1

Cmmc Va Jobs (NOW HIRING)

Senior IAM Administrator

Herndon, VA · On-site

$88K - $119K/yr

Herndon, VA Hybrid (Onsite 3 days in a week) Duration : 1+ years Job Summary: The Senior Identity ... NIST 800-53 rev 4) * Experience with implementation of CMMC guidelines within the IAM Environment ...

IT Support Engineer

Herndon, VA · On-site

$67K - $202K/yr

Strong understanding of NIST 800-171 and CMMC compliance frameworks. * Expertise in maintaining ... Work Location Work Location: Full-time, on-site role in Herndon, VA and Columbia, MD. Salary Range ...

New

Senior Program Analyst/SME

Alexandria, VA · On-site

$124K - $124K/yr

Alexandria, VA (Telework) Position: *Contingent Upon Contract Award* Responsibilities: * Leads a ... We pride ourselves in being a Registered Provider Organization (RPO) with the CMMC Accreditation ...

Showing results 21-40

Cmmc Va information

See salary details

$14

$25

$53

How much do cmmc va jobs pay per hour?

As of Aug 12, 2026, the average hourly pay for cmmc va in the United States is $25.22, according to ZipRecruiter salary data. Most workers in this role earn between $18.03 and $23.80 per hour, depending on experience, location, and employer.

What is a CMMC VA?

CMMC VAs, or Cybersecurity Maturity Model Certification (CMMC) Virtual Assessors, are professionals who evaluate an organization’s compliance with CMMC requirements, often conducting assessments remotely. They help organizations identify gaps in their cybersecurity practices and prepare for formal CMMC certification. CMMC VAs typically have expertise in cybersecurity frameworks and are familiar with Department of Defense (DoD) contractor requirements. Their assessments are crucial for organizations that wish to bid on or maintain DoD contracts where CMMC compliance is mandatory.

How does a CMMC VA typically collaborate with client organizations during the assessment process?

As a CMMC VA, you'll work closely with client organizations to evaluate their cybersecurity practices against CMMC requirements. Collaboration often involves facilitating interviews, reviewing documentation, and touring facilities to understand existing security controls. Transparency and clear communication are key—assessors guide clients through the assessment process, clarify compliance gaps, and may offer feedback on remediation strategies. You'll also coordinate with the client’s IT and compliance teams to ensure all necessary evidence is gathered, making the process as smooth and thorough as possible.

What are the key skills and qualifications needed to thrive as a CMMC VA, and why are they important?

To thrive as a CMMC VA, you need a strong background in cybersecurity principles, risk management, and compliance, typically supported by relevant industry certifications such as CMMC Assessor Certification, CISSP, or CISA. Familiarity with CMMC frameworks, assessment tools, and government compliance systems is crucial for conducting accurate evaluations. Exceptional attention to detail, analytical thinking, and clear communication skills help you interpret standards and convey findings to clients. These competencies ensure thorough and reliable assessments, which are critical to safeguarding sensitive information and meeting regulatory requirements.

What is the difference between Cmmc Va vs Cmmc Auditor?

AspectCmmc VaCmmc Auditor
CertificationsRequires CMMC certification knowledge, security clearance may be preferredRequires CMMC auditing credentials, such as CMMC-AB Certified Professional
Work EnvironmentPrimarily involved in security assessments, vulnerability analysis, and compliance supportConducts audits, reviews security controls, and verifies compliance
Employer & Industry UsageUsed by defense contractors, government agencies, and cybersecurity firmsEmployed by consulting firms, government agencies, and independent auditors

While both roles focus on CMMC compliance, Cmmc VAs primarily assist with implementing security measures and preparing for assessments, whereas Cmmc Auditors evaluate and verify compliance through formal audits. Understanding these differences helps organizations assign the right professionals for their cybersecurity needs.

More about Cmmc Va jobs
What cities are hiring for Cmmc Va jobs? Cities with the most Cmmc Va job openings:
What states have the most Cmmc Va jobs? States with the most job openings for Cmmc Va jobs include:
Infographic showing various Cmmc Va job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 76% Full Time, 16% Part Time, 1% Temporary, and 6% Contract. Highlights an 90% Physical, 2% Hybrid, and 8% Remote job distribution, with an average salary of $52,465 per year, or $25.2 per hour.

Senior IT Cybersecurity Specialist (On-Site)

Groundswell Agriculture Festival

Mclean, VA

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 14 days ago


Job description

Who Are We?
Groundswell is a premier technology integrator and solution provider, resolutely committed to solving the most complex challenges facing federal agencies today. Our name, Groundswell, represents our commitment to be an unstoppable, seismic change in government. Ours is a small company culture with big company reach and results. Are you ready to be audacious, be bold and drive change at a rapid pace? Join us, where we'll make a greater impact together.


What You'll do:

Groundswell is seekinganexperienced, hands-on CybersecuritySpecialistto serve as the senior on-site technicalsupportfor cybersecurity operations, Microsoft Azure Government, Microsoft 365 GCC High, cloud infrastructure, identity, endpoint security, networking, and incident response.

This rolewill serve asanescalation point for complex security and infrastructure issues,and to helpstrengthen Groundswell's internal cyber capabilities,supportingthe company's ongoing compliancewith CMMC level 2. The position willberesponsiblefor investigations, configuration, troubleshooting, control implementation, and high-impact issue resolution.

Theindividual contributorposition works closely withsmall internal operations teamand External Supplier teams.

Key Responsibilities

  • Owncybersecurity operationsto includeincident response,investigations,response, threat identificationthreat,containment, recovery, root-cause analysis, and post-incident improvements.

  • escalation point for complex security, cloud, identity, endpoint, network, Azure Virtual Desktop, and infrastructure issues.

  • Administer privileged access and identity controls, including Conditional Access, multifactor authentication, service principals, Privileged Identity Management, least privilege, separation of duties, and time-limited elevation.

  • MaintainCiscoMerakienvironment, including firewalls, switches, wireless access points, VLANs, access-control lists, segmentation, logging, site connectivity, outage response, and recovery documentation.

  • vulnerability and configuration management using Tenable, Microsoft Defender, Microsoft Secure Score, vendor advisories, and threat-intelligence sources. Prioritize findings based on severity, exploitability, exposure, asset criticality, known exploitation, operational risk, and CUI impact; coordinate remediation, documentexceptionsand residual risk, and confirm corrective actions are effective.

  • Lead AvePoint backup and recovery for Microsoft 365 GCC High, including monitoring jobs, resolving failures, testing restores, andmaintainingrecovery practices for Exchange, SharePoint, OneDrive, and Teams.

  • Serve as a technical subject matter expert for CMMC Level 2 and related certification programs bymaintainingthe System Security Plan, Plans of Action and Milestones,etc

  • Provide seniorescalation support while preserving the Helpdesk's responsibility for routine ticket intake and normal user support, and mentor Helpdesk personnel in incident recognition, evidence preservation, escalation, troubleshooting, and documentation.

  • Prepare, review, implement, and document technical changesin supportofCMMI-SVC, ISO 9001, ISO/IEC 20000-1, ISO/IEC 27001, UK Cyber Essentials, and CMMC requirements.

Required Qualifications:

  • Bachelor's degree in cybersecurity, computer science, information systems, engineering, network engineering, or a related technical field.

  • 10yearyears+experience in cybersecurity operations, cloud security, infrastructure engineering, network engineering, incident response, or a related field.

  • Direct hands-on experience with Microsoft GCC High, Azure Government, Department of Defense cloud environments, or a comparable regulated Microsoft environment.

  • Advanced production experience with Microsoft Sentinel, Defender XDR, Entra ID, Intune, Purview, Exchange Online, SharePoint Online, Teams, Azure networking, Azure Virtual Desktop, KQL, and PowerShell.

  • Hands-on experience administering enterprise network infrastructure and resolving complex cloud, identity, endpoint, and network issues.

  • Demonstrated experience producing technical evidence for audits or assessments, remediating security findings,validatingcorrective actions, and explaining technical risks and controls to technical and nontechnical audiences

  • Ability to lead incident response under pressure, remain personally hands-on, exercise discretion with CUI and sensitive records, manage competing priorities, and work effectively witha variety of customers

  • US Citizenship required for clearance purposes.

  • Location: position is full time on-site in our Mclean, VA office.

Preferred Qualifications:

  • Microsoft Cybersecurity Architect Expert, Microsoft Security Operations Analyst Associate, or Microsoft Azure Security Engineer Associate certification.

  • Demonstrated experience leading AvePoint backup and recovery, security automation, or large-scale operational improvement in a regulated Microsoft Government cloud environment.

  • Advanced Cisco networking experience, including CCNP Enterprise or Cisco Meraki Solutions Specialist certification.


Skills:


Certification:

Why You'll Never Want to Leave:

  • Comprehensive medical, dental, and vision plans

  • Flexible Spending Account

  • 4% 401K Match (immediate vesting)

  • Paid Time Off

  • Tuition reimbursement, certification programs, and professional development

  • Flexible work schedule

  • On-site gym and childcare option

The salary range for this role takes into account the wide range of factors that are considered in making compensation decisions, including but not limited to skill sets, experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for any applicable geographic differential associated with the location at which the position may be filled. At Groundswell, it is not typical for an individual to be hired at or near the top of the range for their role, and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is:

$116,724.00 - $209,019.00


NOTE:Groundswell does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Groundswell, and Groundswell will not be obligated to pay a placement fee.

Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.

Read a copy of the Company's Non-Discrimination Policy Statement.
Additional Resources:

  • EO 13496 Notification of Employee Rights under NLRA

  • Know your rights: Workplace Discrimination is Illegal

Disability Accessibility Accommodation: If you are an individual with a disability and would like to request a reasonable accommodation as part of the employment selection process, please contact us athr@gswell.comor703-639-1777.