1

Cmmc Jobs (NOW HIRING)

Track CMMC rulemaking, NIST guidance updates, and DoD policy changes; brief leadership on implications and required organizational responses * Establish and report on compliance program metrics and ...

Help grow Ariento's CMMC practice by contributing to the development of our capabilities, methodology and foster a continuous improvement environment * Work with practice leadership to build client ...

Help grow Ariento's CMMC practice by contributing to the development of our capabilities, methodology and foster a continuous improvement environment * Work with practice leadership to build client ...

We are looking for a CMMC Security Engineer is responsible for implementing, maintaining, and leading cybersecurity efforts to ensure compliance with the Cybersecurity Maturity Model Certification ...

We are looking for a CMMC Security Engineer is responsible for implementing, maintaining, and leading cybersecurity efforts to ensure compliance with the Cybersecurity Maturity Model Certification ...

Red Cup IT is seeking a CMMC Security Engineer responsible for implementing and maintaining cybersecurity efforts to ensure compliance with CMMC standards. The role involves designing security ...

Track CMMC rulemaking, NIST guidance updates, and DoD policy changes; brief leadership on implications and required organizational responses * Establish and report on compliance program metrics and ...

We seek a highly skilled CMMC Level 2 Certified Assessor (CCA) to join our team on a project basis. This role involves conducting official CMMC Level 2 assessments for organizations seeking ...

The CMMC Engineer is an entry-level technical member of the CMMC Engineering team responsible for supporting the implementation, configuration, maintenance, and monitoring of technologies used within ...

The CMMC Compliance Manager will be responsible for supporting the company's U.S. government cybersecurity compliance program, with primary focus on Cybersecurity Maturity Model Certification (CMMC ...

The CMMC Compliance Manager will be responsible for supporting the company's U.S. government cybersecurity compliance program, with primary focus on Cybersecurity Maturity Model Certification (CMMC ...

The CMMC Compliance Manager will be responsible for supporting the company's U.S. government cybersecurity compliance program, with primary focus on Cybersecurity Maturity Model Certification (CMMC ...

Overview The Nov 10, 2026 CMMC 2.0 Phase 2 deadline is forcing every DIB contractor to prove they protect CUI - and most are trying to do it by tightening controls on the endpoint. That's the wrong ...

next page

Showing results 1-20

Cmmc information

See salary details

$14

$25

$53

How much do cmmc jobs pay per hour?

As of Aug 27, 2026, the average hourly pay for cmmc in the United States is $25.22, according to ZipRecruiter salary data. Most workers in this role earn between $18.03 and $23.80 per hour, depending on experience, location, and employer.

What is a CMMC?

A CMMC job typically involves ensuring an organization complies with the Cybersecurity Maturity Model Certification (CMMC) framework. Professionals in this role assess cybersecurity practices, prepare for audits, and help implement necessary security controls. They may work as consultants, compliance officers, or cybersecurity specialists, depending on the organization's needs. Their goal is to protect sensitive government and defense-related information by meeting CMMC requirements.

What are the primary responsibilities of a CMMC consultant during a client engagement?

As a CMMC Consultant, your main responsibilities include assessing client organizations’ current cybersecurity practices, identifying gaps relative to CMMC requirements, and developing actionable remediation plans. You will collaborate closely with IT teams, management, and external stakeholders to guide clients through the CMMC certification process. Expect to conduct detailed documentation reviews, perform technical evaluations, and provide training or recommendations to help clients achieve required compliance levels. This role involves balancing technical analysis with regulatory interpretation to support clients throughout their compliance journey.

What are the key skills and qualifications needed to thrive in the CMMC position, and why are they important?

To thrive as a CMMC (Cybersecurity Maturity Model Certification) Consultant, you need expertise in cybersecurity frameworks, risk assessments, and compliance standards, typically supported by a degree in information technology or cybersecurity and relevant certifications such as CMMC-AB certifications or CISSP. Proficiency with security assessment tools, regulatory compliance platforms, and documentation systems is essential in this role. Strong analytical thinking, attention to detail, and effective communication skills set top candidates apart in guiding organizations through complex compliance requirements. These skills are vital for ensuring client organizations achieve and maintain compliance with Department of Defense cybersecurity mandates.

More about Cmmc jobs

What cities are hiring for Cmmc jobs?

Cities with the most Cmmc job openings:

What are the most commonly searched types of Cmmc jobs?

The most popular types of Cmmc jobs are:

What states have the most Cmmc jobs?

States with the most job openings for Cmmc jobs include:

Infographic showing various Cmmc job openings in the United States as of August 2026, with employment types broken down into 63% Full Time, 26% Part Time, and 11% Contract. Highlights an 69% In-person, 5% Hybrid, and 26% Remote job distribution, with an average salary of $52,465 per year, or $25.2 per hour.

CMMC Assessment Lead

Mclean, VA • Remote

Paragone Solutions, Inc.
IT Services • 11 - 50 employees

Full-time

Re-posted 10 days ago


Job description

About SecureITSM
SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID #L200002160) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations.
We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements.
The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities.
Location and Travel: This is a remote position with occasional travel required to support customer assessments.
Position Summary
The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership.
This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible.
Key Responsibilities
Plan and Coordinate Assessments (Primary)
  • ​​​​​​​​​​​​​​​​​​​​Maintain the master CMMC customer assessment schedule
  • Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams
  • Conduct readiness reviews and pre-assessment planning meetings
  • Track customer assessment milestones, dependencies, and remediation activities
  • Manage customer communications related to assessment preparation and scheduling
  • Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes
  • Monitor assessment status and provide executive-level reporting on customer readiness
  • Assist customers in understanding assessment scope, boundary definitions, and enclave considerations ​​​​​​​​​​​​​​
Prepare Assessment Packages (Primary)
  • Update implementation statements as needed
  • Gather and organize evidentiary artifacts
  • Coordinate customer evidence collection activities
  • Review SSPs, policies, procedures, and supporting documentation for assessment readiness
  • Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives
  • Prepare assessor-ready evidence packages and artifact repositories
  • Conduct internal quality assurance reviews of documentation and evidence
  • Identify documentation gaps and coordinate remediation activities
  • Support development and maintenance of Plans of Action & Milestones (POA&Ms)
  • Ensure documentation aligns with evolving CMMC and NIST guidance
Support Customer Assessments (Primary)
  • Attend and actively support customer assessments
  • Actively defend implementations and evidence presented to assessors
  • Coordinate assessment interviews and technical demonstrations
  • Support mock assessments and readiness exercises for customers
  • Assist customers in responding to assessor requests and follow-up questions
  • Document assessment observations, findings, and remediation actions
  • Coordinate post-assessment remediation activities and evidence resubmissions when required
  • Serve as a trusted advisor throughout the certification lifecycle
Maintain SecureITSM’s Authorization and Compliance (Secondary)
  • Conduct SecureITSM’s annual self-assessment activities
  • Maintain internal compliance documentation and evidentiary artifacts
  • Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans)
  • Assist with internal policy and procedure updates
  • Support ongoing continuous monitoring and compliance validation activities
  • Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture
 Implementation Statement Management (Secondary)
  • Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance
  • Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments)
  • Standardize implementation language and evidence expectations across customer environments
  • Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices
  • Validate implementation statements for technical accuracy, completeness, and assessor defensibility
  • Support continuous improvement of SecureITSM’s proprietary documentation platform and implementation content library
Maintain and Improve Standard Operating Procedures (Secondary)
  • Develop and maintain assessment preparation Standard Operating Procedures (SOPs)
  • Continuously improve evidence collection and assessment support workflows
  • Create standardized templates, checklists, and assessment playbooks
  • Document lessons learned and incorporate process improvements
  • Maintain internal knowledge base articles and operational documentation
  • Assist in refining SecureITSM’s proprietary CMMC documentation platform workflows and processes
Required Qualifications
  • U.S. Citizenship required
  • Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies
  • 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171
  • Experience supporting compliance assessments, audits, or certification activities
  • Strong understanding of CMMC assessment methodology and evidence requirements
  • Excellent technical writing and communication skills
  • Strong project management and organizational abilities
  • Exceptional attention to detail
  • Ability to manage multiple customer engagements simultaneously
  • Experience working directly with external assessors, auditors, or regulatory bodies
  • Familiarity with secure project management and compliance collaboration platforms
Preferred Qualifications
  • PMP certification preferred
  • CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred
  • CISSP, CISM, or equivalent cybersecurity certification preferred
  • Experience supporting DoD contractors or working within the Defense Industrial Base (DIB)
  • Familiarity with FedRAMP and DFARS 252.204-7012
  • Experience with SIEM, vulnerability management, and endpoint protection technologies
Key Attributes
  • Strong leadership and customer engagement skills
  • Ability to remain composed and professional during high-pressure assessment activities
  • Analytical thinker with strong problem-solving capabilities
  • Self-motivated with ability to work independently
  • Collaborative team player with strong interpersonal skills
  • High level of integrity and professionalism ​​​​​​​

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law.
#ZR

Powered by JazzHR

0mriC7k8Mc