The Lead CMMC Certified Assessor is responsible for the performance of cybersecurity framework ... Minimum of 1 year of experience with cloud-based concepts with an emphasis on security and auditing ...
The Lead CMMC Certified Assessor is responsible for the performance of cybersecurity framework ... Minimum of 1 year of experience with cloud-based concepts with an emphasis on security and auditing ...
Corporate Quality Assurance Auditor
Madison Heights, MI · On-site
$90K - $100K/yr
Lead, manage, and maintain certification processes for AS9100 D, AS9102, AS9103, ISO 9001, CMMC 2.0 ... AS9100 D certification management and auditing * ISO 9001 compliance * NAVSEA welding standards ...
Quick apply
Corporate Quality Assurance Auditor
Madison Heights, MI · On-site
$90K - $100K/yr
Lead, manage, and maintain certification processes for AS9100 D, AS9102, AS9103, ISO 9001, CMMC 2.0 ... AS9100 D certification management and auditing * ISO 9001 compliance * NAVSEA welding standards ...
Senior FedRAMP / CMMC Security & Compliance Engineer Duration: 9+ months Location: : Remote ... Experience collaborating with external assessors, auditors, or third-party partners. * Background ...
Quick apply
Senior FedRAMP / CMMC Security & Compliance Engineer Duration: 9+ months Location: : Remote ... Experience collaborating with external assessors, auditors, or third-party partners. * Background ...
The Lead CMMC Certified Assessor is responsible for the performance of cybersecurity framework ... Minimum of 1 year of experience with cloud-based concepts with an emphasis on security and auditing ...
The Lead CMMC Certified Assessor is responsible for the performance of cybersecurity framework ... Minimum of 1 year of experience with cloud-based concepts with an emphasis on security and auditing ...
... CMMC, etc. * Review and validate compliance with organizational policies and contractual ... Recommend and implement enhancements to auditing tools and techniques. * Stay current on emerging ...
... CMMC, etc. * Review and validate compliance with organizational policies and contractual ... Recommend and implement enhancements to auditing tools and techniques. * Stay current on emerging ...
Cybersecurity Auditor
Atlanta, GA · On-site
... HIPAA, CMMC, etc. Review and validate compliance with organizational policies and contractual ... Continuous Improvement Recommend and implement enhancements to auditing tools and techniques. Stay ...
Cybersecurity Auditor
Atlanta, GA · On-site
... HIPAA, CMMC, etc. Review and validate compliance with organizational policies and contractual ... Continuous Improvement Recommend and implement enhancements to auditing tools and techniques. Stay ...
Senior Security Assessor II
Plano, TX · On-site
Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials. * Certified ...
Senior Security Assessor II
Plano, TX · On-site
Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials. * Certified ...
Senior Security Assessor II
Plano, TX · On-site
Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials. * Certified ...
Senior Security Assessor II
Plano, TX · On-site
Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials. * Certified ...
Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials. * Certified ...
Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials. * Certified ...
Senior Security Assessor II
Plano, TX · On-site
$90 - $130/hr
Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials. * Certified ...
New
Senior Security Assessor II
Plano, TX · On-site
$90 - $130/hr
Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials. * Certified ...
New
Senior Security Assessor II
Plano, TX · On-site
Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials. * Certified ...
Senior Security Assessor II
Plano, TX · On-site
Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials. * Certified ...
Senior Security Assessor II
Plano, TX · On-site
Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials. * Certified ...
Senior Security Assessor II
Plano, TX · On-site
Additional certifications such as PCI QSA, CMMC CP, CMMC CCA, IRCA ISMS Auditor (or higher), IIA Certified Internal Auditor (CIA), HITRUST, or similar industry-recognized credentials. * Certified ...
Cyber Security Auditor
Albuquerque, NM · On-site
$101K - $137K/yr
Ensure compliance with NIST, CMMC 2.0, RMF, JSIG, and related security frameworks * Evaluate ... IT auditing or security engineering * Experience with cybersecurity tools, compliance frameworks ...
Quick apply
Cyber Security Auditor
Albuquerque, NM · On-site
$101K - $137K/yr
Ensure compliance with NIST, CMMC 2.0, RMF, JSIG, and related security frameworks * Evaluate ... IT auditing or security engineering * Experience with cybersecurity tools, compliance frameworks ...
Cyber Security Auditor
Albuquerque, NM · On-site
$101K - $137K/yr
... CMMC 2.0, RMF, JSIG, and related security frameworks • Evaluate firewalls, data protection ... in IT auditing or security engineering • Experience with cybersecurity tools, compliance ...
Cyber Security Auditor
Albuquerque, NM · On-site
$101K - $137K/yr
... CMMC 2.0, RMF, JSIG, and related security frameworks • Evaluate firewalls, data protection ... in IT auditing or security engineering • Experience with cybersecurity tools, compliance ...
... CMMC, DFARS, ITAR, FAR, and applicable Department of Defense (DoD) requirements. This position ... The Lead Compliance Auditor develops risk-based audit plans and checklists, leads audit teams ...
... CMMC, DFARS, ITAR, FAR, and applicable Department of Defense (DoD) requirements. This position ... The Lead Compliance Auditor develops risk-based audit plans and checklists, leads audit teams ...
Lead Compliance Auditor
Huntsville, AL · On-site
$73K - $132K/yr
... CMMC, DFARS, ITAR, FAR, and applicable Department of Defense (DoD) requirements. This position ... The Lead Compliance Auditor develops risk-based audit plans and checklists, leads audit teams ...
Lead Compliance Auditor
Huntsville, AL · On-site
$73K - $132K/yr
... CMMC, DFARS, ITAR, FAR, and applicable Department of Defense (DoD) requirements. This position ... The Lead Compliance Auditor develops risk-based audit plans and checklists, leads audit teams ...
Lead Compliance Auditor
Huntsville, AL · On-site
... CMMC, DFARS, ITAR, FAR, and applicable Department of Defense (DoD) requirements. This position ... The Lead Compliance Auditor develops risk-based audit plans and checklists, leads audit teams ...
Lead Compliance Auditor
Huntsville, AL · On-site
... CMMC, DFARS, ITAR, FAR, and applicable Department of Defense (DoD) requirements. This position ... The Lead Compliance Auditor develops risk-based audit plans and checklists, leads audit teams ...
... CMMC, SOX, FedRAMP, and other regulatory frameworks. - Participate in internal and external audits ... Required Skills - Certified Information Systems Auditor (CISA) certification. - 3+ years of ...
... CMMC, SOX, FedRAMP, and other regulatory frameworks. - Participate in internal and external audits ... Required Skills - Certified Information Systems Auditor (CISA) certification. - 3+ years of ...
... CMMC, SOX, FedRAMP, and other regulatory frameworks. - Participate in internal and external audits ... Desired Skills - Certified Information Systems Auditor (CISA) certification. - Experience ...
... CMMC, SOX, FedRAMP, and other regulatory frameworks. - Participate in internal and external audits ... Desired Skills - Certified Information Systems Auditor (CISA) certification. - Experience ...
Compliance Auditor
Huntsville, AL · On-site
$73K - $132K/yr
Experience auditing against CMMC or NIST SP 800-171 practices * Security clearance eligibility or active clearance preferred * Process Improvement * Problem Solving If you're looking for comfort ...
Compliance Auditor
Huntsville, AL · On-site
$73K - $132K/yr
Experience auditing against CMMC or NIST SP 800-171 practices * Security clearance eligibility or active clearance preferred * Process Improvement * Problem Solving If you're looking for comfort ...
Cmmc Auditor information
See salary details
$10.34 - $13.61
15% of jobs
$14.34 is the 25th percentile. Wages below this are outliers.
$13.61 - $16.89
46% of jobs
$18.63 is the 75th percentile. Wages above this are outliers.
$16.89 - $20.17
26% of jobs
$20.17 - $23.45
7% of jobs
$23.45 - $26.73
1% of jobs
$26.73 - $30
1% of jobs
$30 - $33.28
1% of jobs
$33.28 - $36.56
0% of jobs
$36.56 - $39.84
1% of jobs
$39.84 - $43.12
1% of jobs
$43.12 - $46.39
0% of jobs
$10
$19
$46
How much do cmmc auditor jobs pay per hour?
What is a CMMC auditor?
A CMMC Auditor evaluates an organization's cybersecurity practices to ensure compliance with the Cybersecurity Maturity Model Certification (CMMC) framework. They assess security controls, policies, and procedures to verify they meet the required maturity level for handling controlled unclassified information (CUI). Auditors may work for a Certified Third-Party Assessment Organization (C3PAO) and conduct official CMMC assessments. Their role is critical in helping defense contractors meet Department of Defense (DoD) cybersecurity requirements.
What are the key skills and qualifications needed to thrive as a CMMC auditor?
To thrive as a CMMC Auditor, you need a robust understanding of cybersecurity frameworks, risk assessment, and compliance standards, usually backed by relevant industry certifications such as CMMC-AB Certified Professional or Lead Auditor credentials. Proficiency with compliance management platforms, audit tools, and familiarity with NIST SP 800-171 controls is essential. Strong analytical skills, attention to detail, and effective communication are key soft skills for engaging with clients and preparing thorough audit reports. These abilities ensure accurate assessments, help organizations achieve CMMC certification, and maintain the integrity of sensitive information systems.
What are the typical challenges a CMMC auditor faces during assessments?
CMMC Auditors often face challenges related to interpreting evolving compliance requirements and navigating complex organizational IT environments. Effectively communicating findings to stakeholders with varying technical backgrounds and maintaining objectivity throughout the audit process can also be demanding. Additionally, auditors must stay current on updates to CMMC guidelines and industry best practices to deliver accurate evaluations. These challenges make critical thinking and adaptability especially important for success in the role.
How to become a CMMC auditor?
Who performs CMMC audits?
What cities are hiring for Cmmc Auditor jobs?
Cities with the most Cmmc Auditor job openings:
What states have the most Cmmc Auditor jobs?
States with the most job openings for Cmmc Auditor jobs include:
What job categories do people searching Cmmc Auditor jobs look for?
The top searched job categories for Cmmc Auditor jobs are:

Full-time
Medical, Dental, Vision, Life, Retirement, PTO
Re-posted 29 days ago
Job description
Boston Government Services, LLC. (BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to Lead CMMC Certified Assessor to support our clients in multiple locations.
BGS is an engineering, technology, and security firm helping to advance missions of national importance for government programs, national laboratories, national security facilities, nuclear operations, and complex projects. We support clients at every stage, from strategic planning and program management to the execution of engineering and technical activities. We work to attract and retain the best talent because the best talent delivers the best results for our clients. Our capabilities are based on our experience in complex, secure, and highly regulated environments. We leverage our experience and capabilities to provide mission-driven solutions tuned to our client's mission needs and strategic direction.
Work that Matters. People that Matter More. At BGS, we believe meaningful work starts with great people. We foster a culture built on respect, collaboration, and accountability—where employees are empowered to contribute ideas, grow professionally, and make an impact. We care about our employees’ well-being through competitive benefits, clear expectations, and an environment that values both excellence and connection.
If you align with BGS’ company values and culture, we would love for you to explore opportunities to join our growing team by checking out the job description below!
Overview:
The Lead CMMC Certified Assessor is responsible for the performance of cybersecurity framework assessments to determine compliance with Government-mandated cybersecurity regulatory requirements. This position is primarily responsible for Cybersecurity Maturity Model Certification (CMMC) for Maturity Levels 1, 2, and 3, National Institute of Standards and Technology Special Publication - NIST SP 800-171, and NIST SP 800-172 assessments but may also be asked to conduct assessments against NIST SP 800-53 Risk Management Framework (RMF), International Organization for Standardization - ISO 27001, Center for Internet Security, the NIST Cybersecurity Framework.
Responsibilities:
- Maintain CMMC documentation for BGS as a Certified Third-Party Assessor Organization (C3PAO) within the CMMC Ecosystem.
- Conduct cybersecurity assessments for a broad range of customer environments to determine any gaps that exist between compliance requirements and actual implementation based on common NIST standards, such as NIST SP 800-53, NIST SP 800-82, and NIST SP 800-171.
- Lead or participate in assessment teams to evaluate organizations against compliance standards.
- Develop & manage assessment project plans.
- Work with the customer to conduct interviews and observe technical implementations.
- Provide guidance to customers, as needed, to facilitate compliance requirements.
- Conduct compliance and cybersecurity workshops.
- Create assessment reports and gap analysis reports.
- Create System Security Plans, Plan of Action & Milestones, and security procedures.
- Other duties as assigned.
Requirements:
- Associate’s degree or higher (equivalent experience/military will be considered)
- 4 years of direct cybersecurity or Information Technology experience are required.
- Must have a Lead CMMC Certified Assessor (CCA).
- Must have one or more of the following certifications:
- Cybersecurity & Infrastructure Security Agency (CISA).
- Certified Information Systems Security Professional (CISSP).
- Certified Cloud Security Professional (CCSP).
- Certified Information Security Manager (CISM).
- CompTIA Advanced Security Practitioner (CASP+).
- Certified Chief Information Security Officer (CCISO).
- Global Information Assurance Certification (GIAC).
- GIAC Certified Enterprise Defender (GCED).
- GIAC Certified Incident Handler Certification (GCIH).
- GIAC Security Leadership (GSLC).
- Prior cybersecurity assessment experience is required.
- Experience in technical document writing.
- Experience in a security/compliance focused role with 3 to 5 years of experience performing technical security audits and risk assessments.
- Minimum of 1 year of experience with cloud-based concepts with an emphasis on security and auditing Amazon Web Services (AWS) or Azure controls.
- Ability to pass a federal background check.
- Successful drug screening.
- Must be eligible to obtain and maintain a security clearance.
- Willingness to travel as needed.
Preferred Qualifications:
- 3+ years’ of experience with cloud-based concepts with an emphasis on security and auditing AWS or Azure controls.
Location/Work Arrangement:
- This position is Remote with some travel / onsite requirements.
Benefits:
BGS offers a competitive total compensation package to eligible employees. Benefits include Health, Dental, Vision, Life Insurance, Paid Vacation, 401K, Long and Short-Term Disability.
EEO:
BGS is an Equal Opportunity/Affirmative Action employer. All qualified applicants are encouraged to apply and will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, or protected veteran status.
Exclusive Agreement Disclaimer:
BGS has standing contracts with federal agencies throughout the United States. We require an affirmative exclusive agreement to represent all candidates to our clients. By submitting this application, you are consenting to allow BGS to represent you as a candidate for the role in which you are applying.
Schedule is full-time, Monday – Friday 40-hour week.
About Boston Government Services
Sourced by ZipRecruiter
Industry
Business management consulting
Company size
51 - 200 Employees
Headquarters location
Oak Ridge, TN, US
Year founded
2007