1

Cmmc Va Jobs (NOW HIRING)

Senior IT & Security Engineer (USA)

Warrenton, VA · On-site

$106K - $144K/yr

... VA area. They are seeking a Senior IT & Security Engineer who will oversee IT operations and security engineering for their Warrenton office, ensuring compliance with CMMC/NIST 800-171 standards and ...

next page

Showing results 1-20

Cmmc Va information

See salary details

$14

$25

$53

How much do cmmc va jobs pay per hour?

As of Jul 22, 2026, the average hourly pay for cmmc va in the United States is $25.22, according to ZipRecruiter salary data. Most workers in this role earn between $18.03 and $23.80 per hour, depending on experience, location, and employer.

What are CMMC VAs?

CMMC VAs, or Cybersecurity Maturity Model Certification (CMMC) Virtual Assessors, are professionals who evaluate an organization’s compliance with CMMC requirements, often conducting assessments remotely. They help organizations identify gaps in their cybersecurity practices and prepare for formal CMMC certification. CMMC VAs typically have expertise in cybersecurity frameworks and are familiar with Department of Defense (DoD) contractor requirements. Their assessments are crucial for organizations that wish to bid on or maintain DoD contracts where CMMC compliance is mandatory.

How does a CMMC VA (Certified CMMC Assessor) typically collaborate with client organizations during the assessment process?

As a CMMC VA, you'll work closely with client organizations to evaluate their cybersecurity practices against CMMC requirements. Collaboration often involves facilitating interviews, reviewing documentation, and touring facilities to understand existing security controls. Transparency and clear communication are key—assessors guide clients through the assessment process, clarify compliance gaps, and may offer feedback on remediation strategies. You'll also coordinate with the client’s IT and compliance teams to ensure all necessary evidence is gathered, making the process as smooth and thorough as possible.

What are the key skills and qualifications needed to thrive as a CMMC VA (Cybersecurity Maturity Model Certification Verification Assessor), and why are they important?

To thrive as a CMMC VA, you need a strong background in cybersecurity principles, risk management, and compliance, typically supported by relevant industry certifications such as CMMC Assessor Certification, CISSP, or CISA. Familiarity with CMMC frameworks, assessment tools, and government compliance systems is crucial for conducting accurate evaluations. Exceptional attention to detail, analytical thinking, and clear communication skills help you interpret standards and convey findings to clients. These competencies ensure thorough and reliable assessments, which are critical to safeguarding sensitive information and meeting regulatory requirements.

What is the difference between Cmmc Va vs Cmmc Auditor?

AspectCmmc VaCmmc Auditor
CertificationsRequires CMMC certification knowledge, security clearance may be preferredRequires CMMC auditing credentials, such as CMMC-AB Certified Professional
Work EnvironmentPrimarily involved in security assessments, vulnerability analysis, and compliance supportConducts audits, reviews security controls, and verifies compliance
Employer & Industry UsageUsed by defense contractors, government agencies, and cybersecurity firmsEmployed by consulting firms, government agencies, and independent auditors

While both roles focus on CMMC compliance, Cmmc VAs primarily assist with implementing security measures and preparing for assessments, whereas Cmmc Auditors evaluate and verify compliance through formal audits. Understanding these differences helps organizations assign the right professionals for their cybersecurity needs.

More about Cmmc Va jobs
What cities are hiring for Cmmc Va jobs? Cities with the most Cmmc Va job openings:
What states have the most Cmmc Va jobs? States with the most job openings for Cmmc Va jobs include:
Infographic showing various Cmmc Va job openings in the United States as of July 2026, with employment types broken down into 9% Locum Tenens, 1% Internship, 2% As Needed, 80% Full Time, 4% Part Time, and 4% Contract. Highlights an 86% Physical, 3% Hybrid, and 11% Remote job distribution, with an average salary of $52,465 per year, or $25.2 per hour.

CMMC Practitioner / Pre Audit Specialist

Apogee Global RMS

Arlington, VA • Hybrid

Contractor

Posted 18 days ago


Job description

Apogee Global RMS is seeking a CMMC Practitioner / PreAudit Specialist to support Defense Industrial Base (DIB) organizations preparing for CMMC Level 2 assessments and DFARS 252.2047012 compliance. This role is designed for practitioners who bring handson NIST 800171 implementation experience, understand the realities of CUI environments, and can guide organizations through preaudit readiness with precision and authority.

You will serve as a trusted advisor to engineering, compliance, and executive teams - ensuring that documentation, controls, and evidence packages are audit-ready and aligned to Cyber AB expectations.

What You Will Lead:

  • Preassessment readiness for CMMC Level 2, including gap analysis and remediation planning
  • Development and refinement of SSPs, POA&Ms, evidence artifacts, and policy frameworks
  • Mapping of NIST 800171 controls to technical implementations across onprem, cloud, and hybrid environments
  • Advisory support for DFARS 252.2047012, incident reporting readiness, and CUI boundary protections
  • Coordination with C3PAOs, RPOs, and internal stakeholders to ensure audit alignment
  • Continuous monitoring and compliance sustainment strategies for DIB organizations

Requirements

Certifications:

  • Cyber AB CCP (Certified CMMC Professional)
  • CCA (Certified CMMC Assessor)
  • RPA (Registered Practitioner Advanced)
  • NIST 800171 handson implementation experience
  • DFARS 252.2047012 fluency
  • CISSP or CISA for technical/compliance depth

Technical & Functional Expertise:

  • Deep understanding of CMMC Level 2 practices, assessment criteria, and evidence expectations
  • Experience preparing organizations for C3PAO assessments
  • Ability to translate compliance requirements into actionable engineering tasks
  • Strong documentation, policy development, and auditfacing communication skills
  • Familiarity with CUI handling, enclave design, and boundary protection

Location & Clearance:

  • Must reside in the NCR (DC/MD/VA)
  • Secret minimum; clearable candidates considered

Expected Skills:

  • Understanding the realworld implementation of NIST 800171, not just the text
  • Expertise to guide organizations through complex preaudit readiness with clarity and confidence
  • Communicate effectively with engineers, executives, and assessors
  • Operate with precision, structure, and missionaligned discipline
  • Thrive in hightrust, highimpact advisory environments supporting the DIB

Benefits

Why Apogee:

Apogee supporting federal programs in this Top Tier engagement where compliance maturity directly impacts contract eligibility, mission readiness, and nationallevel defense outcomes. You'll work with decisionmakers, shape audited environments, and operate in a space that values expertise, rigor, and operational excellence.

How to Apply

For any questions (OR) to apply, please contact us at careers@apogeeglobalrms.com.