1

Cmmc Audit Jobs (NOW HIRING)

... a third-party audit * Conduct reviews of security artifacts and aid completing required ... Help grow Ariento's CMMC practice by contributing to the development of our capabilities ...

Be Seen First

Experience leading ongoing self-audits and updates to documentation and plans surrounding risk, compliance, IT Security, R&D Information Sharing and related areas; experience with NIST and or CMMC ...

New

Our professional services focus on security and privacy audits, assessments, and certifications ... As a CMMC Senior Associate at Schellman, you will play a critical role in delivering high-quality ...

... a third-party audit * Conduct reviews of security artifacts and aid completing required ... Help grow Ariento's CMMC practice by contributing to the development of our capabilities ...

Our professional services focus on security and privacy audits, assessments, and certifications ... As a CMMC Senior Associate at Schellman, you will play a critical role in delivering high-quality ...

We need someone who has lived in the DIB world: who understands what a CMMC Program Lead actually does, what it feels like to be a CISO at a Tier-2 sub staring at a C3PAO audit, and what language ...

We need someone who has lived in the DIB world: who understands what a CMMC Program Lead actually does, what it feels like to be a CISO at a Tier-2 sub staring at a C3PAO audit, and what language ...

Showing results 21-40

Cmmc Audit information

See salary details

$61K

$120.2K

$157.5K

How much do cmmc audit jobs pay per year?

As of Aug 16, 2026, the average yearly pay for cmmc audit in the United States is $120,236.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,000.00 and $136,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a CMMC auditor?

To thrive as a CMMC Auditor, you need a deep understanding of cybersecurity frameworks, risk management, and compliance standards, often supported by related degrees and cybersecurity certifications such as CISA, CISSP, or CMMC Provisional Assessor. Familiarity with audit management software, NIST SP 800-171 controls, and CMMC assessment tools is typically required. Strong analytical thinking, communication, and attention to detail are crucial soft skills for interpreting requirements and engaging with clients. These skills ensure accurate, thorough assessments and help organizations achieve and maintain compliance with CMMC requirements.

What is the difference between Cmmc Audit vs Cmmc Consultant?

AspectCmmc AuditCmmc Consultant
CertificationsRequires CMMC Auditor CertificationRequires CMMC Consultant Certification
Work EnvironmentConducts assessments, audits, and compliance reviewsProvides advisory, gap analysis, and implementation support
Employer & Industry UsagePrimarily in government contracting firms needing auditsConsulting firms and contractors seeking CMMC guidance

While both roles focus on CMMC compliance, Cmmc Auditors primarily perform assessments and audits to verify compliance, whereas Cmmc Consultants offer strategic advice and support for achieving CMMC standards. Understanding these differences helps organizations choose the right professional for their cybersecurity needs.

What is a CMMC audit?

A CMMC audit is a formal assessment conducted to determine if an organization meets the cybersecurity requirements outlined in the Cybersecurity Maturity Model Certification (CMMC) framework. This framework was developed by the U.S. Department of Defense to safeguard sensitive information within the defense industrial base. During the audit, a certified third-party assessor evaluates the organization's policies, processes, and technical controls to ensure compliance with the specific CMMC level required for their contracts. Successfully passing a CMMC audit is mandatory for contractors and subcontractors working with the DoD. The audit process helps organizations identify gaps in their cybersecurity posture and implement necessary improvements.

What are some common challenges faced by professionals conducting a CMMC audit, and how can they be addressed?

CMMC auditors often encounter challenges such as varying levels of cybersecurity maturity across organizations, incomplete documentation, and resistance to change within client teams. To address these, auditors need strong communication skills to clearly explain requirements, collaborate closely with client stakeholders, and adapt auditing approaches to different organizational structures. Staying up-to-date with evolving CMMC standards and maintaining meticulous records also help ensure a thorough and efficient audit process.
More about Cmmc Audit jobs

What cities are hiring for Cmmc Audit jobs?

Cities with the most Cmmc Audit job openings:

What states have the most Cmmc Audit jobs?

States with the most job openings for Cmmc Audit jobs include:

Infographic showing various Cmmc Audit job openings in the United States as of August 2026, with employment types broken down into 1% Internship, 90% Full Time, 5% Part Time, 1% Temporary, and 3% Contract. Highlights an 86% Physical, 6% Hybrid, and 8% Remote job distribution, with an average salary of $120,236 per year, or $57.8 per hour.

CMMC Technical Analyst

Point Blank Enterprises Inc

Pompano Beach, FL โ€ข On-site

Full-time

Re-posted 3 days ago


Job description

The CMMC Technical Analyst is responsible for supporting the protection and management of Controlled Unclassified Information (CUI) and ensuring compliance with CMMC best practices. This role provides advanced technical support, contributes to cybersecurity projects, and maintains compliance documentation and evidence repositories to support audit readiness.

Essential Job Duties

Technical & Operational Support

  • Provide Level 2 technical support, including in‑depth diagnostics, root‑cause analysis, system configuration, and network troubleshooting.
  • Maintain accurate hardware and software inventory.
  • Maintain and update the help desk application to support activity tracking and reporting.
  • Ensure all IT operations support corporate objectives and cybersecurity requirements.

CUI Management & Compliance

  • Maintain proficiency in CUI handling requirements and ensure compliance with all applicable regulations.
  • Monitor changes in federal cybersecurity laws, standards, and frameworks related to CUI protection.
  • Ensure organizational policies reflect current regulatory and contractual obligations.

Frameworks & Standards

  • Demonstrate expert knowledge of NIST standards, including NIST SP 800‑171.
  • Apply expert understanding of CMMC 2.0 requirements to support compliance initiatives.
  • Implement and optimize programs aligned with NIST SP 800‑171, CMMC, FedRAMP, and related frameworks.

Documentation & Audit Readiness

  • Develop and maintain System Security Plans (SSPs), POA&Ms, and other compliance artifacts.
  • Maintain evidence repositories, compliance dashboards, and control libraries.
  • Analyze audit findings and continuous monitoring data to assess impacts on cybersecurity maturity.
  • Lead drafting, revision, and lifecycle management of IT policies, procedures, and memos.

Risk, Monitoring & Detection

  • Perform risk assessments, vulnerability analyses, threat modeling, and control testing.
  • Demonstrate proficiency with SIEM platforms, supporting log analysis and monitoring.
  • Support continuous monitoring activities to detect threats, including insider threat indicators.

Cloud, Automation & Systems

  • Demonstrate proficiency with Government Cloud environments (e.g., GCC High, GovCloud).
  • Utilize automation and scripting to streamline compliance and operational processes.
  • Assist the Systems and Network Manager with cybersecurity projects and implementations.

Collaboration & Communication

  • Collaborate with business units to ensure systems, services, and vendors comply with safeguarding requirements.
  • Translate complex technical and compliance information into clear, actionable guidance for non‑technical stakeholders.
  • Train and assist IT support specialists on cybersecurity policies and compliance requirements.

General Responsibilities

  • Adhere to internal IT procedures and recommend improvements as needed.
  • Follow all company safety and quality standards.
  • Maintain a clean, safe, and organized work environment.
  • Perform other related duties as assigned.

Security & Compliance Requirements

  • Must be a U.S. Person as defined by ITAR (U.S. citizen, lawful permanent resident, or protected individual).
  • Must meet eligibility requirements for access to Controlled Unclassified Information (CUI).
  • Must pass all required background screenings.

Qualifications

  • Bachelor’s degree in computer science, Cybersecurity, Information Technology, or a related discipline.
  • Must be a U.S. citizen and able to pass a background check.
  • Minimum of 5 years of experience in Cybersecurity, Security Analysis, or a related field.
  • Industry-recognized certifications preferred, such as CISM, CASP+, CISSP, CISA, Security+, or equivalent credentials.
  • Strong proficiency in English, with the ability to speak, read, and write at a professional level.

Work Environment & Additional Requirements

  • Occasional travel may be required.
  • Availability for after‑hours support during critical compliance activities.
  • Prolonged periods of sitting and computer use.
  • Occasional lifting of up to 25 lbs.

Please note: This position is fully onsite at our corporate office. Applicants must be able to attend an in‑person interview and work onsite.