1

Cmmc Assessor Jobs (NOW HIRING)

$125 - $195/hr

Lead annual CMMC self-assessments, risk assessments, internal audits, certification readiness activities, and coordination with Certified Third-Party Assessment Organizations (C3PAOs) for external ...

New

Our professional services focus on security and privacy audits, assessments, and certifications ... As a CMMC Senior Associate at Schellman, you will play a critical role in delivering high-quality ...

CMMC Program Manager

Falls Church, VA · On-site

$123K - $124K/yr

Lead annual CMMC self-assessments, risk assessments, internal audits, certification readiness activities, and coordination with Certified Third-Party Assessment Organizations (C3PAOs) for external ...

Our professional services focus on security and privacy audits, assessments, and certifications ... As a CMMC Senior Associate at Schellman, you will play a critical role in delivering high-quality ...

Develop an understanding of how technical implementations support CMMC assessment requirements. Engineering Operations & Troubleshooting * Perform routine maintenance and operational tasks for ...

Only candidates qualified to conduct CMMC assessments will be considered. #LI-EA1 With a legacy spanning more than 80 years, NSF leverages science and innovation to improve human and planet health.

Plan and conduct all assessment activities, including documentation reviews, CMMC Level 1 or Level 2 assessments, as well as intake calls and scoping discussions * Participate in the selection of ...

Only candidates qualified to conduct CMMC assessments will be considered. #LI-EA1 With a legacy spanning more than 80 years, NSF leverages science and innovation to improve human and planet health.

Conduct readiness/consulting services directly with our clients to assess their cybersecurity ... Help grow Ariento's CMMC practice by contributing to the development of our capabilities ...

Conduct readiness/consulting services directly with our clients to assess their cybersecurity ... Help grow Ariento's CMMC practice by contributing to the development of our capabilities ...

IT Manager

Knoxville, TN · On-site

$90K - $111K/yr

Certified CMMC Professional (CCP) or Certified CMMC Assessor (CCA) Microsoft Certified: Azure Solutions Architect Expert / Enterprise Administrator Expert CISSP (Certified Information Systems ...

$120 - $180/hr

Perform detailed readiness assessments and gap analyses to prepare client environments for Joint ... CMMC and NIST framework generalist - Grounded in the structural requirements of CMMC 2.0 and NIST ...

New

CMMC Compliance Manager

Denver, CO · On-site

$127 - $175/hr

The CMMC Compliance Manager will be responsible for supporting the company's U.S. government ... S.-based operations, with accountability for readiness, assessment preparation, and ongoing ...

New

Showing results 41-60

Cmmc Assessor information

See salary details

$32.5K

$75.3K

$125.5K

How much do cmmc assessor jobs pay per year?

As of Sep 4, 2026, the average yearly pay for cmmc assessor in the United States is $75,259.00, according to ZipRecruiter salary data. Most workers in this role earn between $46,000.00 and $97,000.00 per year, depending on experience, location, and employer.

What is a CMMC Assessor?

A CMMC Assessor is a certified professional responsible for evaluating an organization's cybersecurity practices against the Cybersecurity Maturity Model Certification (CMMC) framework. They conduct assessments to ensure compliance with cybersecurity requirements set by the Department of Defense (DoD) for contractors handling Controlled Unclassified Information (CUI). CMMC Assessors work with Certified Third-Party Assessment Organizations (C3PAOs) to perform audits, document findings, and provide recommendations for achieving the necessary certification level. Their role is critical in helping organizations secure government contracts by verifying their adherence to required cybersecurity standards.

What does a CMMC Assessor do?

A typical day for a CMMC Assessor involves reviewing cybersecurity policies, conducting in-depth interviews with client personnel, examining technical controls, and documenting assessment findings. CMMC Assessors often work on-site at client locations or remotely, collaborating closely with IT teams and management to validate controls and clarify requirements. The role frequently includes preparing reports, communicating results to stakeholders, and recommending remediation steps where necessary. This position is detail-oriented and dynamic, offering a mix of independent work and teamwork while supporting organizations in achieving and maintaining CMMC certification.

What are the key skills and qualifications needed to thrive as a CMMC Assessor?

To thrive as a CMMC Assessor, you need a comprehensive understanding of cybersecurity frameworks, risk management, and the CMMC (Cybersecurity Maturity Model Certification) standard, typically demonstrated by industry experience and relevant certifications such as CMMC-AB Certified Assessor or CISSP. Familiarity with assessment tools, audit software, and NIST frameworks is critical for evaluating organizations' compliance. Strong analytical thinking, attention to detail, and excellent communication skills help explain findings and recommendations to clients. These skills and qualities are essential for ensuring accurate, credible assessments and guiding organizations toward regulatory compliance.

How to become a CMMC assessor?

To become a CMMC assessor, individuals typically need relevant experience in cybersecurity, auditing, or compliance, along with specific training provided by authorized bodies such as the CMMC Accreditation Body. They must complete assessor training courses, pass certification exams, and demonstrate knowledge of CMMC requirements and assessment procedures. Maintaining ongoing education and recertification is also necessary to stay current with evolving standards.
More about Cmmc Assessor jobs

What cities are hiring for Cmmc Assessor jobs?

Cities with the most Cmmc Assessor job openings:

What are the most commonly searched types of Cmmc Assessor jobs?

The most popular types of Cmmc Assessor jobs are:

What states have the most Cmmc Assessor jobs?

States with the most job openings for Cmmc Assessor jobs include:

What job categories do people searching Cmmc Assessor jobs look for?

The top searched job categories for Cmmc Assessor jobs are:

Infographic showing various Cmmc Assessor job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 87% Full Time, 6% Part Time, 2% Temporary, and 4% Contract. Highlights an 87% Physical, 3% Hybrid, and 10% Remote job distribution, with an average salary of $75,259 per year, or $36.2 per hour.

$125 - $195/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 3 days ago

New


Key responsibilities

  • Serve as the organization's primary internal authority for CMMC compliance and provide guidance on FCI, CUI, and related governance requirements.

  • Own and manage the organization's CMMC compliance program, including developing, reviewing, and maintaining policies, standards, and procedures.

  • Lead assessments, audits, and certification activities related to CMMC compliance, including internal evaluations and coordination with external assessment organizations.


Balfour Beatty US rating

6.8

Company rating: 6.8 out of 10

Based on 50 frontline employees who took The Breakroom Quiz

58th of 80 rated construction


Job description

Our Benefits

Balfour Beatty offers employees a comprehensive compensation and benefit package:

  • Medical, Dental, Vision and Life Insurance
  • Health Savings Account
  • 401(k) with company match
  • Paid time off
  • Tuition Assistance
  • Employee Referral Bonus
  • And more!
Summary

Balfour Beatty Construction, LLC (Company), a member of the Balfour Beatty plc group of companies, is searching for a CMMC Program Manager to support its compliance with cyber and physical security requirements for Federal Contract Information (FCI) and Controlled Unclassified Information (CUI) associated with the Company’s Federal construction contracts, as well as equivalent requirements in private contracts. Candidates must have a strong working knowledge of FAR and DFARS requirements for the handling of FCI and CUI, excellent analytical, project management, communication, and organizational skills.

The selected candidate will ideally work out of our Falls Church, VA, office, but candidates based in Dallas, TX, will be considered as well. This is a hybrid position that requires working in the office three days per week and working from home two days per week.

Essential Functions
  • Serve as the organization's primary internal authority for CMMC compliance within the secure enclave, providing guidance to IT, IT Security, Operations, Human Resources, Legal, Procurement, Communications and executive leadership regarding FCI, CUI and equivalent compliance obligations and governance requirements.
  • Own the organization's CMMC compliance program for the secure enclave, ensuring governance activities remain aligned with organizational objectives, contractual obligations, regulatory requirements, and evolving cybersecurity risks.
  • Develop, maintain, and periodically review the Continuous Monitoring Plan (CMP) and support ISCM procedures.
  • Develop, review, maintain, and coordinate approval of CMMC-related policies, standards, procedures, and supporting documentation.
  • Define and manage ISCM strategy, risk tolerance, and reporting cadence in coordination with the CIO, CISO, CLO, and US Compliance Team.
  • Lead initial implementation, as well as ongoing assessment of security control effectiveness, including vulnerability identification and reporting, configuration compliance, access reviews, and incident monitoring.
  • Lead annual CMMC self-assessments, risk assessments, internal audits, certification readiness activities, and coordination with Certified Third-Party Assessment Organizations (C3PAOs) for external CMMC assessments, as applicable.
  • Present compliance status, risk posture, and strategic recommendations to executive leadership and governance committees.
  • Develop and maintain evidence repositories supporting ongoing internal assessments, external certification activities, and audit readiness.
  • Ensure compliance documentation—including the System Security Plan (SSP), POA&Ms, policies, procedures, system inventories, data flow diagrams, asset inventories, evidence repositories, and assessment records—remains complete, accurate, and current.
  • Track, report, coordinate, and validate remediation of deviations, exceptions, and findings discovered during monitoring or risk assessments.
  • Prepare metrics dashboards and executive reports summarizing enclave risk posture and compliance trends.
  • Coordinate compliance activities involving third-party service providers supporting the enclave, including review of agreements, security documentation, and shared responsibility requirements.
  • Review proposed changes to enclave architecture, systems, applications, and operational processes to evaluate potential impacts to CMMC compliance and update compliance documentation as necessary.
  • Coordinate with IT Operations and IT Security teams to ensure configuration baselines, asset inventories, and system changes remain aligned with approved security configurations and compliance requirements.
  • Coordinate or participate in periodic incident response tabletop exercises involving IT, Legal, Human Resources, Executive Leadership, and applicable business stakeholders.
  • Collect evidence management, control documentation, and audit preparation.
  • Coordinate post-incident reviews, track corrective actions, and ensure lessons learned are incorporated into security controls, policies, procedures, training, and continuous monitoring activities to improve the organization’s overall CMMC compliance posture.
  • Collaborate with internal stakeholders:
  • Business Stakeholders: program managers, project managers, and functional owners using enclave resources. Assist with onboarding, offboarding and transfers as needed.
  • Internal and secure enclave MSSP and IT Security Teams: administrators, network engineers, and analysts managing enclave systems and monitoring tools.
  • Policy and Procedure Enforcement: detect and document deviations or non-compliance, collaborate with HR and/or Legal to resolve violations, and ensure corrective or disciplinary actions are applied and recorded in accordance with organizational policy and audit requirements.
  • CMMC Training Program Management: review, develop, and adjust security awareness or role-based training content to ensure alignment with current government, DOD, and CMMC requirements and to address evolving cyber security and enclave operational risks.
  • Executive Leadership: provide compliance reporting, risk briefings, POA&M status, and recommendations for risk acceptance decisions.
  • Familiarity with export control requirements such as International Traffic in Arms Regulations and Export Administration Regulations.
  • Continuously review and improve ISCM processes, automation, and reporting frequency to align with organizational risk tolerance.
  • Facilitate risk assessments and coordinate risk acceptance activities with executive leadership where appropriate.
  • Supervise and direct security measures necessary for implementing the applicable requirements of the NISPOM and related USG security requirements to ensure the protection of classified information.
  • Establish and execute an insider threat program to gather, integrate, and report relevant and available information indicative of potential or actual insider threat.
  • Support broader Ethics & Compliance initiatives, including performing other ethics, compliance, and special projects as assigned by the Vice President, Ethics & Compliance and as workload and business needs permit.
Minimum Qualifications
  • This position requires access to export-controlled information. To comply with U.S. government regulations and contract obligations applicable so such information, all applicants must be U.S. persons under the U.S. export control regulations.
  • Bachelor’s degree in Risk Management, Compliance and Regulation, Information Security, Information Systems, or a related field. Equivalent experience working within a Department of Defense agency will also be considered.
  • 7+ years in cybersecurity, governance, risk management, compliance, or information security, including at least 3 years supporting NIST SP 800-171 related programs.
  • Hands‑on experience with NIST SP 800-137 implementation or continuous monitoring frameworks.
  • Familiarity with NIST SP 800-171, CMMC Level 1 and 2, and FAR and DFARS.
  • Demonstrated experience developing or managing System Security Plans (SSP) and POA&Ms.
  • Strong analytical, documentation, and executive‑reporting skills.
  • Ability to coordinate cross‑functional teams and enforce accountability.
  • Complete FSO training within 6 months of hire if not already completed.
  • Complete ITPSO training.
Preferred Qualifications / Certifications
  • Experience supporting Department of Defense, Federal Government, or other regulated markets with significant information security requirements.
  • CMMC: Certified CMMC Professional (CCP) or Certified CMMC Assessor (CCA) or CMMC Registered Practitioner Advanced (RPA)
  • Cyber security: Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), Security+ or CySA+
  • Experience operating in secure enclave or DoD contractor environments.
Performance Indicators
  • Timeliness and completeness of annual ISCM assessments
  • Percentage of controls with continuous monitoring coverage
  • Number of open POA&M items vs. remediation rate
  • Accuracy and quality of compliance metrics / dashboards
  • Policy and Procedure enforcement
  • Successful CMMC C3PAO recertification every 3 years
Pay Rate: $125,000-195,000/year

*This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. We may ultimately pay more or less than the posted range, and the range may be modified in the future. An employee's pay position within the salary range will be based on several factors including, but not limited to, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, shift, travel requirements, any collective bargaining agreements, and business or organizational needs. No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, incentive, or any other form of compensation that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company's sole discretion, consistent with the law and any applicable plan documents.

Balfour Beatty is an equal opportunity employer that recognizes the value of a diverse workforce. All qualified individuals will receive consideration for employment without regard to race, color, age, sex, sexual orientation, gender identity, religion, national origin, disability, veteran status, genetic information, or any other criteria protected by federal, state or local law.

#J-18808-Ljbffr

What Balfour Beatty US employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom