1

Local Cmmc Assessor Jobs (NOW HIRING)

... local device controls). * Proven track record of working constructively with engineering and ... Direct experience participating in or maintaining a C3PAO CMMC assessment environment. * Ability to ...

... local device controls). * Proven track record of working constructively with engineering and ... Direct experience participating in or maintaining a C3PAO CMMC assessment environment. * Ability to ...

... local device controls). * Proven track record of working constructively with engineering and ... Direct experience participating in or maintaining a C3PAO CMMC assessment environment. * Ability to ...

... CMMC, etc.). Duties and Responsibilities ● IT Security Risk and Privacy Assessments - Assess ... local law. Incumbent(s) in this position may be required to perform other duties and special ...

As a PCI QSA company, we are expanding the pool of PCI Qualified Security Assessors (QSAs) and CMMC ... local, contractual, and organizational requirements and best practices standards such as ISO 27001 ...

Expert-level knowledge of the CMMC framework, including practice requirements and the assessment ... Local to the Washington DC metro area * Certified Information Security Manager (CISM) * Certified ...

Expert-level knowledge of the CMMC framework, including practice requirements and the assessment ... Local to the Washington DC metro area * Certified Information Security Manager (CISM) * Certified ...

next page

Showing results 1-20

Local Cmmc Assessor information

See salary details

$32.5K

$75.3K

$125.5K

How much do local cmmc assessor jobs pay per year?

As of Aug 12, 2026, the average yearly pay for local cmmc assessor in the United States is $75,259.00, according to ZipRecruiter salary data. Most workers in this role earn between $46,000.00 and $97,000.00 per year, depending on experience, location, and employer.

What is the difference between Local Cmmc Assessor vs CMMC Consultant?

AspectLocal Cmmc AssessorCMMC Consultant
CertificationsRequires CMMC-specific assessments and certificationsOften holds CMMC-related certifications but focuses on advising
Work EnvironmentPerforms on-site assessments for organizationsProvides remote or on-site consulting services
Employer & Industry UsageEmployed by organizations or assessors for complianceHired by organizations to prepare for assessments

The main difference is that a Local Cmmc Assessor conducts official on-site assessments to verify compliance, while a CMMC Consultant offers guidance and preparation support. Assessors are involved in the evaluation process, whereas consultants focus on readiness and strategy.

More about Local Cmmc Assessor jobs
What cities are hiring for Local Cmmc Assessor jobs? Cities with the most Local Cmmc Assessor job openings:
What are the most commonly searched types of Cmmc Assessor jobs? The most popular types of Cmmc Assessor jobs are:
What states have the most Local Cmmc Assessor jobs? States with the most job openings for Local Cmmc Assessor jobs include:
What job categories do people searching Local Cmmc Assessor jobs look for? The top searched job categories for Local Cmmc Assessor jobs are:
Infographic showing various Local Cmmc Assessor job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 69% Full Time, 27% Part Time, and 3% Contract. Highlights an 97% Physical, 1% Hybrid, and 2% Remote job distribution, with an average salary of $75,259 per year, or $36.2 per hour.

Senior Cybersecurity Engineer

Ursa Major

Berthoud, CO • Hybrid

$130K - $162K/yr

Full-time

Posted 12 days ago


Job description

The future of aerospace and defense starts here.


Ursa Major was founded to revolutionize how America and its allies access and apply high-performance propulsion, from hypersonics to solid rocket motors, satellite maneuvering and launch. We design and deliver propulsion and defense systems that solve the most urgent and critical national security demands.

We are bringing a new model to space access: one in which every link in an enormous value chain isn't limited by those around it. We design rocket engines and propulsion solutions.

Our products and technologies require an extraordinary team—one that will ensure the security of tomorrow's technologies while deploying today's best. We are an intrinsically motivated team with a passion for solving problems and empowering each other every day.

As a Senior Cybersecurity Engineer (Level 3) within our Digital Operations team, you won't just be monitoring alerts or checking compliance boxes. You will be a hands-on problem solver and trusted advisor who helps our hardware, software, and manufacturing engineers navigate complex security environments—including Controlled Unclassified Information (CUI)—without slowing down the pace of innovation.

Reporting up through Digital Operations, you will sit at the intersection of DevOps, Digital Manufacturing, Software Engineering, Zero-Trust Networking, and IT. As Ursa Major scales from 380 to 500+ employees by EOY 2026, you will play a central role in evolving our CMMC Level 2 posture—leading the strategic transition from a cloud-only enclave to a high-performing hybrid enclave that integrates on-premise hardware, lab equipment, and manufacturing environments smoothly and securely.

Responsibilities:

  • Stakeholder Enablement & Creative Risk Mitigation
    • Partner directly with non-cyber employees (program managers, manufacturing engineers, test stand operators) to understand their workflows and help them safely manage CUI and new tools without fear or unnecessary friction.
    • Approach security challenges with nuance rather than black-and-white rules. Find pragmatically secure pathways that satisfy federal requirements while keeping physical hardware engineering and CAD/CAM development moving forward.
    • Design controls around engineering workflows to eliminate latency and operational bottlenecks, ensuring compliance feels like an accelerator rather than a roadblock.
  • Hybrid CMMC L2 Expansion & Security Engineering
    • Lead the technical implementation to strategically expand our CMMC Level 2 boundary beyond our cloud-only enclave—safely integrating on-premise infrastructure, physical testing equipment, and shop floor operations without expanding CMMC scope to the entire enterprise network.
    • Manage and optimize technical security controls (SIEM, firewalls, zero-trust network access, identity platforms, vulnerability management) across both cloud and physical network environments.
    • Evolve key compliance artifacts—including System Security Plans (SSPs), Risk Assessment Reports (RARs), and POA&Ms—ensuring physical site boundaries and hybrid hardware data flows are accurately documented.
  • Leadership & Technical Ownership (Level 3)
    • Act as a subject matter expert who tackles ambiguous, high-complexity security and network segmentation challenges with minimal supervision, taking full ownership from diagnosis to resolution.
    • Work side-by-side with Zero-Trust Networking, DevOps, and IT to embed micro-segmentation and physical device controls directly into manufacturing environments and automated pipelines.
    • Provide technical guidance and mentorship to junior staff and IT team members, translating complex federal regulations into clear, actionable advice for non-cyber stakeholders.

Minimum Qualifications:

  • 4+ years of dedicated cybersecurity engineering experience in regulated or high-rigor environments.
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or equivalent practical experience.
  • Deep familiarity with government contracting regulations, specifically NIST SP 800-171 and CMMC Level 2 framework requirements.
  • Demonstrated experience implementing security controls in hybrid IT/OT or cloud-and-physical hardware environments (e.g., site-to-site VPNs, micro-segmentation, local device controls).
  • Proven track record of working constructively with engineering and business stakeholders—focusing on trust-building, communication, and enabling business outcomes rather than simple ticket-taking.

Preferred Qualifications:

  • Master's degree in a technical field; active CISSP, CISM, CISA, or CRISC certifications.
  • Direct experience participating in or maintaining a C3PAO CMMC assessment environment.
  • Ability to obtain and maintain a U.S. Government Security Clearance.

Colorado law requires us to tell you the base compensation range of this role, which is $130,000 - $162,000, determined by your education, experience, knowledge, skills, and abilities. The salary range for this role is intentionally wide as we are evaluating individuals based on their unique experience and abilities to fit our needs. Most importantly, we are excited to meet you and see if you are a great fit for our team. What we can't quantify for you are the exciting challenges, supportive team, and amazing culture we enjoy.

Classification: Full-Time, Exempt

Benefits Include: (Please note, Interns are not eligible for benefits)

  • Unlimited PTO - Vacation, Sick, Personal, and Bereavement
  • Paid Parental and Adoptive Leave
  • Medical, Dental and Vision Insurance
  • Tax Advantage Accounts (HSA/FSA)
  • Employer Paid Short and Long Term Disability, Basic Life, AD&D
  • Additional Benefit Options Including Voluntary Life and Emergency Medical Transport
  • EAP Program
  • Retirement Savings Plan - 401k with Company Match
  • Equity Grants in the Company

How To Apply:
Interested candidates are encouraged to apply by filling out the application below and clicking "Submit Application". This position will be posted for a minimum of 3 days and will remain open until filled or adjusted based on the volume of applicants.


NOTE: Research suggests that women and BIPOC individuals may self-select out of opportunities if they don't meet 100% of the job requirements. We encourage anyone who believes they have the skills and the drive necessary to succeed here to apply for this role.
Must be a U.S. Person (this includes U.S. Citizens and Permanent Residents).
Eligibility to obtain and maintain a U.S. Security Clearance.
We're an equal-opportunity employer. You will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran, or disability status.
No outside recruiters, please.