2

Cmmc Remote Jobs in Virginia (NOW HIRING)

Senior IT Systems Administrator

Reston, VA ยท On-site +1

$89K - $121K/yr

This individual will also play a key role supporting our CMMC compliance efforts and helping stand ... Our positions are based in Reston, Virginia, with much of our team operating in a hybrid or remote ...

... a remote setting, you will be supporting teams of professionals working to evaluate and secure a ... Expert-level knowledge of the CMMC framework, including practice requirements and the assessment ...

... a remote setting, you will be supporting teams of professionals working to evaluate and secure a ... Expert-level knowledge of the CMMC framework, including practice requirements and the assessment ...

... CMMC, NIST 800-171, and CUI handling requirements. The role is charged with developing scalable ... This is a remote position; however, team members should be willing and able to travel if the need ...

Jr. Azure Technician

Mclean, VA ยท On-site +1

$21.75 - $29.75/hr

Provide remote and onsite technical support to end users, resolving incidents efficiently while ... CMMC) requirements. SecureITSM also supports commercial entities that must maintain a high level of ...

Endpoint Engineer

Fairfax, VA ยท Remote

$120K - $150K/yr

Administer and support RMM tools (such as NinjaOne) for monitoring, remote support, automation, and ... Experience with CMMC Level 2 compliance requirements. * Experience with Azure Virtual Desktop (AVD ...

next page

Showing results 1-20

Cmmc Remote information

What are the key skills and qualifications needed to thrive as a CMMC Remote Assessor, and why are they important?

To thrive as a CMMC Remote Assessor, you need a strong understanding of cybersecurity frameworks, auditing principles, and the CMMC (Cybersecurity Maturity Model Certification) requirements, often supported by relevant certifications such as CMMC-AB Certified Assessor or similar credentials. Familiarity with compliance management tools, secure file-sharing platforms, and remote assessment technologies is essential. Excellent communication, attention to detail, and analytical thinking are critical soft skills for interpreting complex security controls and collaborating with client organizations. These skills ensure accurate, thorough remote assessments and help organizations achieve and maintain required cybersecurity standards.

What is the difference between Cmmc Remote vs Cmmc Onsite?

AspectCmmc RemoteCmmc Onsite
Work EnvironmentRemote, from any locationOn-site, at designated facilities
CertificationsSame CMMC certifications requiredSame CMMC certifications required
Employer & Industry UsageUsed by organizations with remote teams in cybersecurity and complianceUsed by organizations requiring on-site security assessments
Work TasksRemote compliance assessments, documentation, and auditsOn-site security evaluations and physical assessments

The main difference between Cmmc Remote and Cmmc Onsite lies in the work environment. Cmmc Remote professionals perform compliance tasks from any location, offering flexibility, while Cmmc Onsite roles require physical presence for assessments. Both roles demand the same certifications and serve similar industry needs, but the work setting varies based on client requirements and job specifics.

What is a CMMC Remote job?

A CMMC Remote job refers to a position in which professionals work remotely to help organizations achieve and maintain compliance with the Cybersecurity Maturity Model Certification (CMMC) standards. These jobs typically involve assessing cybersecurity practices, preparing documentation, conducting virtual assessments, and advising on compliance strategies for contractors in the defense supply chain. Remote CMMC roles can include consultants, assessors, project managers, or compliance specialists, and enable organizations to access expertise regardless of geographic location. The work is essential for companies aiming to meet Department of Defense (DoD) cybersecurity requirements.

What are the most common challenges faced by professionals working in a remote CMMC compliance role?

Professionals in remote CMMC compliance roles often encounter challenges related to communication and collaboration, especially when coordinating with multiple departments to ensure cybersecurity standards are met. Remote work can make it more difficult to access sensitive systems securely and to conduct in-person assessments or interviews with stakeholders. Staying updated on evolving CMMC requirements and maintaining clear documentation can also be challenging without direct office resources. Successful candidates typically leverage secure collaboration tools, proactive communication, and well-structured workflows to overcome these obstacles.
What are the most commonly searched types of Cmmc jobs in Virginia? The most popular types of Cmmc jobs in Virginia are:
What job categories do people searching Cmmc Remote jobs in Virginia look for? The top searched job categories for Cmmc Remote jobs in Virginia are:
What cities in Virginia are hiring for Cmmc Remote jobs? Cities in Virginia with the most Cmmc Remote job openings:
Infographic showing various Cmmc Remote job openings in Virginia as of July 2026, with employment types broken down into 94% Full Time, and 6% Part Time. Highlights an 100% Remote job distribution.

CMMC Assessment Lead

Paragone Solutions, Inc.

Mclean, VA โ€ข Remote

Full-time

Re-posted 14 days ago


Job description

About SecureITSM
SecureITSM is a Certified CMMC Managed Service Provider (MSP) supporting Department of Defense (DoD) contractors that must obtain and maintain Cybersecurity Maturity Model Certification (CMMC). SecureITSM is a CMMC Certified Organization (CMMC UID #L200002160) and has developed a proprietary CMMC documentation and compliance platform designed to streamline assessment preparation, evidence management, and ongoing compliance operations.
We are seeking a highly organized and technically skilled CMMC Assessment Lead to oversee the planning, preparation, coordination, and support of customer CMMC assessments conducted by authorized C3PAOs. This role is critical to ensuring our customers successfully achieve and maintain compliance with NIST SP 800-171 Rev. 2 and future Rev. 3 requirements.
The ideal candidate combines deep cybersecurity and compliance expertise with exceptional project management, customer communication, and assessment defense capabilities.
Location and Travel: This is a remote position with occasional travel required to support customer assessments.
Position Summary
The CMMC Assessment Manager will oversee customer assessment readiness activities from initial scheduling through final assessment support and remediation coordination. The role requires direct interaction with customers, assessors, internal engineering teams, and executive leadership.
This individual will manage multiple concurrent customer engagements while ensuring assessment artifacts, implementation statements, policies, procedures, and evidentiary documentation are accurate, complete, and defensible.
Key Responsibilities
Plan and Coordinate Assessments (Primary)
  • ​​​​​​​​​​​​​​​​​​​​Maintain the master CMMC customer assessment schedule
  • Coordinate assessment timelines with customers, C3PAOs, and internal SecureITSM teams
  • Conduct readiness reviews and pre-assessment planning meetings
  • Track customer assessment milestones, dependencies, and remediation activities
  • Manage customer communications related to assessment preparation and scheduling
  • Coordinate Rules of Engagement (ROE), assessment logistics, and secure evidence transfer processes
  • Monitor assessment status and provide executive-level reporting on customer readiness
  • Assist customers in understanding assessment scope, boundary definitions, and enclave considerations ​​​​​​​​​​​​​​
Prepare Assessment Packages (Primary)
  • Update implementation statements as needed
  • Gather and organize evidentiary artifacts
  • Coordinate customer evidence collection activities
  • Review SSPs, policies, procedures, and supporting documentation for assessment readiness
  • Validate evidence traceability to NIST SP 800-171 requirements and assessment objectives
  • Prepare assessor-ready evidence packages and artifact repositories
  • Conduct internal quality assurance reviews of documentation and evidence
  • Identify documentation gaps and coordinate remediation activities
  • Support development and maintenance of Plans of Action & Milestones (POA&Ms)
  • Ensure documentation aligns with evolving CMMC and NIST guidance
Support Customer Assessments (Primary)
  • Attend and actively support customer assessments
  • Actively defend implementations and evidence presented to assessors
  • Coordinate assessment interviews and technical demonstrations
  • Support mock assessments and readiness exercises for customers
  • Assist customers in responding to assessor requests and follow-up questions
  • Document assessment observations, findings, and remediation actions
  • Coordinate post-assessment remediation activities and evidence resubmissions when required
  • Serve as a trusted advisor throughout the certification lifecycle
Maintain SecureITSM’s Authorization and Compliance (Secondary)
  • Conduct SecureITSM’s annual self-assessment activities
  • Maintain internal compliance documentation and evidentiary artifacts
  • Coordinate annual evidence collection activities (e.g., training certificates, access reviews, vulnerability scans)
  • Assist with internal policy and procedure updates
  • Support ongoing continuous monitoring and compliance validation activities
  • Track changes to CMMC, NIST SP 800-171, and related DoD guidance affecting internal compliance posture
 Implementation Statement Management (Secondary)
  • Maintain and update SecureITSM master implementation statement libraries aligned to NIST SP 800-171 and evolving CMMC guidance
  • Develop and maintain industry-specific implementation statement sets (e.g., manufacturing, engineering, professional services, telework-only environments)
  • Standardize implementation language and evidence expectations across customer environments
  • Coordinate updates to implementation statements based on assessment findings, regulatory changes, and best practices
  • Validate implementation statements for technical accuracy, completeness, and assessor defensibility
  • Support continuous improvement of SecureITSM’s proprietary documentation platform and implementation content library
Maintain and Improve Standard Operating Procedures (Secondary)
  • Develop and maintain assessment preparation Standard Operating Procedures (SOPs)
  • Continuously improve evidence collection and assessment support workflows
  • Create standardized templates, checklists, and assessment playbooks
  • Document lessons learned and incorporate process improvements
  • Maintain internal knowledge base articles and operational documentation
  • Assist in refining SecureITSM’s proprietary CMMC documentation platform workflows and processes
Required Qualifications
  • U.S. Citizenship required
  • Detailed understanding of Microsoft Azure, Microsoft Defender, Microsoft Sentinel, Microsoft 365 GCC/GCC High, and related Microsoft security technologies
  • 6+ years of cybersecurity experience with strong focus on NIST SP 800-53 and/or NIST SP 800-171
  • Experience supporting compliance assessments, audits, or certification activities
  • Strong understanding of CMMC assessment methodology and evidence requirements
  • Excellent technical writing and communication skills
  • Strong project management and organizational abilities
  • Exceptional attention to detail
  • Ability to manage multiple customer engagements simultaneously
  • Experience working directly with external assessors, auditors, or regulatory bodies
  • Familiarity with secure project management and compliance collaboration platforms
Preferred Qualifications
  • PMP certification preferred
  • CMMC Certified Professional (CCP) or Certified Assessor (CCA) preferred
  • CISSP, CISM, or equivalent cybersecurity certification preferred
  • Experience supporting DoD contractors or working within the Defense Industrial Base (DIB)
  • Familiarity with FedRAMP and DFARS 252.204-7012
  • Experience with SIEM, vulnerability management, and endpoint protection technologies
Key Attributes
  • Strong leadership and customer engagement skills
  • Ability to remain composed and professional during high-pressure assessment activities
  • Analytical thinker with strong problem-solving capabilities
  • Self-motivated with ability to work independently
  • Collaborative team player with strong interpersonal skills
  • High level of integrity and professionalism ​​​​​​​

All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, status as a protected veteran or any other basis prohibited by law.
#ZR

Powered by JazzHR

0mriC7k8Mc

Company Description

Paragone Solutions, Inc. is a boutique provider of services to the Department of Defense. We are process-oriented (i.e. ISO 9001 certified) services company that provides cybersecurity, IT training, and industrial health/occupational safety support services. Founded in 2008, we are a certified woman-owned small business and a SBA certified 8(a) firm. Paragone offers competitive salaries and a relaxed, life-friendly work environment.