1

Cmmc Assessor Jobs in Reston, VA (NOW HIRING)

Director of Sales

Fairfax, VA · On-site

$120 - $160/hr

CMMC readiness and C3PAO certification assessments * FedRAMP readiness and 3PAO security assessments * NIST 800-171 readiness and compliance programs * MARS-E security and privacy assessments

Participate in CMMC preparation, assessment, and certification activities * Deliver occasional cyber security awareness and IT training to team members * Maintain IT inventory, lifecycle management ...

New

... 53, CMMC, ISO 27001, or SOC 2 requirements. Our advisory teams partner with organizations to navigate cybersecurity and compliance challenges--from readiness assessments and gap analyses to ...

New

Showing results 21-40

Cmmc Assessor information

See Reston, VA salary details

$33.8K

$78.3K

$130.6K

How much do cmmc assessor jobs pay per year?

As of Aug 21, 2026, the average yearly pay for cmmc assessor in Reston, VA is $78,297.00, according to ZipRecruiter salary data. Most workers in this role earn between $47,900.00 and $100,900.00 per year, depending on experience, location, and employer.

What is a CMMC Assessor?

A CMMC Assessor is a certified professional responsible for evaluating an organization's cybersecurity practices against the Cybersecurity Maturity Model Certification (CMMC) framework. They conduct assessments to ensure compliance with cybersecurity requirements set by the Department of Defense (DoD) for contractors handling Controlled Unclassified Information (CUI). CMMC Assessors work with Certified Third-Party Assessment Organizations (C3PAOs) to perform audits, document findings, and provide recommendations for achieving the necessary certification level. Their role is critical in helping organizations secure government contracts by verifying their adherence to required cybersecurity standards.

What does a CMMC Assessor do?

A typical day for a CMMC Assessor involves reviewing cybersecurity policies, conducting in-depth interviews with client personnel, examining technical controls, and documenting assessment findings. CMMC Assessors often work on-site at client locations or remotely, collaborating closely with IT teams and management to validate controls and clarify requirements. The role frequently includes preparing reports, communicating results to stakeholders, and recommending remediation steps where necessary. This position is detail-oriented and dynamic, offering a mix of independent work and teamwork while supporting organizations in achieving and maintaining CMMC certification.

What are the key skills and qualifications needed to thrive as a CMMC Assessor?

To thrive as a CMMC Assessor, you need a comprehensive understanding of cybersecurity frameworks, risk management, and the CMMC (Cybersecurity Maturity Model Certification) standard, typically demonstrated by industry experience and relevant certifications such as CMMC-AB Certified Assessor or CISSP. Familiarity with assessment tools, audit software, and NIST frameworks is critical for evaluating organizations' compliance. Strong analytical thinking, attention to detail, and excellent communication skills help explain findings and recommendations to clients. These skills and qualities are essential for ensuring accurate, credible assessments and guiding organizations toward regulatory compliance.

How to become a CMMC assessor?

To become a CMMC assessor, individuals typically need relevant experience in cybersecurity, auditing, or compliance, along with specific training provided by authorized bodies such as the CMMC Accreditation Body. They must complete assessor training courses, pass certification exams, and demonstrate knowledge of CMMC requirements and assessment procedures. Maintaining ongoing education and recertification is also necessary to stay current with evolving standards.

What job categories do people searching Cmmc Assessor jobs in Reston, VA look for?

The top searched job categories for Cmmc Assessor jobs in Reston, VA are:

What cities near Reston, VA are hiring for Cmmc Assessor jobs?

Cities near Reston, VA with the most Cmmc Assessor job openings:

Infographic showing various Cmmc Assessor job openings in Reston, VA as of August 2026, with employment types broken down into 75% Full Time, 20% Part Time, 1% Temporary, and 4% Contract. Highlights an 75% Physical, 3% Hybrid, and 22% Remote job distribution, with an average salary of $78,297 per year, or $37.6 per hour.

IT and Security Manager

Brightline Interactive

Ashburn, VA • On-site

Other

Re-posted yesterday


Job description

IT and Security Manager (On-Site) 


Overview 

We’re hiring a hands-on IT & Security Manager to lead our company through the CMMC certification process—from gap assessment and remediation planning to control implementation, evidence collection, and assessment readiness—while owning on-site IT operations, security governance, and compliance. You’ll administer Microsoft 365 and core IT platforms, secure our enclaves and endpoints, run SIEM/vulnerability/IR workflows, and lead audits (CMMC, NIST, FedRAMP alignment). You’ll report to the COO, collaborate closely with engineering, operations, and leadership, and ensure controls are effective without disrupting production. 


Key Responsibilities 

CMMC Program Leadership 

  • Own CMMC end-to-end: Gap analysis → remediation roadmap → control implementation (SSP/POA&M) → objective evidence library → assessment readiness. 
  • Assessment readiness: Coordinate internal audits, stakeholder drills, assessor engagement, and track findings to closure. 
  • Vendor due diligence and contract clauses for CUI handling. 

IT Operations (ITSM) & Asset Lifecycle 

  • Service reliability: Own M365 tenant administration (Entra ID/SSO, Intune, Exchange, SharePoint/OneDrive), core IT services, and helpdesk workflows. 
  • Asset management: Provisioning, inventory, and lifecycle for laptops, peripherals, and enclave hardware; maintain CMDB accuracy. 
  • On/Offboarding: Role-based access, least-privilege, and auditable user transitions. 
  • Change management: Define CAB/approvals, back-out plans, and maintenance windows with minimal disruption. 

Security Engineering & SecOps 

  • Controls & hardening: Enclaves, endpoints, VMs/containers (policy baselines, MFA, encryption in transit/at rest). 
  • SIEM & monitoring: Manage detections, triage alerts, and lead incident response/post-mortems. 
  • Vulnerability management: Scans (e.g., Nessus), risk-based prioritization, remediation SLAs, and verification. 
  • Network & endpoint security: Firewalls, VPNs (WireGuard/OpenVPN/IPsec), IDS/IPS, EDR, device posture. 
  • Automation: PowerShell, Bash, and Python for baselines, hardening, and evidence capture. 

Security Evaluations (Software/Hardware) 

  • Tool & hardware reviews: Perform security evaluations of software tools and hardware (pre-procurement and periodic) to ensure compliance with CMMC/NIST controls and internal standards. 
  • Standards & artifacts: Assess against benchmarks, DISA STIGs, vendor hardening guides; verify SBOMs, patch cadence, logging/telemetry, data residency, encryption, and identity integrations (SSO/MFA/SCIM). 
  • 3rd-party risk: Run security questionnaires, review pen-test/SOC 2/FedRAMP reports, and document compensating controls and residual risk. 

Compliance, Audit & Risk 

  • Framework ownership: CMMC, NIST 800-171/53, CSF; support FedRAMP alignment where applicable. 
  • Documentation: Maintain SSP, POA&M, policies/standards, diagrams, data flows, and objective evidence mapped to practices. 
  • Assessments & audits: Internal audits, vendor risk reviews, external assessor support. 
  • Training & awareness: Security and CUI handling enablement across teams. 

On-Site Responsibilities 

  • Hands-on enclave access/process support, break/fix triage, and lab/office network hygiene. 
  • Vendor/tooling evaluation, renewals, and contracts that meet security/compliance needs. 

Required Qualifications 

  • 5+ years in IT operations/service management and security within regulated/public-sector or similar environments. 
  • CMMC/NIST 800-171 leadership (gap analysis, remediation, evidence, assessor readiness). 
  • M365 administration (Entra ID/SSO, Intune, Exchange, SharePoint/OneDrive) and endpoint management. 
  • SecOps: SIEM, vulnerability management, incident response; strong network security fundamentals. 
  • Scripting/automation: PowerShell, Bash, and/or Python. 
  • Communication & leadership: Clear writing, stakeholder influence, cross-team enablement. 
  • Education: Bachelor’s in CS/IT/Cybersecurity or equivalent experience. 
  • US Citizenship required. 

Preferred Qualifications

  • CISSP, CISM, Security+, or audit certs (e.g., CISA). 
  • Experience with container hardening and Terraform/Kubernetes governance (policy/admission controls)—advisory/controls focus. 
  • Familiarity with FedRAMP, DoD IL4/IL5 expectations and evidence workflows. 
  • Project management experience running multi-team initiatives. 

Nice to Have Qualifications:

  • Exposure to spatial/immersive tech or game-engine security. 
  • Cloud or full-stack development experience (for automation/internal tools). 
  • Experience supporting public-sector customers and responding to RFP/security questionnaires.