1

Cmmc Fedramp Jobs (NOW HIRING)

Perform consulting/readiness and compliance services for organizations seeking compliance with CMMC, DFARS 252.204-7012, NIST SP 00-171, and FedRAMP * Conduct readiness/consulting services directly ...

Perform consulting/readiness and compliance services for organizations seeking compliance with CMMC, DFARS 252.204-7012, NIST SP 00-171, and FedRAMP * Conduct readiness/consulting services directly ...

Director of Sales

Fairfax, VA · On-site

$125 - $150/hr

This role will drive revenue growth across CMMC, FedRAMP, NIST 800-171, MARS-E, and other Federal-related compliance services by managing enterprise sales executives and developing strategic sales ...

$150 - $200/hr

Analyze and apply NIST SP 800‑53 controls and FedRAMP Moderate and High baselines to ensure ... CMMC and NIST framework generalist - Grounded in the structural requirements of CMMC 2.0 and NIST ...

GRC Engineer (CMMC)

$58.50 - $72/hr

Analyze and apply NIST SP 800-53 controls and FedRAMP Moderate and High baselines to ensure client ... CMMC and NIST framework generalist - Grounded in the structural requirements of CMMC 2.0 and NIST ...

Provide senior advisory oversight for customer programs supporting DFARS, CMMC, FedRAMP, NIST CSF and NIST SP 800-171 initiatives. * Own engagement success by partnering with client leadership to ...

Provide senior advisory oversight for customer programs supporting DFARS, CMMC, FedRAMP, NIST CSF and NIST SP 800-171 initiatives. * Own engagement success by partnering with client leadership to ...

Provide senior advisory oversight for customer programs supporting DFARS, CMMC, FedRAMP, NIST CSF and NIST SP 800-171 initiatives. * Own engagement success by partnering with client leadership to ...

We are looking for a CMMC Security Engineer is responsible for implementing, maintaining, and ... Experience conducting technical assessments, vulnerability management, and implementing FedRAMP ...

next page

Showing results 1-20

Cmmc Fedramp information

What are CMMC and FedRAMP?

CMMC (Cybersecurity Maturity Model Certification) and FedRAMP (Federal Risk and Authorization Management Program) are two separate frameworks used by the U.S. government to ensure the security of information systems. CMMC is focused on assessing and enhancing the cybersecurity practices of defense contractors working with the Department of Defense. FedRAMP, on the other hand, is a government-wide program that standardizes security assessment, authorization, and continuous monitoring for cloud services used by federal agencies. Both frameworks aim to protect sensitive government data, but they apply to different contexts and have distinct compliance requirements.

What are some common challenges faced when coordinating CMMC and FedRAMP compliance efforts within an organization?

One of the main challenges professionals encounter is aligning the differing requirements and documentation standards of both CMMC and FedRAMP frameworks. This often involves managing cross-functional teams, ensuring that security controls meet the expectations of both standards, and preventing redundant work. Additionally, coordinating audits and assessments for both programs can be complex, requiring detailed project management and clear communication with stakeholders. Building a strong compliance culture and staying up-to-date with evolving regulations are also essential tasks in this role.

What are the key skills and qualifications needed to thrive as a CMMC/FedRAMP compliance specialist, and why are they important?

To thrive as a CMMC/FedRAMP compliance specialist, you need deep knowledge of cybersecurity frameworks, risk management, and regulatory requirements, often supported by relevant degrees or certifications like CISSP or CISA. Familiarity with technical tools such as security assessment software, GRC (Governance, Risk, and Compliance) platforms, and cloud security solutions is typically essential. Strong attention to detail, analytical thinking, and effective communication skills set standout professionals apart in this role. These skills and qualities are vital to ensure organizations achieve and maintain compliance, protect sensitive data, and meet federal contracting requirements.

What is the difference between Cmmc Fedramp vs Cybersecurity Analyst?

AspectCmmc FedrampCybersecurity Analyst
CertificationsFISMA, FedRAMP, CMMCCompTIA Security+, CISSP, CEH
Work EnvironmentGovernment agencies, cloud service providersPrivate sector, various industries
Industry UsageFederal compliance, cloud securitySecurity assessment, threat analysis

While both roles involve cybersecurity, Cmmc Fedramp focuses on compliance and security standards for government cloud services, requiring certifications like FedRAMP and CMMC. Cybersecurity Analysts primarily perform security assessments and threat mitigation across various sectors, often holding certifications like Security+ or CISSP. Understanding these differences helps organizations align roles with their compliance and security needs.

More about Cmmc Fedramp jobs

What job categories do people searching Cmmc Fedramp jobs look for?

The top searched job categories for Cmmc Fedramp jobs are:

What other helpful pages are available for Cmmc Fedramp?

Other pages related to Cmmc Fedramp:

Infographic showing various Cmmc Fedramp job openings in the United States as of September 2026, with employment types broken down into 2% Internship, 92% Full Time, 2% Part Time, and 4% Contract. Highlights an 53% In-person, 2% Hybrid, and 45% Remote job distribution.

Senior CMMC Consultant

On-site

Ariento Inc
11 - 50 employees

Full-time

Re-posted 20 days ago


Job description

Ariento is seeking a Senior Consultant to join our Advisory and Consulting Team and act as a Cybersecurity Maturity Model Certification (CMMC) Subject Matter Expert (SME). This role will:

  • Perform consulting/readiness and compliance services for organizations seeking compliance with CMMC, DFARS 252.204-7012, NIST SP 00-171, and FedRAMP
  • Conduct readiness/consulting services directly with our clients to assess their cybersecurity posture and improve the effectiveness of their security controls in preparation for a third-party audit
  • Conduct reviews of security artifacts and aid completing required documentation to include: SSPs, POA&Ms, Policies, Procedures, Plans, dataflow diagrams, network diagrams, and other documents
  • Assume responsibility for the successful execution and delivery of compliance assessments to include CMMC, FedRAMP, and NIST as part of Ariento’s C3PAO team
  • Help grow Ariento’s CMMC practice by contributing to the development of our capabilities, methodology and foster a continuous improvement environment
  • Work with practice leadership to build client relationships and identify sales opportunities.

Role Responsibilities:

You should also be able to deliver on the following expertly and consistently:

  • Perform CMMC Readiness consulting engagements to assess client’s security controls against CMMC requirements and produce detailed gap analysis reports
  • Verify and document the implementation of security controls necessary to achieve compliance
  • Lead remediation engagements to help clients meet security controls and prepare them for a third-party assessment.
  • Participate as part of the Assessment Team during CMMC Level 2 assessments and support the Lead Assessor across all phases of the assessment: Plan & Prepare the Assessment, Conduct the Assessment, Report Assessment Results, Close out POA&Ms and Assessment
  • Review documentation, validate evidence, and identify security and compliance gaps
  • Review and develop System Security Plans (SSPs), Plans of Actions and Milestones (POA&Ms), and as well as necessary artifacts
  • Develop various policy documents (SOPs) as required. This may include policies regarding Configuration Management, IS Sanitization, Media Security, Password Policy, Business Continuity, Continuity of Operations, Incident Response, Disaster Recovery, and Security Assessments
  • Support the development of assessment reports, including findings, recommendations, and action plans
  • Work closely with clients to address security and compliance concerns, provide guidance, and ensure regulatory requirements are met against industry frameworks.
  • Participate in client meetings, take effective notes, and ask relevant questions to gather information
  • Contribute to the continuous improvement of the organization's cyber security and compliance practices, methodologies, and tools
  • Maintain up-to-date knowledge of regulatory changes, emerging threats, and industry trends
  • Ensure that all deliverables are of the highest quality and that tasks are executed in accordance project timelines and budgets
  • Support business development and RFP activities

Required Skills and Qualifications

  • 5+ years of experience with conducting security control assessments against industry frameworks, including CMMC, NIST RMF, NIST SP 800-171, NIST 800-53, etc.
  • A US citizen who can pass a suitability determination process from the DoD
  • A deep knowledge of CMMC 2.0
  • Candidate must possess or be able to obtain at least one or more of the following: CMMC Certified Assessor (CCA) (Preferred) OR CMMC Certified Professional (CCP) (Minimum)
  • Bachelor’s degree in business administration, computer science, IT, cybersecurity, or related field/experience.
  • Team player able to work well with others in a collaborative manner and is a self-starter who can work with minimum supervision
  • Work to continually build and improve solid and well-rounded practices and processes
  • Excellent communication skills, both written and verbal with strong presentation skills
  • Ability to interact with clients and represent the company in a professional manner
  • Ability to successfully manage multiple tasks with competing priorities
  • Strong customer service and consulting experience
  • Experience with preparing and delivering executive level reporting
  • 5+ years in a consulting role specifically client facing
  • Experience with Windows and Linux system administration
  • Ability to travel as required.

Preferred Qualifications

  • CISSP, CISM, CISA, CCA, CCP or related certification preferred