managing helpdesk tickets, supporting SRIP agents, maintaining documentation, coordinating backend configurations, and producing operational reports. You will interact directly with clients, work alongside engineering, and coordinate with field technicians on the ground.

Role Fit & Non-Negotiables

  • Onsite in Fairfax, VA — no remote.
  • U.S. citizen required (ITAR and government customer obligations).
  • Comfortable across hardware, software, networking, and documentation in the same role.
  • Willing to travel to client sites for kiosk installations, diagnostics, and field support.
  • Clear written and verbal communication — client-facing daily.
  • Takes ownership through to completion: documents work, follows escalation, closes the loop.

What You’ll Own (30–90 Day Outcomes)

  • Fully onboarded across all active client environments, deployed stations, open tickets, and team workflows within 30 days.
  • Own assigned helpdesk queues: process, triage, resolve or escalate within SLA across all accounts.
  • Execute at least one end-to-end deployment or update rollout: image, configure, test, and document a kiosk or environment update from staging to production.
  • Produce at least one client-facing deliverable: installation guide, onboarding runbook, or updated user guide that meets client standards.
  • Complete SRIP agent program onboarding: training workflow, certification, session quality standards, and intervention procedures.
  • Participate in or lead an onsite technician visit: conduct or coordinate field diagnostics, document findings, close or escalate.

Key Responsibilities

The Client Solutions Engineer supports the following functions under the Senior Manager. You engage with each from the start; depth develops over time.

Helpdesk Operations
  • Process and triage tickets across all client accounts; categorize by severity and impact; route appropriately.
  • Provide Tier 1, 2, and escalated Tier 3 support; own issues until resolved or properly escalated.
  • Support oversight of outsourced Level 1 helpdesk agents under the Senior Manager: monitor quality, flag issues.
  • Track SLA timelines; escalate when deadlines are at risk.
  • Conduct root cause analysis on recurring or significant incidents; document findings and corrective actions.
  • Communicate with clients during open incidents: status updates, ETAs, resolution confirmation.
  • Participate in post-incident reviews; ensure documentation and follow-through are complete.
  • Escalate confirmed bugs to engineering with full log analysis, reproduction steps, and environment context.
Client Support & Enablement
  • Serve as point of contact for clients on day-to-day operational matters under Senior Manager guidance.
  • Prepare and maintain client-facing documentation: installation guides, onboarding materials, user/admin guides, runbooks.
  • Deliver training and daily support to SRIP agents; follow SOPs; keep agents informed of product and process updates.
  • Support demo environment setup and maintenance for client evaluations and internal testing.
  • Fulfill contract-defined service obligations across applicable accounts.
Documentation & Knowledge Management
  • Translate engineering release notes into clear documentation non-technical stakeholders can act on.
  • Create and maintain internal runbooks, SOPs, and operational guides; update as the platform evolves.
  • Maintain the team knowledge base: current, organized, accessible.
  • Produce and update architecture and deployment diagrams per client environment as configurations change.
  • Support compliance and audit documentation to federal and enterprise client standards.
System Deployment & Provisioning
  • Execute kiosk imaging, configuration, and deployment for new and replacement units.
  • Provision and configure client environments: cloud, on-prem, and hybrid.
  • Document and communicate network and firewall requirements to client IT before deployment.
  • Manage staging and production environment readiness for new releases.
  • Plan and execute system update rollouts with minimal operational disruption.
  • Coordinate hardware logistics and staging; schedule and support field technicians for installations and replacements.
Backend & Infrastructure Coordination
  • Manage tenant and environment configurations across identity platform systems.
  • Manage agent certificates and access configurations across all client environments.
  • Support server updates, DNS changes, and cloud infrastructure tasks with engineering.
  • Manage remote access tooling and secure connection setup for deployed kiosks.
  • Document infrastructure issues thoroughly; escalate to engineering with actionable, well-supported requests.
Field Services
  • Perform kiosk hardware and software diagnostics remotely and onsite across biometric sensors, document scanners, cameras, card printers, and network equipment.
  • Travel to client sites for installations, hardware replacements, and field troubleshooting.
  • Diagnose and resolve remote session failures: connectivity, network path, configuration.
  • Troubleshoot networking in enterprise environments: VPN, firewall, proxy, DNS.
  • Execute remote desktop and remote management sessions on deployed kiosks.
  • Collect, parse, and analyze logs to isolate fault sources; document with depth sufficient for root cause analysis and permanent fixes.
  • Coordinate with third-party vendors and service providers on behalf of clients.
  • Isolate faults between on-prem and cloud environments to determine ownership and resolution path.
SRIP Operations
  • Manage SRIP agent onboarding, credentialing, and platform access provisioning.
  • Deliver platform training; track agent certification status.
  • Monitor session quality; intervene in real time when issues arise.
  • Handle agent performance issues: escalate, document, coordinate remediation.
  • Support scheduling operations and coordination across agent pools.
Reporting & Analytics
  • Generate uptime and availability reports across the deployed kiosk fleet.
  • Track and report session volume and quality metrics by account.
  • Maintain client-facing usage dashboards with current, accurate data.
  • Analyze incident trends; surface systemic issues to the Senior Manager and engineering.
  • Produce SLA compliance reports per client contract requirements.
  • Contribute to internal performance reporting to the Senior Manager and leadership.

Required Qualifications

  • 3+ years in technical support, solutions engineering, IT operations, or managed services.
  • Demonstrated ability to troubleshoot hardware and software across complex, multi-component systems.
  • Helpdesk operations experience with multi-tier ticket management across enterprise or government accounts.
  • Networking fundamentals: TCP/IP, DNS, DHCP, VPN, firewall configuration, and connectivity troubleshooting.
  • Experience deploying and configuring systems in cloud and on-prem environments.
  • Ability to produce clear, professional technical documentation for internal and client audiences.
  • Strong written and verbal communication; comfortable with enterprise and federal agency clients.
  • Onsite in Fairfax, VA with travel as required — no remote or hybrid option.
  • U.S. citizen.

Preferred Qualifications

  • Identity proofing, ICAM, biometrics, PIV/CAC credentialing, or NIST 800-63 experience.
  • Familiarity with SRIP workflows, kiosk-based service delivery, or biometric enrollment station operations.
  • Prior federal agency contract support experience.
  • Remote access and fleet management tooling experience.
  • AWS infrastructure, DNS management, and certificate lifecycle management.
  • Managing or overseeing outsourced helpdesk or Level 1 support resources.
  • ITIL Foundation or equivalent certification.

Signals We Look For

  • You can walk through a ticket from first contact through triage, troubleshooting, client communication, and escalation — with clear documentation at every step.
  • You have configured or deployed a system in production or staging and can describe what you verified before and after.
  • You have written technical documentation — runbook, guide, SOP — and can speak to how you structured it and for whom.
  • You are composed on a client call during an active issue: you listen, communicate clearly, and don’t overpromise.
  • You know when to escalate and when to keep working the problem — and you document either way.
  • You follow through. If you opened it, you close it or hand it off properly.

What Success Looks Like

  • Fully onboarded across all active client environments, open tickets, and workflows within 30 days — processing assigned queues within SLA from day one.
  • Tickets handled completely: triaged correctly, communicated professionally, escalated with full documentation, closed without loose ends.
  • Client-facing documentation accurate, current, and usable — not just filed.
  • Deployments and updates executed cleanly: imaged, configured, tested, documented, and communicated to clients on time.
  • SRIP agents supported consistently: trained to standard, monitored, issues caught and escalated before they become client problems.
  • Field visits coordinated and productive: findings documented, tickets closed or escalated, nothing falls through the cracks.
  • At 12 months: the Senior Manager relies on this person across all eight functions. Clients know the name. Engineering trusts the escalations.

Onsite – Fairfax, VA · U.S. Citizen Required (ITAR / Government Customer Requirements) - Full Time

View Position Details

DevSecOps Manager (Gov / FedRAMP Focus)

NextgenID is hiring an on-site, hands-on DevSecOps Manager to lead security and platform operations for multi-cloud services across AWS, Azure, and Google Cloud, and to manage a global network of identity verification stations. This is a player/coach role: you will lead daily execution while setting the security and delivery standards required for SOC 2 (12–18 months) and FedRAMP Moderate. The role has a defined growth path to Director/VP based on performance, operating maturity, and leadership impact.

Role Fit & Non-Negotiables

  • Onsite in Fairfax, VA — remote is not available.
  • U.S. citizen required due to ITAR and government customer obligations.
  • Comfortable operating as an incident leader when needed, with primary operational hours generally 8am–7pm EST.
  • Hands-on ownership of security posture and DevOps/platform execution — this is not a policy-only or advisory role.

What You’ll Own (90–180 Day Outcomes)

  • Establish an audit-ready Secure SDLC and begin the transition from Azure DevOps (ADO) to GitHub, aligned with FedRAMP expectations.
  • Implement pragmatic CI/CD controls: SAST/SCA, secrets scanning, infrastructure-as-code scanning, environment protections, and evidence capture.
  • Harden multi-cloud identity and access: federation/SSO, least privilege, break-glass, and periodic access reviews.
  • Improve detection and response using Elastic; mature vulnerability management using Qualys with SLAs, dashboards, and exception governance.
  • Strengthen Windows fleet security using our custom command center: patching strategy, rollout rings/canary, rollback, remote isolate, baseline hardening, and telemetry coverage.
  • Stand up a repeatable operating cadence: standups, change control, incident review, postmortems, and measurable reliability/security KPIs.

Key Responsibilities

Security Leadership (Hands-On)

  • Own threat modeling and security architecture across edge, cloud, and SDLC.
  • Lead incident response end-to-end (triage, containment, eradication, recovery, postmortem).
  • Drive identity, encryption/key management, logging, detection engineering, and secure configuration baselines.

DevOps / Platform Engineering (Hands-On)

  • Own CI/CD pipelines and release governance across Kubernetes and VM-based workloads.
  • Define and enforce golden paths (templates, approved patterns, environment promotion, rollback) that accelerate delivery while improving security.
  • Select and standardize infrastructure-as-code approach (Terraform/CloudFormation/Bicep/Pulumi) and implement policy guardrails.

Compliance Execution (SOC 2 & FedRAMP Moderate)

  • Translate compliance requirements into engineering deliverables (controls, automation, evidence, continuous monitoring).
  • Partner with GRC to prepare audit-ready artifacts without creating manual, high-friction processes.
  • Create operational runbooks and control evidence that meets assessor scrutiny (NIST 800-53 mindset).

People Leadership (Player/Coach)

  • Lead and mentor a small SOC/NOC and DevOps team, with clear priorities and accountability.
  • Create a culture of high standards: measurable goals, calm execution under pressure, and continuous improvement.
  • Hire and scale the team as the platform and compliance program grows.

Required Qualifications

  • 7+ years in Security Engineering, DevOps, Platform/SRE, or equivalent roles with direct production ownership.
  • Demonstrated experience building and operating secure CI/CD and release governance; experience with Azure DevOps and/or GitHub Actions.
  • Strong cloud security fundamentals and hands-on delivery experience in at least two of AWS/Azure/GCP (multi-cloud preferred).
  • Practical Windows security experience; ability to harden and operate Windows 10/11 environments at scale (IoT/embedded a plus).
  • Incident response leadership experience (performed as incident commander or equivalent).
  • Hands-on experience with SIEM/telemetry operations (Elastic preferred) and vulnerability management (Qualys preferred).
  • Proven ability to lead, mentor, and build a small team; able to set standards without becoming a bottleneck.
  • Must be able to work onsite in Fairfax, VA; U.S. citizen.

Preferred Qualifications

  • FedRAMP Moderate experience (NIST 800-53 controls, SSP support, continuous monitoring, assessor engagement) and/or SOC 2 readiness delivery.
  • Kubernetes security experience (RBAC, admission control, network policy, image policy, workload identity) plus VM hardening experience.
  • Software supply chain maturity: SBOM, signed artifacts/provenance, dependency governance, runner hardening, secretless authentication (OIDC).
  • Device fleet operations: staged rollouts, canary rings, rollback safety, remote isolation, and resilience under intermittent connectivity.
  • PKI/credential management exposure: certificate lifecycle (issue/renew/revoke), CRL/OCSP concepts, HSM/KMS custody patterns, and separation of duties.

Signals We Look For

  • You can explain how you prevent CI/CD credential theft and guarantee artifact integrity (OIDC/short-lived creds, signing/provenance, environment protections).
  • You have led real incidents and can describe decisions, containment steps, and postmortem-driven improvements — not just tool lists.
  • You think in guardrails and golden paths: standardization that increases velocity while raising security and reliability.
  • You can operate across Windows edge realities (physical exposure, patching/rings, remote isolate) and cloud control planes.

What Success Looks Like

  • Security controls are implemented as automated guardrails, not manual gates; delivery speed improves while risk decreases.
  • Incidents are handled predictably with documented playbooks and measurable improvements (MTTD/MTTR, recurrence reduction).
  • SOC 2 and FedRAMP readiness progresses with high-quality evidence capture and continuous monitoring, minimizing manual audit churn.
  • The team becomes independent and scalable, enabling a Director-level operating model.

Fairfax, Virginia - On-site - Full-time exempt

View Position Details

Field Technician

The field technician assists cross-functionally the business units to deploy, test, deliver, and support NextgenID products for demonstrations, client deliveries, and internal programs. The Field Tech assists the Product Owner by collecting client requirements, conveying the requirements clearly to the dev team, and confirming the delivery and integrated functional testing of those tasks in the product release.

Responsibilities, Duties, and Expectations

  • Design, evaluate, and build mechanical/electromechanical products, equipment, systems, and processes.
  • Assemble, test, repair, inspect, build, and install product assemblies, power circuits, rack assemblies, electronics terminations, lift systems, camera systems, and various other electrical, mechanical, and electronics assemblies.
  • Collaborate closely with other developers/engineers and become a valued member of an autonomous, cross-functional team
  • Perform functional and integrated QA and Testing.
  • Investigate system malfunctions or anomalies, identify the root cause and corrective actions, and perform manual and automated tests.
  • Perform assembly, test, integration, operation, maintenance, and repair of products to ensure they are performing to specifications.
  • Must be able to travel frequently.

Field Technician Requirements:

  • Bachelor’s degree in computer science or technical Field
  • CompTIA A+, Network+, and Security+ certifications a plus
  • 12-24 months of electrical, mechanical, computer, hardware / software experience
  • Ability to build, assemble, code, deploy, and test system and subsystem components
  • Ability to shift priorities as needed and work in a fast-paced startup environment
  • Experience with off-the-shelf peripheral integration, biometric enrollment peripherals and processes is a plus
  • Experience with mechanical movement systems, controls, lighting, and illumination is a plus

Benefits

  • Competitive salary
  • Medical, dental, and vision insurance
  • Retirement savings plan
  • Paid time off and holidays
  • Opportunities for professional development

Role Fit & Non-Negotiables

  • Onsite at our Fairfax, VA headquarters. This role is hands-on and evidence-heavy.
  • U.S. citizen, required for FedRAMP and federal-customer obligations.
  • Two or more years in GRC, security compliance, audit support, or a closely related role.
  • Comfortable owning documentation, evidence, and trackers to a deadline.
  • Detail-oriented and discreet with sensitive security information.

What You Will Own (90 to 180 Day Outcomes)

  • Current, well-organized control documentation and evidence repositories, moving from SharePoint into Vanta.
  • The operational FedRAMP evidence effort: control documentation, gap-finding tracking, and Trust Center content drafts.
  • A monthly POA&M produced from Qualys findings using the FedRAMP template, with remediation tracked to closure.
  • Completed, consistent security questionnaires delivered on time for GRC Lead review.
  • The UK DVS documentation package and Kantara assessment materials kept current and submission-ready.

Core Responsibilities

Compliance Documentation & Evidence — keep the record current and audit-ready.

  • Maintain control documentation, policies, and procedures, and migrate evidence into Vanta.
  • Gather and organize evidence from engineering, DevSecOps, and operations leads.
  • Convert implemented controls into machine-readable (OSCAL / JSON) format for FedRAMP submission.

Authorization & Assessment Support — run the operational side of our certifications.

  • Refine and maintain the UK DVS / DIATF documentation package and scoping forms.
  • Prepare Kantara assessment materials (SoCA, S3A, KAR) and the Rev 4 gap working draft.
  • Coordinate assessment and pentest logistics, scheduling, and evidence with assessors and leads.

Vulnerability & POA&M Tracking — keep the remediation record honest.

  • Produce the monthly POA&M from Qualys findings using the FedRAMP template.
  • Track vulnerability remediation and compensating controls with the RedTeam / DevSecOps leads.
  • Maintain vulnerability and vendor-risk evidence logs (for example, the BeyondTrust remediation log).

Customer & Vendor Assurance Support — answer the questionnaires and support vendor risk.

  • Complete security questionnaires (for example, CCRA and customer InfoSec assessments) consistent with prior responses.
  • Support third-party and vendor risk assessments and evidence requests.
  • Route completed responses to the GRC Lead and management for review before submission.

Research & Program Support — support the wider compliance effort.

  • Provide compliance and privacy research to the document and product teams.
  • Support ADA / Section 508 assessments and international import certification documentation (BIS, WPC, ATA Carnet).
  • Help configure and maintain GRC tooling (Vanta) and keep the compliance calendar updated.

What You Must Have Already Done

  • Gathered and organized audit evidence and maintained compliance documentation to a deadline.
  • Worked with a control framework (NIST 800-53, 800-63, ISO 27001, or SOC 2) on real evidence or gap work.
  • Tracked vulnerabilities or POA&M items and coordinated remediation with technical teams.
  • Completed a customer or vendor security questionnaire using documented evidence.
  • Kept a tracker, repository, or evidence log accurate across many moving items.

Required Qualifications

  • Two or more years in GRC, security compliance, audit support, or a closely related role.
  • Working knowledge of NIST SP 800-53 and/or NIST SP 800-63, ISO 27001, or SOC 2.
  • Experience gathering evidence and maintaining compliance documentation.
  • Experience with vulnerability or POA&M tracking and remediation coordination.
  • Familiarity with vulnerability tooling (Qualys or Nessus) and evidence / GRC platforms (Vanta or similar).
  • Strong writing and documentation skills for policies, procedures, and questionnaire responses.
  • Highly organized and detail-oriented, able to manage many concurrent items.
  • Discreet and reliable with sensitive security and compliance information.
  • Must be able to work onsite in Fairfax, VA; U.S. citizen (FedRAMP / federal customer).

Preferred Qualifications

  • Security+, GRCP, CySA+, or progress toward CISA.
  • Exposure to FedRAMP or FISMA continuous monitoring (ConMon) and 3PAO assessments.
  • Experience with Kantara / NIST 800-63 identity assurance or UK DIATF / DVS.
  • Familiarity with OSCAL or machine-readable control formats.
  • Experience with security questionnaires (CAIQ, CCRA, customer InfoSec assessments).
  • Background in an IDaaS, cloud, or federal-contractor environment.

Signals We Look For

  • You keep trackers and evidence current without being chased.
  • You read a control and know what evidence proves it.
  • You write clearly enough that your draft needs little rework before sign-off.
  • You chase the last 10 percent of detail that makes evidence audit-ready.
  • You handle sensitive information with discretion and never submit without review.

What Success Looks Like

  • Control documentation and evidence are current, organized, and audit-ready in Vanta.
  • The monthly POA&M is produced on time and remediation is tracked to closure.
  • UK DVS and Kantara materials are submission-ready ahead of each deadline.
  • Security questionnaires are completed accurately and on time for GRC Lead review.
  • Inherited workstreams from the departing analyst and intern continue without gaps.

Why NextgenID

NextgenID builds the compliance-grade identity infrastructure that federal agencies and enterprises rely on to verify and credential identity at IAL3. Compliance is the product’s license to operate, and the evidence you produce is what makes it real. As GRC Analyst, you will see your work in every certification we hold and every customer questionnaire we clear, and you will grow into deeper risk and program ownership. For the right person, this is the path to a senior GRC or GRC Lead role.

Role Fit & Non-Negotiables

  • Onsite at our Fairfax, VA headquarters. This is a hands-on leadership role, not remote.
  • U.S. citizen, required for FedRAMP and federal-customer obligations.
  • Five or more years in governance, risk, and compliance, including ownership of a formal authorization or audit program.
  • Direct experience with FedRAMP, FISMA, or an equivalent federal framework, and with third-party (3PAO) assessments.
  • Able to make and defend risk decisions and to sign off on evidence that goes to assessors and customers.

What You Will Own (90 to 180 Day Outcomes)

  • A single, authoritative compliance calendar and program plan across FedRAMP, Kantara, UK DVS, SOC 2, and customer questionnaires.
  • The FedRAMP 20x authorization effort carried toward submission, including the 3PAO relationship, Trust Center publication, and machine-readable (OSCAL) control package.
  • A current, governed risk register and monthly POA&M process, with documented risk decisions and compensating controls.
  • Kantara 800-63A (IAL3) certification maintained, with a planned path from Rev 3 to Rev 4.
  • A functioning GRC tooling and evidence pipeline (Vanta) that keeps documentation and submissions current with less manual effort.
  • A GRC Analyst onboarded, directed, and delivering, with the departing analyst’s and intern’s workstreams fully absorbed.

Core Responsibilities

Compliance Program Leadership — own the program, the calendar, and the standard.

  • Own the compliance calendar and program plan across FedRAMP, FISMA, Kantara/NIST 800-63, UK DIATF/DVS, SOC 2, and ADA.
  • Set GRC policy, standards, and process, and keep them current and version-controlled.
  • Report compliance status, risk posture, and audit readiness to the CTO and leadership.

Authorizations & External Assessments — lead audits, 3PAOs, and certification bodies.

  • Lead FedRAMP 20x authorization: 3PAO selection and relationship, ATO timeline, Trust Center publication, and the OSCAL submission strategy.
  • Own the Kantara certification program (800-63A, IAL3) and the Rev 3 to Rev 4 transition strategy.
  • Own the UK DVS / DIATF certification, including scoping and gap-assessment leadership.

Risk Management — own the risk register and the decisions that carry risk.

  • Maintain the enterprise and vendor risk register and govern the monthly POA&M process.
  • Make and document risk decisions, risk adjustments, and compensating controls, including vendor vulnerabilities.
  • Set vulnerability remediation priorities and pentest readiness with the engineering and DevSecOps leads.

Vendor & Customer Assurance — prove our posture to third parties without slowing the business.

  • Own third-party and vendor risk assessments across our tooling and supply chain.
  • Own the security-questionnaire program (final review and sign-off) and represent our posture to customers and prospects.
  • Partner with Growth and Legal on assurance commitments and trust-center content.

Team & Tooling — deliver the program through the analyst and the toolchain.

  • Lead, mentor, and prioritize the work of the GRC Analyst and absorb the departing intern’s workstreams.
  • Own GRC tooling strategy and the evidence pipeline (Vanta, Qualys, OSCAL).
  • Coordinate engineering, DevSecOps, operations, and legal contributors to compliance deliverables.

What You Must Have Already Done

  • Owned a federal authorization or audit program (FedRAMP, FISMA, StateRAMP, or equivalent) through a 3PAO or independent assessment.
  • Built and maintained a risk register and a POA&M process, and defended risk decisions to an assessor or customer.
  • Interpreted a control framework (NIST 800-53, 800-63, or ISO 27001) and translated it into policy, procedure, and evidence.
  • Managed an external assessor or certification-body relationship end to end.
  • Led or mentored analysts and coordinated cross-functional contributors to a compliance deadline.

Required Qualifications

  • Five or more years in governance, risk, and compliance, security compliance, or audit, with program ownership.
  • Direct experience with FedRAMP and/or FISMA, including continuous monitoring (ConMon) and 3PAO assessment.
  • Working command of NIST SP 800-53 and NIST SP 800-63 (identity assurance), and of risk-assessment methodology.
  • Experience owning a risk register, a POA&M process, and a vendor-risk program.
  • Experience managing external assessors, auditors, or certification bodies.
  • Experience with GRC or compliance-automation tooling (Vanta or similar) and vulnerability tools (Qualys or Nessus).
  • Ability to make, document, and defend risk decisions.
  • Excellent written and verbal communication for assessors, customers, and executives.
  • Must be able to work onsite in Fairfax, VA; U.S. citizen (FedRAMP / federal customer).

Preferred Qualifications

  • CISA, CRISC, CISSP, or CISM certification.
  • Experience with Kantara / NIST 800-63 identity assurance (IAL2 / IAL3) certification.
  • Experience with international identity frameworks (UK DIATF / DVS) or ISO 27001 certification.
  • Experience with OSCAL or machine-readable control packages for FedRAMP 20x.
  • Background in a federal-contractor or IDaaS / identity-security environment.
  • Experience managing security questionnaires (CAIQ, CCRA, customer InfoSec assessments).
  • Familiarity with SOC 2 and ADA / Section 508 accessibility assessments.

Signals We Look For

  • You own the calendar in your head: you know what is due, to whom, and what evidence proves it.
  • You make risk calls and defend them with documented reasoning, not hand-waving.
  • You turn a framework into a short list of what has to be done, and get it done.
  • You keep assessors and customers confident because your evidence is clean and current.
  • You lead through other teams, coordinating engineering and operations without owning their headcount.

What Success Looks Like

  • FedRAMP 20x reaches submission on schedule, with a published Trust Center and a machine-readable control package.
  • Kantara IAL3 certification stays current, with a credible Rev 4 transition plan.
  • A single risk register and monthly POA&M process run on cadence, with documented risk decisions.
  • Customer questionnaires and external assessments are answered accurately and on time, with no material findings from poor evidence.
  • The GRC Analyst is productive and the departing analyst’s and intern’s workstreams continue without gaps.

Why NextgenID

NextgenID builds the compliance-grade identity infrastructure that federal agencies and enterprises rely on to verify and credential identity at IAL3. Compliance is not overhead here — it is the product’s license to operate. As GRC Lead, you own the authorizations and the evidence that let us sell and deliver, and you will see your work directly in every certification we hold and every customer we win. For the right person, this is the path to a GRC Manager or Director role as the program grows.

Role Fit & Non-Negotiables

  • Onsite at our Fairfax, VA depot. This is bench and hands-on work; it cannot be done remotely.
  • U.S. citizen, required for ITAR and government-customer obligations.
  • Comfortable with hands-on hardware: assembly, wiring, connectors, and swapping physical components.
  • Able to trace and troubleshoot low-voltage DC power with a multimeter (12 VDC and 24 VDC).
  • Able to lift and move kiosks and crates (up to about 50 lbs) and occasionally travel to a customer site.

What You Will Own (90 to 180 Day Outcomes)

  • A clean, accurate spare-parts depot: every part counted and binned, min/max levels set, and reorder points working.
  • Kiosks built and repaired to the documented standard, each passing acceptance testing before it ships.
  • A steady flow of remove-and-replace repairs completed at the bench and, when needed, in the field.
  • DC power faults traced to the failed part and fixed, rather than whole units replaced.
  • A current RMA and warranty pipeline: failed parts returned, credits tracked, and serials recorded.
  • Accurate serialized asset records for every unit and tracked component in the Command Center.

Core Responsibilities

Kiosk Build & Component Replacement

  • Build kiosks and mobile kits from documented assembly instructions, drawings, and photos.
  • Remove and replace cameras, fingerprint and document scanners, card readers, signature pads, printers, touchscreens, monitors, USB hubs, fans, locks, power supplies, and UPS batteries.
  • Seat cables and connectors correctly, with proper strain relief, so nothing works loose.

DC Power Tracing & Troubleshooting

  • Trace 12 VDC and 24 VDC rails with a multimeter, checking voltage at the supply and at each device.
  • Find and fix blown fuses, loose ferrules, bad barrel connectors, and dead rails.
  • Service the UPS and backup battery, and follow the power-on, power-off, and safety steps.

Spare Parts & Depot Inventory

  • Receive, count, bin, and issue spare parts, and keep min/max levels and reorder points current.
  • Build and stage known-good swap units and repair kits so service is fast.
  • Record serial numbers for consigned and tracked parts and reconcile inventory regularly.

Testing, Acceptance & Basic Connectivity

  • Run the acceptance-test and hardware-test steps and record pass or fail with evidence.
  • Confirm the unit powers up, all peripherals are detected, and it comes online with a network cable or the installed cellular modem.
  • Escalate any network configuration or software-image change to the Hardware / Network Engineer.

Field Support, RMA & Documentation

  • Perform on-site swaps and repairs, and support Field Service Engineers with parts and known-good units.
  • Process warranty and RMA returns, and track failed parts, credits, and replacements.
  • Log every repair, part used, and serial number in the ticket and the Command Center.

What You Must Have Already Done

  • Repaired and maintained electro-mechanical equipment in the field or at a bench: ATMs, vending or arcade machines, copiers and printers, POS, or similar.
  • Removed and replaced failed components and returned equipment to service, working from documented procedures.
  • Traced a low-voltage DC power fault to its cause with a multimeter and repaired it, rather than swapping the whole unit.
  • Managed spare parts or a repair-parts inventory, including counts, reorder points, and serialized tracking.
  • Kept accurate service records: what failed, what you did, and which parts and serials were involved.

Qualifications

Required

  • Two or more years repairing and maintaining electro-mechanical or electronic equipment (ATM, vending or arcade, copier or printer, POS, kiosk, or similar).
  • Hands-on component replacement: swapping boards, peripherals, power supplies, and cabling.
  • Low-voltage DC troubleshooting: 12 VDC and 24 VDC, multimeter voltage tracing, fuses, connectors, and power-supply replacement.
  • Able to read and follow assembly drawings, wiring diagrams, and documented procedures.
  • Comfortable using basic hand tools, crimpers, and a multimeter.
  • Basic computer literacy: connect a unit to power and network, confirm it boots and comes online, and run a test application.
  • Spare-parts or inventory handling experience, including serialized asset tracking.
  • Careful, methodical, and safety-minded around live low-voltage parts.
  • Able to lift and move up to about 50 lbs and stand for extended bench work.
  • Must be able to work onsite in Fairfax, VA; U.S. citizen (ITAR).

Preferred

  • Experience with biometric or identity peripherals: cameras, fingerprint sensors, document or passport scanners, or card readers.
  • Experience servicing self-service kiosks, ATMs, or unattended machines in the field.
  • CompTIA A+ or a similar electronics or repair certification.
  • Soldering, crimping, or wiring-level repair experience.
  • Shipping, receiving, and logistics or depot experience.
  • Familiarity with ticketing systems and asset or inventory tools.
  • Valid driver’s license and willingness to travel occasionally to customer sites.

Signals We Look For

  • You fix to the failed part, not the whole unit, and you can explain how you found it.
  • You keep a clean bench and an honest parts count, because you know downtime hides in disorder.
  • You follow the documented standard so every unit that ships is identical and traceable.
  • You work safely around low-voltage power: you read the labels, check the rails, and respect live parts.
  • You know when a problem is beyond hardware and hand it to the Hardware / Network Engineer instead of guessing.

What Success Looks Like

  • Every kiosk you build or repair passes acceptance testing before it ships.
  • Depot inventory is accurate, with reorder points working and no stock-outs of critical spares.
  • Repairs are resolved at the component level, keeping unit replacements to a minimum.
  • RMA and warranty returns are processed promptly, with serials and credits tracked.
  • Serialized asset records match the physical fleet in the Command Center.

Why NextgenID

NextgenID builds the compliance-grade identity infrastructure that federal agencies and enterprises rely on to verify and credential identity at the highest assurance level. The kiosks you build and repair are where that mission meets the real world. Every unit that leaves the depot carries your build quality, your wiring, and your test sign-off. You will see the direct result of your work in fleet uptime, and for the right person this is the path to senior technician and field-lead roles as the fleet grows.

NextgenID is an Equal Opportunity Employer. We do not discriminate based on race, color, religion, sex, national origin, age, disability, veteran status, or any other characteristic protected by applicable law.

Load More Listings

Benefits & Perks

At NextgenID, we offer a thoughtfully designed benefits package that supports your health, financial security, and overall well-being.

Health & Wellness

  • Comprehensive medical, dental, and vision coverage

  • Primary care and virtual care options for convenient access

  • Mental health support, including online therapy resources

  • Care advocacy services to help navigate providers, claims, and billing

  • Women's health and family-planning support

Financial Well-Being

  • 401(k) retirement plan

  • Health Savings Account (HSA) options

  • Life and disability coverage, including optional supplemental plans

Time Off & Flexibility

  • Paid time off (PTO)

  • Sick leave

  • Paid company holidays

Be part of our rapidly growing company and join our subject matter experts