1

Cmmc Audit Jobs (NOW HIRING)

$110 - $180/hr

Consultant, Internal Audit Date: Aug 22, 2026 Summary Celestica is the brand behind the brands you ... Working knowledge of NIST SP 800-171, CMMC 2.0 framework, and related DoD cybersecurity policy

Consultant, Internal Audit

Plano, TX · On-site

$110 - $180/hr

Consultant, Internal Audit Date: Aug 22, 2026 Summary Celestica is the brand behind the brands you ... Working knowledge of NIST SP 800-171, CMMC 2.0 framework, and related DoD cybersecurity policy

NSF is currently seeking a Senior Auditor, CMMC, to conduct third-party audits for our CMMC clients. In this role, you will be responsible for effective communication with both external clients and ...

Perform complex, senior-level auditing and advisory work to develop a new audit program and processes for SOC2 and Department of Defense (DOD) Cybersecurity Maturity Model Certification (CMMC ...

NSF is currently seeking a Senior Auditor, CMMC, to conduct third-party audits for our CMMC clients. In this role, you will be responsible for effective communication with both external clients and ...

NSF is currently seeking a Senior Auditor, CMMC, to conduct third-party audits for our CMMC clients. In this role, you will be responsible for effective communication with both external clients and ...

Showing results 41-60

Cmmc Audit information

See salary details

$61K

$120.2K

$157.5K

How much do cmmc audit jobs pay per year?

As of Aug 30, 2026, the average yearly pay for cmmc audit in the United States is $120,236.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,000.00 and $136,500.00 per year, depending on experience, location, and employer.

What is a CMMC audit?

A CMMC audit is a formal assessment conducted to determine if an organization meets the cybersecurity requirements outlined in the Cybersecurity Maturity Model Certification (CMMC) framework. This framework was developed by the U.S. Department of Defense to safeguard sensitive information within the defense industrial base. During the audit, a certified third-party assessor evaluates the organization's policies, processes, and technical controls to ensure compliance with the specific CMMC level required for their contracts. Successfully passing a CMMC audit is mandatory for contractors and subcontractors working with the DoD. The audit process helps organizations identify gaps in their cybersecurity posture and implement necessary improvements.

What are the key skills and qualifications needed to thrive as a CMMC auditor?

To thrive as a CMMC Auditor, you need a deep understanding of cybersecurity frameworks, risk management, and compliance standards, often supported by related degrees and cybersecurity certifications such as CISA, CISSP, or CMMC Provisional Assessor. Familiarity with audit management software, NIST SP 800-171 controls, and CMMC assessment tools is typically required. Strong analytical thinking, communication, and attention to detail are crucial soft skills for interpreting requirements and engaging with clients. These skills ensure accurate, thorough assessments and help organizations achieve and maintain compliance with CMMC requirements.

What are some common challenges faced by professionals conducting a CMMC audit, and how can they be addressed?

CMMC auditors often encounter challenges such as varying levels of cybersecurity maturity across organizations, incomplete documentation, and resistance to change within client teams. To address these, auditors need strong communication skills to clearly explain requirements, collaborate closely with client stakeholders, and adapt auditing approaches to different organizational structures. Staying up-to-date with evolving CMMC standards and maintaining meticulous records also help ensure a thorough and efficient audit process.

What is the difference between Cmmc Audit vs Cmmc Consultant?

AspectCmmc AuditCmmc Consultant
CertificationsRequires CMMC Auditor CertificationRequires CMMC Consultant Certification
Work EnvironmentConducts assessments, audits, and compliance reviewsProvides advisory, gap analysis, and implementation support
Employer & Industry UsagePrimarily in government contracting firms needing auditsConsulting firms and contractors seeking CMMC guidance

While both roles focus on CMMC compliance, Cmmc Auditors primarily perform assessments and audits to verify compliance, whereas Cmmc Consultants offer strategic advice and support for achieving CMMC standards. Understanding these differences helps organizations choose the right professional for their cybersecurity needs.

How to become a CMMC auditor?

To become a CMMC auditor, individuals typically need a background in cybersecurity, information technology, or related fields, along with experience in security assessments. They must complete specific CMMC auditor training and certification programs approved by the CMMC Accreditation Body (CMMC-AB), which include passing exams and demonstrating knowledge of CMMC requirements and assessment procedures.

Who performs CMMC audits?

CMMC audits are performed by certified third-party assessment organizations (C3PAOs) authorized by the Cybersecurity Maturity Model Certification Accreditation Body. These auditors are trained to evaluate a company's cybersecurity practices and compliance with CMMC requirements, often requiring specific certifications and experience in cybersecurity and auditing. The process involves a thorough review of security controls, documentation, and implementation to ensure adherence to CMMC standards.
More about Cmmc Audit jobs

What cities are hiring for Cmmc Audit jobs?

Cities with the most Cmmc Audit job openings:

What states have the most Cmmc Audit jobs?

States with the most job openings for Cmmc Audit jobs include:

Infographic showing various Cmmc Audit job openings in the United States as of August 2026, with employment types broken down into 1% Internship, 92% Full Time, 5% Part Time, and 2% Contract. Highlights an 84% Physical, 7% Hybrid, and 9% Remote job distribution, with an average salary of $120,236 per year, or $57.8 per hour.

Full-time

Re-posted 7 days ago


Celestica rating

8.8

Company rating: 8.8 out of 10

Based on 8 frontline employees who took The Breakroom Quiz

14th of 159 rated electronics manufacturers


Job description

Req ID: 138942 
Region: Americas 
Country: USA 
State/Province: Texas 
City:  Plano 

Summary

Celestica is the brand behind the brands you love in cutting-edge technology solutions, partnering with some of the world's largest companies across diverse sectors like tech, enterprise, communications, automotive, aerospace & defense, HealthTech, industrial & smart energy, capital equipment, consumer, and robotics. Within this high-tech global landscape, our leadership relies on IT Internal Audit to objectively evaluate risk management controls and provide value-added recommendations that maintain our world-class standards. As the Consultant, Internal Audit, IT you apply your expertise in IT systems and infrastructure to ensure the adequacy and reliability of internal controls. You tackle problems requiring evaluation of data and security factors to minimize risk exposure. Operating as a Level 10 leader, you have the autonomy to deliver on team goals, influence management on significant technology issues, and resolve conflicts with tact and diplomacy across our global operations in the Americas, Europe, and Asia.

Responsibilities
  • Strategic IT Audit Leadership: Lead and conduct comprehensive IT audits and reviews of systems, applications, and IT processes. You are responsible for audits involving new acquisitions and the implementation of emerging technology audits with no prior history or background.
  • Security & Infrastructure Oversight: Conduct IT security audits across applications (ERP/SAP, Shop-floor, Quality systems), networks, operating systems, and databases. You evaluate security vulnerabilities and coordinate audit scopes with business units and external security experts. You will also lead assessments of NIST SP 800-171 and Cybersecurity Maturity Model Certification (CMMC) compliance.
  • Risk Management Advisory: Provide IT management with guidance on IT risk management, specifically regarding application and infrastructure security. You design risk and control matrices based on evaluations of underlying business risks.
  • SOX & Compliance Testing: Perform and review SOX effectiveness testing of IT key controls. You oversee the testing of IT General Controls (ITGC), application controls, and key reports identified during the walkthrough process.
  • Systems Implementation Reviews: Perform pre- and post-implementation reviews of major system enhancements or new global deployments to ensure control integrity from the design phase through to go-live.
  • Stakeholder & Relationship Management: Interface with senior managers on issues related to your area of IT expertise. You coordinate with management to formulate action plans and lead follow-up activities to verify the resolution of identified deficiencies.
  • Annual Audit Planning: Participate in the formulation of the annual audit plan, defining the scope, purpose, and objectives of IT-specific audits. You act as a liaison to outsourced internal auditors and provide IT support to operational auditors.
  • Liaison & Influence: Interact with and influence management on significant IT and security issues, ensuring that cost-effective solutions are implemented to improve controls and enhance business operations.
Critical Skills

The ideal candidate for this role will have:

  • IT Control Knowledge: Experience in IT General Controls (ITGC) related to logical/physical security, change management, business continuity, and network layers.
  • Technical Infrastructure Knowledge: Understanding of complex IT infrastructures, including cloud-based solutions (Google Cloud, Azure, and AWS platforms) and networking (firewalls, routers, active directory).
  • Information Security Expertise: Knowledge of security standards (ISO-27000 series), frameworks (COBIT, NIST, COSO), and the current enterprise threat landscape as it relates to global manufacturing.
  • ERP Proficiency: Experience auditing SAP or similar integrated business applications and their interfaces is a plus.
  • Analytical Problem Solving: Ability to evaluate diverse factors and build business cases to provide high-impact recommendations to senior leadership.
  • Communication & Diplomacy: Ability to communicate findings to "busy" auditees and management with tact, ensuring a collaborative approach to remediation.
Education
  • Bachelor's degree in Computer Science, Information Systems, Business Administration, or Accounting is required.
  • CISA (Certified Information Systems Auditor) or CISSP (Certified Information Systems Security Professional) designation is required.
Experience
  • Typically requires 6-8 years of applicable experience in IT audit, information security, or IT risk management, preferably within a global manufacturing environment.
  • Experience conducting cybersecurity assessments, audits, or compliance evaluations
  • Working knowledge of NIST SP 800-171, CMMC 2.0 framework, and related DoD cybersecurity policy
  • Familiarity with cloud environments (e.g., GovCloud, Microsoft 365 GCC/GCC High) and their CMMC implications
  • Proven track record of managing or supporting IT audits and providing recommendations to senior leadership.
Notes

This job description is not intended to be an exhaustive list of all duties and responsibilities of the position. Employees are held accountable for all duties of the job. Job duties and the % of time identified for any function are subject to change at any time.

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Celestica's policy on equal employment opportunity prohibits discrimination based on race, color, creed, religion, national origin, gender, sexual orientation, gender identity, age, marital status, veteran or disability status, or other characteristics protected by law. 
This policy applies to hiring, promotion, discharge, pay, fringe benefits, job training, classification, referral and other aspects of employment and also states that retaliation against a person who files a charge of discrimination, participates in a discrimination proceeding, or otherwise opposes an unlawful employment practice will not be tolerated. All information will be kept confidential according to EEO guidelines.

COMPANY OVERVIEW:

Celestica, Inc. (NYSE: CLS; TSX: CLS) is a technology leader dedicated to driving customer success and market advancements. With deep expertise in design, engineering, manufacturing, supply chain, and platform solutions, Celestica enables critical data center infrastructure for AI, cloud, and hybrid cloud and advances technologies in high-growth markets. With a talented team and a strategic global network, Celestica helps its customers achieve competitive advantages.

Today, Celestica delivers innovative supply chain solutions globally to customers in strategic two operating and reporting segments:  Advanced Technology Solutions (ATS) and Connectivity and Cloud Solutions (CC):

ATS: This segment serves customers in complex, regulated and high-reliability markets such as Industrial & Smart Energy, Aerospace & Defense, Semiconductor Capital Equipment, and HealthTech. It is engineering led, with deep expertise in design, manufacturing and lifecycle solutions.

CCS: This segment focuses on high-performance technology solutions and services for the data center, serving hyperscalers, digital native customers and enterprises. Celestica's Platform Solutions offering provides innovative and customizable computing, storage and networking solutions enabling AI-driven growth.

Built on a legacy of trust and performance, Celestica has earned its reputation by delivering results in complex and fast-changing markets. Celestica exceeds customer expectations by identifying trends and staying ahead of the curve. Backed by comprehensive capabilities and a global network across North America, Europe and Asia, Celestica helps customers gain competitive advantage with the quality, flexibility and resiliency they need to respond quickly to shifts in demand. Guided by a bold vision to accelerate market advancements, Celestica delivers innovative solutions and technologies that turn complexity into opportunity. Anchored in teamwork and commitment, Celestica strives to be the most trusted partner to its customers and colleagues worldwide.

Celestica would like to thank all applicants, however, only qualified applicants will be contacted.
Celestica does not accept unsolicited resumes from recruitment agencies or fee based recruitment services.

This location is a US ITAR facility and these positions will involve the release of export controlled goods either directly to employees or through the employee's movement within the facility. As such, Celestica will require necessary information from all applicants upon an applicant's acceptance of employment to determine if any export control exemptions or licenses must be filed.


What Celestica employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom