1

Cmmc Consulting Jobs (NOW HIRING)

Senior IT Systems Administrator

Reston, VA · On-site +1

$89K - $121K/yr

Build and mature Scout's in-house IT support capability while maintaining strong working relationships with our Managed Service Provider (MSP), CMMC consultants, and other technology partners

Senior IT Systems Administrator

Reston, VA · Hybrid

$89K - $121K/yr

Build and mature Scout's in-house IT support capability while maintaining strong working relationships with our Managed Service Provider (MSP), CMMC consultants, and other technology partners

Senior IT Systems Administrator

Reston, VA · Hybrid

$89K - $121K/yr

Build and mature Scout's in-house IT support capability while maintaining strong working relationships with our Managed Service Provider (MSP), CMMC consultants, and other technology partners

Lead cybersecurity compliance consulting engagements for assigned clients from planning through ... Experience supporting organizations through CMMC assessments or ongoing CMMC compliance programs.

New

Lead cybersecurity compliance consulting engagements for assigned clients from planning through ... Experience supporting organizations through CMMC assessments or ongoing CMMC compliance programs.

New

If the consultant is not yet a CMMC RP, the consultant will be expected to attain CMMC RP certification within 3 months of attaining PCI QSA certification. Travel Requirements: This is a remote role ...

Formal C3PAO Assessments As 112Cyber's business is focused on CMMC (as opposed to SOC2, FedRAMP, and other consulting and/or attestation services), the individual will need to either be or become ...

Formal C3PAO Assessments As 112Cyber's business is focused on CMMC (as opposed to SOC2, FedRAMP, and other consulting and/or attestation services), the individual will need to either be or become ...

Formal C3PAO Assessments As 112Cyber's business is focused on CMMC (as opposed to SOC2, FedRAMP, and other consulting and/or attestation services), the individual will need to either be or become ...

Showing results 41-60

Cmmc Consulting information

See salary details

$99.5K

$121.2K

$142.5K

How much do cmmc consulting jobs pay per year?

As of Aug 14, 2026, the average yearly pay for cmmc consulting in the United States is $121,249.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,000.00 and $132,500.00 per year, depending on experience, location, and employer.

What is CMMC consulting?

CMMC consulting refers to professional services that help organizations prepare for and achieve compliance with the Cybersecurity Maturity Model Certification (CMMC) framework. CMMC is a set of cybersecurity standards required by the U.S. Department of Defense for contractors handling controlled unclassified information. Consultants guide companies through gap assessments, remediation, policy development, and readiness for official CMMC audits. Their expertise ensures that businesses understand and implement the required cybersecurity practices efficiently. Ultimately, CMMC consultants help reduce risks and facilitate successful certification.

What does a CMMC consulting do?

A CMMC consulting professional helps organizations achieve and maintain compliance with the Cybersecurity Maturity Model Certification (CMMC) standards required for defense contracts. They assess security practices, develop remediation plans, and prepare organizations for audits, often utilizing tools like NIST frameworks and cybersecurity best practices.

What is the difference between Cmmc Consulting vs CMMC Auditor?

AspectCmmc ConsultingCMMC Auditor
CertificationsTypically involves CMMC compliance expertise, consulting certifications, and industry-specific knowledgeRequires CMMC-AB Certified Professional and auditor-specific credentials
Work EnvironmentAdvisory, client-facing, project-based consulting firmsAuditing organizations, government contracts, compliance assessments
Employer & Industry UsageConsulting firms, defense contractors, cybersecurity firmsGovernment agencies, third-party assessment organizations, defense contractors

While both roles focus on CMMC compliance, Cmmc Consulting involves advising organizations on achieving and maintaining compliance, whereas CMMC Auditors conduct official assessments to verify compliance status. The roles often overlap but serve different functions within the cybersecurity and defense industry.

What is a CMMC consulting professional?

A CMMC consulting professional is an expert who helps organizations prepare for and achieve Cybersecurity Maturity Model Certification (CMMC) compliance. They assess security practices, develop implementation plans, and assist with documentation to meet CMMC requirements, often requiring knowledge of cybersecurity frameworks and relevant standards.

What are the key skills and qualifications needed to thrive as a CMMC consultant?

To thrive as a CMMC Consultant, you need a strong background in cybersecurity frameworks, risk assessment, and compliance, often supported by certifications such as CMMC-AB Registered Practitioner or Certified CMMC Professional (CCP). Familiarity with tools like NIST 800-171 assessment utilities, compliance management platforms, and security auditing systems is essential. Excellent communication, analytical thinking, and client management skills help consultants effectively guide organizations through complex compliance processes. These skills ensure organizations achieve and maintain CMMC certification, which is critical for securing Department of Defense contracts and safeguarding sensitive information.

What are some common challenges CMMC consultants face when helping organizations prepare for certification?

CMMC consultants often encounter challenges such as aligning existing cybersecurity practices with the required maturity level, bridging gaps in documentation, and ensuring consistent employee engagement across departments. They frequently need to translate complex technical requirements into actionable steps for non-technical staff and manage tight timelines to meet client deadlines. Additionally, consultants must stay up-to-date with evolving CMMC regulations and effectively communicate compliance expectations to both leadership and operational teams.
More about Cmmc Consulting jobs

What cities are hiring for Cmmc Consulting jobs?

Cities with the most Cmmc Consulting job openings:

What states have the most Cmmc Consulting jobs?

States with the most job openings for Cmmc Consulting jobs include:

Infographic showing various Cmmc Consulting job openings in the United States as of August 2026, with employment types broken down into 1% Internship, 85% Full Time, 8% Part Time, and 6% Contract. Highlights an 84% Physical, 6% Hybrid, and 10% Remote job distribution, with an average salary of $121,249 per year, or $58.3 per hour.

$95K - $105K/yr

Full-time

Re-posted 24 days ago


Job description

Description

We are seeking a Cyber Security Engineer with a strong security focus to support our CMMC Level 2 certification effort under DFARS. The right candidate will own assigned NIST SP 800-171 control domains, drive Microsoft security platform operations, and help protect a hybrid environment spanning on-premises infrastructure and cloud services including Azure, Defender, Sentinel, and Hyper-V.

 This position is a US based (Orlando, FL), and is an in-office role (no hybrid or remote).
 


Essential Job Functions:

CMMC Level 2 / Cybersecurity Compliance

  • Support CUI / FCI scoping activities, including identifying systems, users, data flows, enclaves, cloud services, endpoints, and third-party services in scope for CMMC Level 2.
  • Maintain assessment-ready evidence mapped to NIST SP 800-171 control domains and CMMC assessment requirements in the System Security Plan (SSP).
  • Identify, track, and remediate gaps via the Plan of Action & Milestones (POA&M).
  • Support C3PAO third-party assessment preparation; build and maintain assessment-ready evidence packages including screenshots, configuration exports, policy references, ticket records, vulnerability scan results, audit logs, training records, and control implementation narratives.
  • Maintain audit logging, log integrity, and SIEM operations.
  • Conduct periodic vulnerability scans and coordinate remediation with the team.
  • Assist in developing and enforcing security policies, procedures, and user awareness training.
  • Ensure security-relevant changes are documented, approved, tested, and traceable through the ITSM or change management process.


Microsoft Security Platform Operations

  • Administer and tune Microsoft Sentinel - build and maintain analytics rules, workbooks, and incident response playbooks.
  • Manage Microsoft Defender for Endpoint, Identity, and Office 365 - configure policies, investigate alerts, and drive remediation.
  • Maintain Azure security posture including Entra ID (Azure AD), Conditional Access, PIM, and role-based access controls.
  • Support and manage Hyper-V virtualization environments including VM provisioning, snapshots, and performance monitoring.
  • Leverage Microsoft Purview for data classification, sensitivity labeling, and compliance reporting.


Infrastructure & Systems Administration

  • Administer and harden Windows Server, Active Directory, and Group Policy environments.
  • Maintain network security posture including firewall rules, VLANs, and access control configurations.
  • Maintain asset inventory, software inventory, secure configuration baselines, and change control evidence for servers, endpoints, network devices, cloud services, and security tools.
  • Support endpoint management and patch compliance using enterprise ITSM and endpoint management tooling.
  • Provide Tier 2/3 escalation support for security-relevant endpoint, identity, access, and infrastructure issues.
  • Support ERP and line-of-business application integrations from an IT infrastructure and security perspective as needed.


Security Operations

  • Monitor security alerts across Microsoft Sentinel and Defender, investigate incidents, and escalate per defined IR procedures.
  • Support DFARS 252.204-7012 cyber incident response obligations, including evidence preservation, incident documentation, escalation, and coordination with leadership and external partners.
  • Manage privileged access, MFA enforcement, and identity governance across on-premises and cloud environments.
  • Assist with endpoint detection and response (EDR) configuration and hardening baselines.
  • Participate in tabletop exercises and contribute to business continuity and DR planning.
  • Support backup, recovery, business continuity, and disaster recovery controls, including backup monitoring, restore testing, retention validation, and protection of backup data from unauthorized modification or deletion.
  • Coordinate with external MSPs, CMMC consultants, C3PAOs, auditors, software vendors, and managed security providers to support remediation, evidence collection, and assessment readiness.


Requirements

Qualifications:

Required

  • 3+ years of experience in systems administration or IT infrastructure, with demonstrated hands-on security responsibilities and willingness to grow into CMMC control ownership.
  • Demonstrated knowledge of NIST SP 800-171 or CMMC Level 2 requirements.
  • Hands-on experience with Windows Server, Active Directory, and Group Policy.
  • Working knowledge of Microsoft Defender (Endpoint, Identity, or O365) and Microsoft Sentinel.
  • Familiarity with Microsoft Azure and Entra ID administration.
  • Experience with Hyper-V or equivalent enterprise virtualization platform.
  • Understanding of network security fundamentals: firewalls, VLANs, DNS, DHCP.
  • Strong documentation skills - SSP/POA&M experience a significant plus.

Preferred

  • CompTIA Security+, CySA+, or SSCP certification (or actively pursuing).
  • Microsoft certifications: SC-200, AZ-500, SC-300, SC-400 a strong plus.
  • Familiarity with enterprise ITSM platforms and endpoint management tooling.
  • Familiarity with DoD SPRS reporting and GRC tools.
  • Prior experience working in a Defense Industrial Base (DIB) environment.
  • Exposure to ERP security scoping (Infor CloudSuite or similar).




Management reserves the right to assign or reassign duties and responsibilities to this job at any time.


EOE, including disability/vets