1

Cmmc Fedramp Jobs (NOW HIRING)

Required : • Deep understanding of CMMC 2.0 framework, NIST SP 800-171, and DFARS requirements. • Experience conducting technical assessments, vulnerability management, and implementing FedRAMP ...

You will also be cross-trained to support FedRAMP and other engagements based on NIST 800-53, contributing to Schellman's broader Federal Practice. CMMC Senior Associates perform a variety of ...

Get to know the GRC Engineering (GOV) Team Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment ...

$150 - $200/hr

The GRC Engineering (GOV) Team Our GRC engineering team guides defense contractors and federal organizations through their CMMC, NIST SP 800-171, NIST SP 800-53, FedRAMP, and Assessment ...

Support Engineer III

Reston, VA · On-site

$90K - $100K/yr

Ensure compliance with NIST 800-171, CMMC, and FedRAMP, partnering with Cybersecurity & Compliance teams Collaboration & Cross-Department Support * Partner with Program Management (PMO) to execute ...

You will also be cross-trained to support FedRAMP and other engagements based on NIST 800-53, contributing to Schellman's broader Federal Practice. CMMC Senior Associates perform a variety of ...

Support Engineer III

Reston, VA · On-site

$90K - $100K/yr

Ensure compliance with NIST 800-171, CMMC, and FedRAMP, partnering with Cybersecurity & Compliance teams Collaboration & Cross-Department Support * Partner with Program Management (PMO) to execute ...

CMMC Compliance Manager

Leesburg, VA · On-site

$150 - $200/hr

The CMMC Compliance Manger will be responsible for owning and managing the organization's CMMC ... Experience with FedRAMP, NIST CSF, ISO 27001, SOC 2, or other security frameworks. Compensation and ...

Showing results 21-40

Cmmc Fedramp information

What are CMMC and FedRAMP?

CMMC (Cybersecurity Maturity Model Certification) and FedRAMP (Federal Risk and Authorization Management Program) are two separate frameworks used by the U.S. government to ensure the security of information systems. CMMC is focused on assessing and enhancing the cybersecurity practices of defense contractors working with the Department of Defense. FedRAMP, on the other hand, is a government-wide program that standardizes security assessment, authorization, and continuous monitoring for cloud services used by federal agencies. Both frameworks aim to protect sensitive government data, but they apply to different contexts and have distinct compliance requirements.

What are some common challenges faced when coordinating CMMC and FedRAMP compliance efforts within an organization?

One of the main challenges professionals encounter is aligning the differing requirements and documentation standards of both CMMC and FedRAMP frameworks. This often involves managing cross-functional teams, ensuring that security controls meet the expectations of both standards, and preventing redundant work. Additionally, coordinating audits and assessments for both programs can be complex, requiring detailed project management and clear communication with stakeholders. Building a strong compliance culture and staying up-to-date with evolving regulations are also essential tasks in this role.

What are the key skills and qualifications needed to thrive as a CMMC/FedRAMP compliance specialist, and why are they important?

To thrive as a CMMC/FedRAMP compliance specialist, you need deep knowledge of cybersecurity frameworks, risk management, and regulatory requirements, often supported by relevant degrees or certifications like CISSP or CISA. Familiarity with technical tools such as security assessment software, GRC (Governance, Risk, and Compliance) platforms, and cloud security solutions is typically essential. Strong attention to detail, analytical thinking, and effective communication skills set standout professionals apart in this role. These skills and qualities are vital to ensure organizations achieve and maintain compliance, protect sensitive data, and meet federal contracting requirements.

What is the difference between Cmmc Fedramp vs Cybersecurity Analyst?

AspectCmmc FedrampCybersecurity Analyst
CertificationsFISMA, FedRAMP, CMMCCompTIA Security+, CISSP, CEH
Work EnvironmentGovernment agencies, cloud service providersPrivate sector, various industries
Industry UsageFederal compliance, cloud securitySecurity assessment, threat analysis

While both roles involve cybersecurity, Cmmc Fedramp focuses on compliance and security standards for government cloud services, requiring certifications like FedRAMP and CMMC. Cybersecurity Analysts primarily perform security assessments and threat mitigation across various sectors, often holding certifications like Security+ or CISSP. Understanding these differences helps organizations align roles with their compliance and security needs.

More about Cmmc Fedramp jobs

What job categories do people searching Cmmc Fedramp jobs look for?

The top searched job categories for Cmmc Fedramp jobs are:

What other helpful pages are available for Cmmc Fedramp?

Other pages related to Cmmc Fedramp:

Infographic showing various Cmmc Fedramp job openings in the United States as of September 2026, with employment types broken down into 2% Internship, 92% Full Time, 2% Part Time, and 4% Contract. Highlights an 53% In-person, 2% Hybrid, and 45% Remote job distribution.

Senior DevOps CI/CD Engineer - AWS (DevSecOps Champion)

Fairfax, VA • On-site

GDIT
IT Services • 10K+ employees

$144K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 14 days ago


General Dynamics Information Technology rating

7.8

Company rating: 7.8 out of 10

Based on 63 frontline employees who took The Breakroom Quiz

89th of 226 rated it services


Job description

Type of Requisition:

Regular

Clearance Level Must Currently Possess:

Secret

Clearance Level Must Be Able to Obtain:

Secret

Public Trust/Other Required:

None

Job Family:

Software Engineering

Job Qualifications:

Skills:

Controls Compliance, Identity Access Management (IAM), Secure Software Development, Security Testing, Web Applications

Certifications:

None

Experience:

8 + years of related experience

US Citizenship Required:

Yes

Job Description:

DEVOPS ENGINEER PRINCIPAL

GDIT is looking for a Engineer - AWS (DevSecOpsChampion) a senior technical rolesupporting DOJ Homeland Security Task Force (HSTF) / National Coordination Center (NCC).This role leads secure CI/CD andDevSecOpspractices for AWS-based solutions, designing and governing pipelines and automation that embed security, compliance, and risk management into the delivery lifecycle formissioncriticalsystems.

Responsibilities

  • Define and enforce secure CI/CD andDevSecOpsstandards, patterns, and guardrails for AWS-hosted applications, in alignment with GDIT Cyber Security Policy, Cyber Security Handbook, and Cloud/Security standards.
  • Design, build, andmaintainCI/CD pipelines (e.g., AWSCodePipeline/CodeBuild, Jenkins, GitLab CI, GitHub Actions, Azure DevOps) with integrated security scanning, compliance checks, approvals, and testing.
  • Leadinfrastructureascode(IaC) implementations (CloudFormation, Terraform) with embedded security and configuration baselines, supporting secure provisioning of AWS environments.
  • Automate secure environment provisioning, configuration, and deployments across development, test, and production AWS accounts, in line with cyber and IT risk management requirements.
  • Implement monitoring, logging, and alerting (CloudWatch, CloudTrail, centralized logging) to support secure, observable, and auditable delivery pipelines.
  • Integrate identity and access management, encryption, secrets management, vulnerability scanning, and compliance controls into CI/CD workflows as part ofDevSecOpspractices.
  • Ensure CI/CD pipelines and AWS solutionscomply withapplicable contractual and regulatory requirements (e.g., NIST 80053/171, CMMC, FedRAMP, ISO 27001) and internal cyber standards.
  • Collaborate with application development, cloud platform, cyber security, IT risk, and operations teams to ensure architectures are "DevSecOps-ready" and align with secure development standards.
  • Provide technical leadership, coaching, and documentation for project teams adoptingDevSecOpsand secure CI/CD practices; develop reusable secure pipeline templates and patterns.
  • Support proposals, technical reviews, and risk assessments where secure CI/CD, cloud security, andDevSecOpscapabilities arerequired, including input to labor category mapping and staffing.

Basic Qualifications

  • Bachelor's degree in Computer Science, Information Systems, Engineering, Cyber Security, or related field; or equivalent experience.
  • Typically8+ years of relevant IT experience, withsignificant experiencein DevOps/DevSecOpsand CI/CD for production systems.
  • Handsonexperience with AWS services (e.g., EC2, ECS/EKS, S3, IAM, VPC, CloudWatch/CloudTrail) insecuritysensitiveor regulated environments.
  • Proven experience designing and operating CI/CD pipelines using one or more modern platforms (AWSCodePipeline/CodeBuild, Jenkins, GitLab CI, GitHub Actions, Azure DevOps).
  • Strong experience withinfrastructureascode(e.g.CloudFormation, Terraform) and secure configuration management and automation.
  • Demonstrated experience promoting signed builds into an air-gapped, classified, or otherwise network-isolated target environment, including artifact transfer procedures and post-deployment verification.
  • Experience with containers and orchestration (e.g.Docker, ECS, EKS, Kubernetes) including security aspects (image scanning, runtime security, least privilege).
  • Demonstrated experience integrating security testing, vulnerability scanning, and compliance checks into CI/CD workflows (DevSecOps).
  • Experience working under formal security and risk frameworks (e.g., NIST 80053/171, CMMC, FedRAMP, ISO 27001,customerspecificcyber requirements).
  • Strong communicationand collaboration skills, with ability to work across cyber, risk, engineering, and program management teams.

Preferred Qualifications

  • AWS certifications (e.g., AWS Certified DevOps Engineer - Professional, AWS Certified Security - Specialty, AWS Solutions Architect).
  • Security/DevSecOpscertifications.
  • Experience supporting or implementing secure cloud architectures.
  • Experience in enterpriseDevSecOpsor security transformation initiatives, or in a cloud/cyber center of excellence.
  • Experience withmultiaccountAWS Organizations, landing zones, and centralized security/governance services.

OWN YOUR OPPORTUNITY
Explore a career in software development at GDIT and you'll find endless opportunities to grow alongside colleagues who share your dedication to advancing innovation.

The likely salary range for this position is $144,500 - $195,500. This is not, however, a guarantee of compensation or salary. Rather, salary will be set based on experience, geographic location and possibly contractual requirements and could fall outside of this range.

Scheduled Weekly Hours:

40

Travel Required:

50-75%

Telecommuting Options:

Hybrid

Work Location:

USA VA Fairfax

Additional Work Locations:

Total Rewards at GDIT:

Our benefits package for all US-based employees includes a variety of medical plan options, some with Health Savings Accounts, dental plan options, a vision plan, and a 401(k) plan offering the ability to contribute both pre and post-tax dollars up to the IRS annual limits and receive a company match. To encourage work/life balance, GDIT offers employees full flex work weeks where possible and a variety of paid time off plans, including vacation, sick and personal time, holidays, paid parental, military, bereavement and jury duty leave. To ensure our employees are able to protect their income, other offerings such as short and long-term disability benefits, life, accidental death and dismemberment, personal accident, critical illness and business travel and accident insurance are provided or available. We regularly review our Total Rewards package to ensure our offerings are competitive and reflect what our employees have told us they value most.

Our Identity Verification Process:

As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during virtual interviews. We reserve the right to take your picture to verify your identity and prevent fraud. By proceeding, you authorize the collection, processing, and use of your biometric data for identity verification and security purposes.

About Our Work:

We are GDIT. A global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense and intelligence community. Our 26,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. We operate across 50+ countries worldwide, offering leading mission-ready capabilities in AI, cloud, cyber and software development.Join our Talent Community to stay up to date on our career opportunities and events at

gdit.com/tc.

Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

What General Dynamics Information Technology employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


General Dynamics Information Technology logo

About General Dynamics Information Technology

Sourced by ZipRecruiter

GDIT is a global technology and professional services company that delivers technology solutions and mission services to every major agency across the U.S. government, defense, and intelligence community. Its 30,000 experts extract the power of technology to create immediate value and deliver solutions at the edge of innovation. The company operates across 50+ countries worldwide, offering leading capabilities in digital modernization, AI/ML, cloud, cyber, and application development.

Industry

It services

Company size

10,000+ Employees

Headquarters location

Falls Church, VA, US