If the consultant is not yet a CMMC RP, the consultant will be expected to attain CMMC RP certification within 3 months of attaining PCI QSA certification. Travel Requirements: This is a remote role ...
If the consultant is not yet a CMMC RP, the consultant will be expected to attain CMMC RP certification within 3 months of attaining PCI QSA certification. Travel Requirements: This is a remote role ...
Lead CCA Certified Professionals (Part Time & Remote)
Sterling, VA · On-site +1
$60 - $105/hr
The consultant will work with our clients to help them navigate CMMC levels 1-3 and ensure continuous compliance with DoD cybersecurity regulations. This is a part-time, flexible position ideal for a ...
Lead CCA Certified Professionals (Part Time & Remote)
Sterling, VA · On-site +1
$60 - $105/hr
The consultant will work with our clients to help them navigate CMMC levels 1-3 and ensure continuous compliance with DoD cybersecurity regulations. This is a part-time, flexible position ideal for a ...
Korean Bilingual IT Systems & Infrastructure Specialist (CMMC)
Arlington, VA · On-site
$95 - $135/hr
Korean Bilingual IT Systems & Infrastructure Specialist (CMMC) Job Summary This role executes the ... We are an outstanding national Consulting company with 20 years of success. Corporate Values * 1. ...
Korean Bilingual IT Systems & Infrastructure Specialist (CMMC)
Arlington, VA · On-site
$95 - $135/hr
Korean Bilingual IT Systems & Infrastructure Specialist (CMMC) Job Summary This role executes the ... We are an outstanding national Consulting company with 20 years of success. Corporate Values * 1. ...
The Cybersecurity Risk and Compliance Consultant should be familiar with multiple security ... Certified CMMC Professional (CCP), Certified CMMC Assessor (CCA), Certified Information Systems ...
Quick apply
The Cybersecurity Risk and Compliance Consultant should be familiar with multiple security ... Certified CMMC Professional (CCP), Certified CMMC Assessor (CCA), Certified Information Systems ...
$90 - $120/hr
The Cybersecurity Risk and Compliance Consultant should be familiar with multiple security ... Certified CMMC Professional (CCP), Certified CMMC Assessor (CCA), Certified Information Systems ...
$90 - $120/hr
The Cybersecurity Risk and Compliance Consultant should be familiar with multiple security ... Certified CMMC Professional (CCP), Certified CMMC Assessor (CCA), Certified Information Systems ...
Senior IT Systems Administrator
Reston, VA · Hybrid
$89K - $121K/yr
Build and mature Scout's in-house IT support capability while maintaining strong working relationships with our Managed Service Provider (MSP), CMMC consultants, and other technology partners
Quick apply
Senior IT Systems Administrator
Reston, VA · Hybrid
$89K - $121K/yr
Build and mature Scout's in-house IT support capability while maintaining strong working relationships with our Managed Service Provider (MSP), CMMC consultants, and other technology partners
Senior IT Systems Administrator
Reston, VA · Hybrid
$89K - $121K/yr
Build and mature Scout's in-house IT support capability while maintaining strong working relationships with our Managed Service Provider (MSP), CMMC consultants, and other technology partners
Senior IT Systems Administrator
Reston, VA · Hybrid
$89K - $121K/yr
Build and mature Scout's in-house IT support capability while maintaining strong working relationships with our Managed Service Provider (MSP), CMMC consultants, and other technology partners
Senior IT Systems Administrator
Reston, VA · On-site +1
$89K - $121K/yr
Build and mature Scout's in-house IT support capability while maintaining strong working relationships with our Managed Service Provider (MSP), CMMC consultants, and other technology partners
Senior IT Systems Administrator
Reston, VA · On-site +1
$89K - $121K/yr
Build and mature Scout's in-house IT support capability while maintaining strong working relationships with our Managed Service Provider (MSP), CMMC consultants, and other technology partners
Senior IT Systems Administrator
Reston, VA · Hybrid
$89K - $121K/yr
Build and mature Scout's in-house IT support capability while maintaining strong working relationships with our Managed Service Provider (MSP), CMMC consultants, and other technology partners
Senior IT Systems Administrator
Reston, VA · Hybrid
$89K - $121K/yr
Build and mature Scout's in-house IT support capability while maintaining strong working relationships with our Managed Service Provider (MSP), CMMC consultants, and other technology partners
Expert-level knowledge of the CMMC framework, including practice requirements and the assessment ... Provide consultative reviews of security documentation with accompanying remediation or enhancement ...
Expert-level knowledge of the CMMC framework, including practice requirements and the assessment ... Provide consultative reviews of security documentation with accompanying remediation or enhancement ...
Expert-level knowledge of the CMMC framework, including practice requirements and the assessment ... Provide consultative reviews of security documentation with accompanying remediation or enhancement ...
Expert-level knowledge of the CMMC framework, including practice requirements and the assessment ... Provide consultative reviews of security documentation with accompanying remediation or enhancement ...
Required : • Java Full Stack with CMMC: 30% • Good Communication Skill: 35% • Good Technical Skill: 35% • A minimum of 10 years of experience is essential for this role. • Strong experience ...
Required : • Java Full Stack with CMMC: 30% • Good Communication Skill: 35% • Good Technical Skill: 35% • A minimum of 10 years of experience is essential for this role. • Strong experience ...
Senior Compliance Consultant
Eastern, KY · On-site
$120 - $210/hr
The Consultant will author (for new systems/environments) and/or augment policies, plans, processes ... Experience: 5+ years with various compliance standards including but not limited to CMMC, NIST 800 ...
Senior Compliance Consultant
Eastern, KY · On-site
$120 - $210/hr
The Consultant will author (for new systems/environments) and/or augment policies, plans, processes ... Experience: 5+ years with various compliance standards including but not limited to CMMC, NIST 800 ...
Senior Security Consultant, Continuity and Compliance - PCI DSS QSA
Mclean, VA · On-site +1
$130K - $155K/yr
Own assigned consulting engagements from initiation through completion, including the accuracy ... Support additional security and compliance engagements involving NIST, HIPAA, CMMC, or related ...
Senior Security Consultant, Continuity and Compliance - PCI DSS QSA
Mclean, VA · On-site +1
$130K - $155K/yr
Own assigned consulting engagements from initiation through completion, including the accuracy ... Support additional security and compliance engagements involving NIST, HIPAA, CMMC, or related ...
Senior Security Consultant, Continuity and Compliance - PCI DSS QSA
Mclean, VA · Remote
$130K - $155K/yr
Own assigned consulting engagements from initiation through completion, including the accuracy ... Support additional security and compliance engagements involving NIST, HIPAA, CMMC, or related ...
Quick apply
Senior Security Consultant, Continuity and Compliance - PCI DSS QSA
Mclean, VA · Remote
$130K - $155K/yr
Own assigned consulting engagements from initiation through completion, including the accuracy ... Support additional security and compliance engagements involving NIST, HIPAA, CMMC, or related ...
Lead CCA Certified Professionals (Part Time & Remote)
Sterling, VA · On-site
$82.66 - $144.65/hr
The consultant will work with our clients to help them navigate CMMC levels 1‑3 and ensure continuous compliance with DoD cybersecurity regulations. This is a part‑time, flexible position ideal ...
Lead CCA Certified Professionals (Part Time & Remote)
Sterling, VA · On-site
$82.66 - $144.65/hr
The consultant will work with our clients to help them navigate CMMC levels 1‑3 and ensure continuous compliance with DoD cybersecurity regulations. This is a part‑time, flexible position ideal ...
Experience as a Quality Consultant, preferably for small companies ... Cybersecurity Maturity Model Certification (CMMC) a plus.
Experience as a Quality Consultant, preferably for small companies ... Cybersecurity Maturity Model Certification (CMMC) a plus.
Formal C3PAO Assessments As 112Cyber's business is focused on CMMC (as opposed to SOC2, FedRAMP, and other consulting and/or attestation services), the individual will need to either be or become ...
Quick apply
Formal C3PAO Assessments As 112Cyber's business is focused on CMMC (as opposed to SOC2, FedRAMP, and other consulting and/or attestation services), the individual will need to either be or become ...
Formal C3PAO Assessments As 112Cyber's business is focused on CMMC (as opposed to SOC2, FedRAMP, and other consulting and/or attestation services), the individual will need to either be or become ...
Formal C3PAO Assessments As 112Cyber's business is focused on CMMC (as opposed to SOC2, FedRAMP, and other consulting and/or attestation services), the individual will need to either be or become ...
Expert-level knowledge of the CMMC framework, including practice requirements and the assessment ... Provide consultative reviews of security documentation with accompanying remediation or enhancement ...
Expert-level knowledge of the CMMC framework, including practice requirements and the assessment ... Provide consultative reviews of security documentation with accompanying remediation or enhancement ...
Cmmc Consultant information
See salary details
$10.34 - $17.31
5% of jobs
$17.31 - $24.28
6% of jobs
$28.14 is the 25th percentile. Wages below this are outliers.
$24.28 - $31.25
24% of jobs
The median wage is $35.17 / hr.
$31.25 - $38.22
25% of jobs
$38.22 - $45.19
14% of jobs
$45.39 is the 75th percentile. Wages above this are outliers.
$45.19 - $52.16
9% of jobs
$52.16 - $59.13
5% of jobs
$59.13 - $66.11
3% of jobs
$66.11 - $73.08
3% of jobs
$73.08 - $80.05
2% of jobs
$80.05 - $87.02
2% of jobs
$10
$41
$87
How much do cmmc consultant jobs pay per hour?
What is a CMMC consultant?
A CMMC Consultant helps organizations comply with the Cybersecurity Maturity Model Certification (CMMC) framework, which is required for working with the Department of Defense (DoD). They assess current cybersecurity practices, identify gaps, and recommend improvements to meet CMMC requirements. Consultants also guide businesses through the certification process, ensuring they achieve the necessary maturity level to bid on DoD contracts. Their role includes risk assessments, policy development, and employee training to enhance cybersecurity resilience.
What does a CMMC consultant do?
A typical workday for a CMMC Consultant involves conducting compliance gap analyses, reviewing cybersecurity controls, preparing detailed documentation, and advising clients on remediation strategies. You’ll often collaborate with IT and compliance teams to develop action plans or provide training on CMMC requirements. Communication with stakeholders, updating progress, and staying current with regulatory changes are also key aspects of the role. This position is dynamic, balancing independent technical assessments with group meetings and client consultations, making adaptability and clear communication essential.
What are the key skills and qualifications needed to thrive as a CMMC consultant?
To thrive as a CMMC Consultant, you need a strong knowledge of cybersecurity frameworks, risk assessments, and compliance methodologies, usually backed by experience in IT security and CMMC-specific training or certification. Familiarity with compliance management tools, NIST SP 800-171, and CMMC assessment software is essential. Strong communication, project management, and problem-solving abilities are standout soft skills for engaging with clients and guiding them through complex compliance processes. These skills and qualities are crucial to ensure organizations efficiently achieve and maintain CMMC certification, meet contractual obligations, and protect sensitive information.
What cities are hiring for Cmmc Consultant jobs?
Cities with the most Cmmc Consultant job openings:
What are the most commonly searched types of Cmmc Consultant jobs?
The most popular types of Cmmc Consultant jobs are:
What states have the most Cmmc Consultant jobs?
States with the most job openings for Cmmc Consultant jobs include:
What job categories do people searching Cmmc Consultant jobs look for?
The top searched job categories for Cmmc Consultant jobs are:

Job description
At Presidio, we're at the forefront of a global technology revolution, transforming industries through cutting-edge digital solutions and next-generation AI. We empower businesses - and their internal customers - to achieve more through innovation, automation, and intelligent insights.
The RoleA Principal Security Governance Consultant is expected to have a deep level of expertise and vast knowledge base in core information security governance, risk, compliance, and privacy domains. It is critical that a Principal Security Governance Consultant be able to present complex solutions and topics in a concise manner. The consultant must be comfortable blending multiple service offerings and deliverables into a single aggregate final risk report/deliverable and executive presentation for audiences of all levels and skillsets.
The consultant will have experience in reviewing, understanding, and interpreting risk management and compliance frameworks, security standards, and privacy models. The consultant must have a professional and practical understanding of Information Technology, including how technical and administrative controls are implemented across various industry verticals and company sizes. The candidate should be well versed in assessing said controls, understand how controls should be governed, and be able to assist in the strategic development of aligning security goals to business objectives.
As a PCI QSA company, we are expanding the pool of PCI Qualified Security Assessors (QSAs) and CMMC Registered Practitioners (RPs) on the Information Security Governance (ISG) team to meet client demand. The ideal consultant will have a certification from both List A and List B from the QSA qualification requirements listed below. If a certification has not yet been attained from either List A or List B, the consultant will be expected to attain a certification within the first 3 months of employment in order to register for PCI QSA training within 6 months of hire date and complete CPEs annually to renew certifications. If the consultant is not yet a CMMC RP, the consultant will be expected to attain CMMC RP certification within 3 months of attaining PCI QSA certification.
Travel Requirements:
This is a remote role located in the Continental US. You will be required to travel up to 30% to client locations to deliver professional services when needed.
Responsibilities Include:
- Lead client engagements and project execution providing information security consultation and assessment services, helping our clients meet their compliance obligations by evaluating their business, technology, and operations against industry security standards
- Educate, mentor, advise, and share your expertise with clients and colleagues to aid in making decisions on topics like Artificial Intelligence, organizational security strategy and services scope as well provide consultative guidance on complex projects
- Providing clear, organized findings and recommendations to clients and tracking progress towards resolution and compliance
- Consult/advise with C-level Security Leaders (CISO, CSO, CIO, etc.) and the Board of Directors with our most valued and strategic clients
- Develop strategic, operational, and tactical recommendations tailored to each client with the intent to improve a client's security posture and compliance position
- Create detailed strategic security roadmaps with short-term, mid-term, and long-term goals that prioritize remediation recommendations and address all instances of non-compliance with applicable regulatory, statutory, contractual, and organizational obligations
- Lead large security engagements in concert with other cybersecurity practices and Presidio teams
- Develop security policies, standards, and procedures that are custom-tailored to each client's unique culture, security goals, and organizational objectives using industry best practices and compliance requirements
- Review, analyze, and assess key factors, including inherent risk, mitigating controls, business impact, likelihood and other key elements to determine organizational security risk
- Ensure and assess client alignment to, and/or compliance with, applicable regulatory, federal, state, local, contractual, and organizational requirements and best practices standards such as ISO 27001, NIST Cyber Security Framework (CSF), PCI DSS, HIPAA, FERPA, NIST 800-171, CMMC, etc.
- Work closely with organizations to conduct security program development by establishing the foundation for a best of breed security program architecture reference model using industry frameworks and standards such as ISO 27001, NIST 800-53, NIST CSF, etc.
- Work with other seasoned Principal Security Consultants in a collaborative setting to support and assist on the execution and delivery of key services such as Cloud Governance, Advisory Services, security program development, documentation review, and security consulting services
- Execute tabletop exercises after collaborating with client stakeholders to select the scenario then create an After-Action Report
- Deliver PCI Advisory Services, including PCI Gap Analysis, SAQs, ROCs and AOCs
- Deliver CMMC Advisory Services, including CMMC Readiness Assessments
- Assist leadership in cybersecurity administrative functions, such as documentation maintenance, documentation creation, peer review, and other internal cybersecurity activities
Additional Professional Experience and Service Delivery Requirements:
- Strong professional expertise in information security with the ability to thoroughly understand complex principles and apply them practically
- Deliver consulting services on time and on budget
- Comfortably present security concepts and/or findings to both highly technical and entirely non-technical audiences
- Must be analytical, detail oriented, innovative, and recognize opportunities to provide value added consulting services to clients
- Ability to manage multiple and simultaneous clients, tasks, and responsibilities, work alone or in small teams, achieve established goals and objectives, and proactively communicate progress
- Ability to work collaboratively or independently as required by the engagement's needs
- Ability to be flexible and embrace change
- Continuously evolve approaches based on changing requirements, new information, or updated guidance
- Ability to manage multiple and changing priorities and tasks
Required Skills and Professsonal Experience:
- Bachelor's Degree with a focus on Information Security, IT, Computer Science, or Engineering preferred or the equivalent work experience and/or military experience
- 5-8 years previous consulting experience
- 5-8 years' experience conducting Information Security risk and compliance assessments
- 5-8 years' experience evaluating compliance with regulatory and key IT standards such as HIPAA, PCI DSS, NIST CSF, ISO 27001, and other similar standards/frameworks
- Cloud experience with AWS, Azure or Google Cloud Platform or non-foundational certification for any of these cloud platforms or one of the following cloud agnostic certifications: Certified Cloud Security Professional (CCSP), Certificate of Cloud Security Knowledge (CCSK), GIAC Cloud Security Essentials (GCLD)
- Possess at least one of the following accredited, industry-recognized professional certifications from each list:
- List A
- ISC2 Certified Information System Security Professional (CISSP)
- ISACA Certified Information Security Manager (CISM)
- Certified ISO 27001 Lead Implementer
- List B
- ISACA Certified Information Systems Auditor (CISA)
- GIAC Systems and Network Auditor (GSNA)
- Certified ISO 27001, Lead Auditor, Internal Auditor 1
- IRCA ISMS Auditor or higher-e.g., Auditor/Lead Auditor, Principal Auditor
- IIA Certified Internal Auditor (CIA)
- List A
Additional Professional Experience and Service Delivery Requirements:
- Strong professional expertise in information security with the ability to thoroughly understand complex principles and apply them practically
- Deliver consulting services on time and on budget
- Comfortably present security concepts and/or findings to both highly technical and entirely non-technical audiences
- Must be analytical, detail oriented, innovative, and recognize opportunities to provide value added consulting services to clients
- Ability to manage multiple and simultaneous clients, tasks, and responsibilities, work alone or in small teams, achieve established goals and objectives, and proactively communicate progress
- Ability to work collaboratively or independently as required by the engagement's needs
- Ability to be flexible and embrace change.
- Continuously evolve approaches based on changing requirements, new information, or updated guidance
- Ability to manage multiple and changing priorities and tasks
Preferred Skills and Professional Experience
- One or more AI certifications (e.g., ISO 42001, ISACA AAISM, ISACA AAIR, IAPP AIGP)
- Experience leading AI security assessments, maturity reviews, and developing remediation roadmaps for clients
- Ability to translate technical AI risks into executive-level recommendations and measurable controls
Your future at PresidioJoiningPresidio means stepping into a culture of trailblazers - thinkers, builders, and collaborators - who push the boundaries of what's possible. With our expertise AI-driven analytics, cloud solutions, cybersecurity, and next-gen infrastructure, we enable businesses to stay ahead in an ever-evolving digital world.
Here, your impact is real. Whether you're harnessing the power of Generative AI, architecting resilient digital ecosystems, or driving data-driven transformation, you'll be part of a team that is shaping the future.
Ready to innovate? Let's redefine what's next-together.
About Presidio
Presidio is committed to hiring the most qualified candidates to join our amazing culture. We aim to attract and hire top talent from all backgrounds, including underrepresented and marginalized communities. We encourage women, people of color, people with disabilities, and veterans to apply for open roles at Presidio. Diversity of skills and thought is a key component to our business success.
At Presidio, speed and quality meet technology and innovation. Presidio is a trusted ally for organizations across industries with a decades-long history of building traditional IT foundations and deep expertise in AI and automation, security, networking, digital transformation, and cloud computing. Presidio fills gaps, removes hurdles, optimizes costs, and reduces risk. Presidio's expert technical team develops custom applications, provides managed services, and enables actionable data insights and builds forward-thinking solutions that drive strategic outcomes for clients globally. For more information visit
****
Applications will be accepted on a rolling basis.
Presidio has a strong commitment to the community we serve and our employees. As an Equal Opportunity Employer, we strive to have a workforce that includes the community we serve.
Presidio is an Equal Opportunity Employer Disability/Vets. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information, and other legally protected categories.
The "Know Your Rights" Poster is available here: https://www.eeoc.gov/poster
Presidio EEO Policy Statement is available here: https://www.presidio.com/careers
Presidio is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please send an e-mail to recruitment@presidio.com and let us know the nature of your request and your contact information.
Presidio is a VEVRAA Federal Contractor requesting priority referrals of protected veterans for its openings. State Employment Services, please provide priority referrals to.
Notice of Massachusetts Candidates: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
Recruitment Agencies, Please Note: Presidio does not accept unsolicited agency resumes/CVs. Do not forward resumes/CVs to our career's email address, Presidio employees or any other means. Presidio is not responsible for any feeds related to unsolicited resumes/CVs.
#LI-PH1
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.