1

Cmmc Audit Jobs (NOW HIRING)

Governance, Risk & Compliance • Lead internal audits, control testing, and continuous monitoring ... CMMC practices and security best practices. • Foster a culture of security awareness and ...

Lead Network Engineer

$103K - $143K/yr

Support CMMC audit readiness activities, including documentation and evidence collection * Participate in vendor evaluation and selection for networking hardware, services, and connectivity solutions

Draft, review, and audit security policies, procedures, and supporting evidence for clients and ... Stay up-to-date on CMMC requirements, regulatory changes, and industry best practices.

Prepare comprehensive audit reports, including findings, recommendations, and remediation plans, following CMMC-AB standards. * Collaborate with a C3PAO (CMMC Third-Party Assessment Organization) to ...

Smithers is an authorized CMMC Third-Party Assessment Organization (C3PAO) in the CMMC ecosystem ... Writes and submits audit reports to meet certifications requirements. * Maintain timely ...

PA

$99K - $165K/yr

The CMMC Compliance Manager will play a critical role in maintaining and enhancing our ... Conduct regular audits and assessments to identify and mitigate cybersecurity risks and ...

New

Smithers is an authorized CMMC Third-Party Assessment Organization (C3PAO) in the CMMC ecosystem ... Writes and submits audit reports to meet certifications requirements. * Maintain timely ...

SUMMARY: Manages and tracks audit activities for assigned clients and auditors. Supporting ... Must be a ISACA CMMC Certified Professional in good standing. ESSENTIAL DUTIES AND RESPONSIBILITIES:

SUMMARY: Manages and tracks audit activities for assigned clients and auditors. Supporting ... Must be a ISACA CMMC Certified Professional in good standing. ESSENTIAL DUTIES AND RESPONSIBILITIES:

DBT Sr. PM CMMC Specialist

Arlington, VA · Hybrid

$94K - $130K/yr

Interpret CMMC practices and objectives and translate requirements into structured, actionable ... Experience preparing for and supporting external regulatory assessments or certification audits.

next page

Showing results 1-20

Cmmc Audit information

See salary details

$61K

$120.2K

$157.5K

How much do cmmc audit jobs pay per year?

As of Jun 10, 2026, the average yearly pay for cmmc audit in the United States is $120,236.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,000.00 and $136,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a CMMC Auditor, and why are they important?

To thrive as a CMMC Auditor, you need a deep understanding of cybersecurity frameworks, risk management, and compliance standards, often supported by related degrees and cybersecurity certifications such as CISA, CISSP, or CMMC Provisional Assessor. Familiarity with audit management software, NIST SP 800-171 controls, and CMMC assessment tools is typically required. Strong analytical thinking, communication, and attention to detail are crucial soft skills for interpreting requirements and engaging with clients. These skills ensure accurate, thorough assessments and help organizations achieve and maintain compliance with CMMC requirements.

What is the difference between Cmmc Audit vs Cmmc Consultant?

AspectCmmc AuditCmmc Consultant
CertificationsRequires CMMC Auditor CertificationRequires CMMC Consultant Certification
Work EnvironmentConducts assessments, audits, and compliance reviewsProvides advisory, gap analysis, and implementation support
Employer & Industry UsagePrimarily in government contracting firms needing auditsConsulting firms and contractors seeking CMMC guidance

While both roles focus on CMMC compliance, Cmmc Auditors primarily perform assessments and audits to verify compliance, whereas Cmmc Consultants offer strategic advice and support for achieving CMMC standards. Understanding these differences helps organizations choose the right professional for their cybersecurity needs.

What is a CMMC audit?

A CMMC audit is a formal assessment conducted to determine if an organization meets the cybersecurity requirements outlined in the Cybersecurity Maturity Model Certification (CMMC) framework. This framework was developed by the U.S. Department of Defense to safeguard sensitive information within the defense industrial base. During the audit, a certified third-party assessor evaluates the organization's policies, processes, and technical controls to ensure compliance with the specific CMMC level required for their contracts. Successfully passing a CMMC audit is mandatory for contractors and subcontractors working with the DoD. The audit process helps organizations identify gaps in their cybersecurity posture and implement necessary improvements.

What are some common challenges faced by professionals conducting a CMMC audit, and how can they be addressed?

CMMC auditors often encounter challenges such as varying levels of cybersecurity maturity across organizations, incomplete documentation, and resistance to change within client teams. To address these, auditors need strong communication skills to clearly explain requirements, collaborate closely with client stakeholders, and adapt auditing approaches to different organizational structures. Staying up-to-date with evolving CMMC standards and maintaining meticulous records also help ensure a thorough and efficient audit process.
More about Cmmc Audit jobs
What cities are hiring for Cmmc Audit jobs? Cities with the most Cmmc Audit job openings:
What states have the most Cmmc Audit jobs? States with the most job openings for Cmmc Audit jobs include:
Infographic showing various Cmmc Audit job openings in the United States as of June 2026, with employment types broken down into 87% Full Time, and 13% Part Time. Highlights an 74% In-person, 13% Hybrid, and 13% Remote job distribution, with an average salary of $120,236 per year, or $57.8 per hour.
CMMC Security Engineer (Remote)

CMMC Security Engineer (Remote)

Red Cup IT, Inc.

Los Angeles, CA • Remote

Full-time

Posted 19 hours ago


Job description

We are looking for a CMMC Security Engineer is responsible for implementing, maintaining, and leading cybersecurity efforts to ensure compliance with the Cybersecurity Maturity Model Certification (CMMC) standards, focusing on protecting Controlled Unclassified Information (CUI) for organizations in the Defense Industrial Base (DIB).

Key Responsibilities
  • Design, implement, and monitor security controls aligned with CMMC requirements, including access controls, encryption, endpoint protection, and secure configurations.
  • Lead vulnerability assessments, scan remediation tracking, and continuous risk management across hybrid and cloud environments.
  • Support incident response, threat hunting, and forensic analysis for cybersecurity events.
  • Prepare for and facilitate CMMC assessments (self and third-party), maintain certification documentation (SSP, POA&M), and address audit findings.
  • Collaborate with compliance managers, legal/data protection officers, and operations teams to ensure continuous alignment with NIST SP 800-171/DFARS controls.
  • Oversee CMMC continuous monitoring programs and identify compliance gaps in workflows.
  • Provide security awareness training and promote a culture of cybersecurity vigilance across departments.
Required Skills
  • Deep understanding of CMMC 2.0 framework, NIST SP 800-171, and DFARS requirements.
  • Experience conducting technical assessments, vulnerability management, and implementing FedRAMP Moderate or equivalent systems for CUI.
  • Strong documentation skills for policies, procedures, and audit support.
  • Ability to communicate technical findings to both technical and non-technical stakeholders.
  • Knowledge of cloud (e.g., Azure, Microsoft 365) and on-premise security technologies.
Typical Qualifications
  • Bachelor's degree in Information Security, Computer Science, or a related field.
  • Professional certifications such as CISSP, CISM, GIAC, or CCA/CCP (CMMC-specific certifications preferred).
  • Experience supporting DoD compliance or federal contracts is highly valued.
Job Purpose

The role ensures a secure and compliant enclave for CUI, mitigates cybersecurity risks, leads compliance projects, and prepares for third-party assessments and audits under the evolving CMMC 2.0 regulations.