1

Cmmc Audit Jobs (NOW HIRING)

As the Consultant, Internal Audit, IT you apply your expertise in IT systems and infrastructure to ... Working knowledge of NIST SP 800-171, CMMC 2.0 framework, and related DoD cybersecurity policy

NSF is currently seeking a Senior Auditor, CMMC, to conduct third-party audits for our CMMC clients. In this role, you will be responsible for effective communication with both external clients and ...

NSF is currently seeking a Senior Auditor, CMMC, to conduct third-party audits for our CMMC clients. In this role, you will be responsible for effective communication with both external clients and ...

NSF is currently seeking a Senior Auditor, CMMC, to conduct third-party audits for our CMMC clients. In this role, you will be responsible for effective communication with both external clients and ...

NSF is currently seeking a Senior Auditor, CMMC, to conduct third-party audits for our CMMC clients. In this role, you will be responsible for effective communication with both external clients and ...

NSF is currently seeking a Senior Auditor, CMMC, to conduct third-party audits for our CMMC clients. In this role, you will be responsible for effective communication with both external clients and ...

Showing results 41-60

Cmmc Audit information

See salary details

$61K

$120.2K

$157.5K

How much do cmmc audit jobs pay per year?

As of Aug 16, 2026, the average yearly pay for cmmc audit in the United States is $120,236.00, according to ZipRecruiter salary data. Most workers in this role earn between $104,000.00 and $136,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a CMMC auditor?

To thrive as a CMMC Auditor, you need a deep understanding of cybersecurity frameworks, risk management, and compliance standards, often supported by related degrees and cybersecurity certifications such as CISA, CISSP, or CMMC Provisional Assessor. Familiarity with audit management software, NIST SP 800-171 controls, and CMMC assessment tools is typically required. Strong analytical thinking, communication, and attention to detail are crucial soft skills for interpreting requirements and engaging with clients. These skills ensure accurate, thorough assessments and help organizations achieve and maintain compliance with CMMC requirements.

What is the difference between Cmmc Audit vs Cmmc Consultant?

AspectCmmc AuditCmmc Consultant
CertificationsRequires CMMC Auditor CertificationRequires CMMC Consultant Certification
Work EnvironmentConducts assessments, audits, and compliance reviewsProvides advisory, gap analysis, and implementation support
Employer & Industry UsagePrimarily in government contracting firms needing auditsConsulting firms and contractors seeking CMMC guidance

While both roles focus on CMMC compliance, Cmmc Auditors primarily perform assessments and audits to verify compliance, whereas Cmmc Consultants offer strategic advice and support for achieving CMMC standards. Understanding these differences helps organizations choose the right professional for their cybersecurity needs.

What is a CMMC audit?

A CMMC audit is a formal assessment conducted to determine if an organization meets the cybersecurity requirements outlined in the Cybersecurity Maturity Model Certification (CMMC) framework. This framework was developed by the U.S. Department of Defense to safeguard sensitive information within the defense industrial base. During the audit, a certified third-party assessor evaluates the organization's policies, processes, and technical controls to ensure compliance with the specific CMMC level required for their contracts. Successfully passing a CMMC audit is mandatory for contractors and subcontractors working with the DoD. The audit process helps organizations identify gaps in their cybersecurity posture and implement necessary improvements.

What are some common challenges faced by professionals conducting a CMMC audit, and how can they be addressed?

CMMC auditors often encounter challenges such as varying levels of cybersecurity maturity across organizations, incomplete documentation, and resistance to change within client teams. To address these, auditors need strong communication skills to clearly explain requirements, collaborate closely with client stakeholders, and adapt auditing approaches to different organizational structures. Staying up-to-date with evolving CMMC standards and maintaining meticulous records also help ensure a thorough and efficient audit process.
More about Cmmc Audit jobs

What cities are hiring for Cmmc Audit jobs?

Cities with the most Cmmc Audit job openings:

What states have the most Cmmc Audit jobs?

States with the most job openings for Cmmc Audit jobs include:

Infographic showing various Cmmc Audit job openings in the United States as of August 2026, with employment types broken down into 1% Internship, 90% Full Time, 5% Part Time, 1% Temporary, and 3% Contract. Highlights an 86% Physical, 6% Hybrid, and 8% Remote job distribution, with an average salary of $120,236 per year, or $57.8 per hour.

CMMC Technical Analyst

Point Blank Enterprises, Inc.

Pompano Beach, FL • On-site

Full-time

Re-posted 3 days ago


Job description

Job Summary:
Point Blank Enterprises, Inc. is seeking a CMMC Technical Analyst to support the protection and management of Controlled Unclassified Information (CUI) and ensure compliance with CMMC best practices. The role involves providing technical support, contributing to cybersecurity projects, and maintaining compliance documentation to support audit readiness.
Responsibilities:
• Provide Level 2 technical support, including in‑depth diagnostics, root‑cause analysis, system configuration, and network troubleshooting.
• Maintain accurate hardware and software inventory.
• Maintain and update the help desk application to support activity tracking and reporting.
• Ensure all IT operations support corporate objectives and cybersecurity requirements.
• Maintain proficiency in CUI handling requirements and ensure compliance with all applicable regulations.
• Monitor changes in federal cybersecurity laws, standards, and frameworks related to CUI protection.
• Ensure organizational policies reflect current regulatory and contractual obligations.
• Demonstrate expert knowledge of NIST standards, including NIST SP 800‑171.
• Apply expert understanding of CMMC 2.0 requirements to support compliance initiatives.
• Implement and optimize programs aligned with NIST SP 800‑171, CMMC, FedRAMP, and related frameworks.
• Develop and maintain System Security Plans (SSPs), POA&Ms, and other compliance artifacts.
• Maintain evidence repositories, compliance dashboards, and control libraries.
• Analyze audit findings and continuous monitoring data to assess impacts on cybersecurity maturity.
• Lead drafting, revision, and lifecycle management of IT policies, procedures, and memos.
• Perform risk assessments, vulnerability analyses, threat modeling, and control testing.
• Demonstrate proficiency with SIEM platforms, supporting log analysis and monitoring.
• Support continuous monitoring activities to detect threats, including insider threat indicators.
• Demonstrate proficiency with Government Cloud environments (e.g., GCC High, GovCloud).
• Utilize automation and scripting to streamline compliance and operational processes.
• Assist the Systems and Network Manager with cybersecurity projects and implementations.
• Collaborate with business units to ensure systems, services, and vendors comply with safeguarding requirements.
• Translate complex technical and compliance information into clear, actionable guidance for non‑technical stakeholders.
• Train and assist IT support specialists on cybersecurity policies and compliance requirements.
• Adhere to internal IT procedures and recommend improvements as needed.
• Follow all company safety and quality standards.
• Maintain a clean, safe, and organized work environment.
• Perform other related duties as assigned.
Qualifications:
Required:
• Bachelor’s degree in computer science, Cybersecurity, Information Technology, or a related discipline.
• Must be a U.S. citizen and able to pass a background check.
• Minimum of 5 years of experience in Cybersecurity, Security Analysis, or a related field.
• Strong proficiency in English, with the ability to speak, read, and write at a professional level.
• Must be a U.S. Person as defined by ITAR (U.S. citizen, lawful permanent resident, or protected individual).
• Must meet eligibility requirements for access to Controlled Unclassified Information (CUI).
• Must pass all required background screenings.
Preferred:
• Industry-recognized certifications preferred, such as CISM, CASP+, CISSP, CISA, Security+, or equivalent credentials.
• Occasional travel may be required.
• Availability for after‑hours support during critical compliance activities.
• Prolonged periods of sitting and computer use.
• Occasional lifting of up to 25 lbs.
Company:
Point Blank Enterprises, Inc. Founded in 2011, the company is headquartered in Pompano Beach, USA, with a team of 1001-5000 employees. The company is currently Late Stage.